Help - Search - Members - Calendar
Full Version: IE + RealPlayer = Security hole
Vault9 Forums > Tech Den > Binary Refinery > The Backdoor

Custom Search
Fishfly
QUOTE
If you have RealPlayer installed and use Internet Explorer to browse the web, beware: an exploit in circulation can allow an attacker to take complete control of your machine, Symantec is warning.

Attacks targeting the most recent version of RealNetworks' music and video player were first observed Thursday night. They exploit a vulnerability in the way RealPlayer interacts with IE, providing a stealthy means for miscreants to shoehorn their way into a user's PC.

"If you have RealPlayer installed, simply visiting a malicious Web page can put your computer at risk," a Symantec blog post explains. "The player does not need to be running."

The ActiveX object being exploited resides in the the RealPlayer component ierpplug.dll. Attack code reviewed by Symantec causes RealPlayer to download and execute a copy of Trojan.Zonebac.


LINK


Man I couldn't believe this... I just downloaded the latest version of real-player 11 beta and next then everything on my PC started hanging/rebooting and system would grind to a halt with NO programs running or any processing power being utilized... beware!
Carrots
That'll teach you!

cyfermaster
Very very interesting. Always knew there was a reason I stopped using I.E.
Fishfly
what would teach me?? it's not my feking fault IE is shit... I don't use it, it's just there crying.gif

feking realplayer and IE se ma se balhara!
Carrots
Just like people who beat women, I have no respect for people who use realplayer :-p
Fishfly
lol well unfortunately some anime series I obtained are not in avi... and I do detest REALPLAYER... why you think this is my first installation?
Carrots
I think GOM player also plays .rm files. Not sure though.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Custom Search
Invision Power Board © 2001-2008 Invision Power Services, Inc.