Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

 Malicious Subtitles Threaten Kodi, VLC and Popcorn, Security alert

views
     
TSOCMAX
post May 24 2017, 03:04 PM, updated 9y ago

Enthusiast
*****
Senior Member
858 posts

Joined: Jan 2003


QUOTE
Online streaming is booming, and applications such as Kodi, Popcorn Time and VLC have millions of daily users.

Some of these use pirated videos, often in combination with subtitles provided by third-party repositories.

While most subtitle makers do no harm, it appears that those with malicious intent can exploit these popular streaming applications to penetrate the devices and systems of these users.

Researchers from Check Point, who uncovered the problem, describe the subtitle ‘attack vector’ as the most widespread, easily accessed and zero-resistance vulnerability that has been reported in recent years.

“By conducting attacks through subtitles, hackers can take complete control over any device running them. From this point on, the attacker can do whatever he wants with the victim’s machine, whether it is a PC, a smart TV, or a mobile device,” they write.

“The potential damage the attacker can inflict is endless, ranging anywhere from stealing sensitive information, installing ransomware, mass Denial of Service attacks, and much more.”

In a demonstration video, using Popcorn Time, the researchers show how easy it is to compromise the system of a potential victim.

A demo of the subtitles vulnerability


XBMC Foundation’s Project lead Martijn Kaijser informs TorrentFreak that the Kodi team is aware of the situation, which they will address soon. “We will release 17.2 which will have the fix this week,” he told us.

VLC’s VideoLAN addressed the issue as well, and doesn’t expect that it is still exploitable.

“The VLC bug is not exploitable. The first big issue was fixed in 2.2.5. There are 2 other small issues, that will be fixed in 2.2.6,” VideoLAN informed us.

The team behind PopcornTime.sh applied a fix several months ago after the researchers approached them, TorrentFreak is informed. The Popcorn Time team trusts their subtitle provider OpenSubtitles but says that it now sanitizes malicious subtitle files, also those that are added by users.

The same applies to the Butter project, which is closely related to Popcorn Time. Butter was not contacted by Check Point but their fix is visible in a GitHub commit from February.

“None of the Butter Project developers were contacted by the research group. We’d love to have them talk to us if our code is still vulnerable. To the extent of our research it is not, but we’d like the ‘responsible disclosure’ terms to actually mean something,” The Butter project informs TorrentFreak.

Finally, another fork Popcorn-Time.to, also informed us that they are not affected by the reported vulnerability.

The Check Point researchers expect that other applications may also be affected. They do not disclose any technical details at this point, nor do they state which of the applications successfully addressed the vulnerability.

“Some of the issues were already fixed, while others are still under investigation. To allow the developers more time to address the vulnerabilities, we’ve decided not to publish any further technical details at this point,” the researchers state.

More updates will be added if more information becomes available. For now, however, people who regularly use subtitle files should remain vigilant.


https://www.xwn2.com/malicious-subtitles-th...searchers-warn/
TSOCMAX
post May 24 2017, 07:03 PM

Enthusiast
*****
Senior Member
858 posts

Joined: Jan 2003


QUOTE(GuyM @ May 24 2017, 06:33 PM)
Will Jarvis be affected as well?
*
I believed if the infected sub-title are injected with the code you will be a target. NO matter what version you used. Unless there's a patch to block the code.

Better to used VPN at the moment.

Most important now is to Clear the sub-title downloaded cache.

This post has been edited by OCMAX: May 24 2017, 07:11 PM
TSOCMAX
post May 24 2017, 10:59 PM

Enthusiast
*****
Senior Member
858 posts

Joined: Jan 2003


Safest way are to download the subtitle manually.

I used to download it manually last time because sometime the audio and title sync is way out.

https://subtitle.udownloadrooz.xyz/

This post has been edited by OCMAX: May 24 2017, 11:01 PM
TSOCMAX
post May 24 2017, 11:17 PM

Enthusiast
*****
Senior Member
858 posts

Joined: Jan 2003


QUOTE(voncrane @ May 24 2017, 11:13 PM)
Wrong again bro... Safest way is to UPDATE to the latest versions of the media players that have the fixes included.. Why? Cuz the malicious folks can manipulate the ranking algorithms on the various subs downloading sites, faking their way to the top and into trusted status, which once downloaded (automatically or manually) and ran using an "unfixed" media player, playing the video WILL trigger the exploit and compromise the system.
*
For sure it the apps will be updated lor. LOL

That's my personal precaution. LOL

So what about the old device. they abandoning them at the moment. I also created my own Kodi 17.2.ipa for my ipad. smile.gif
TSOCMAX
post May 24 2017, 11:30 PM

Enthusiast
*****
Senior Member
858 posts

Joined: Jan 2003


QUOTE(voncrane @ May 24 2017, 11:26 PM)
Personal protection is good.. Check out my reply in Kodi thread..  laugh.gif

As for older devices and or versions.. There will be no official support provided. They simply do not have the manpower to carry on developing for older/legacy systems. As with Kodi V17 and android versions running OS versions lower than Lollipop.. Nothing.. Left at the mercy of the likes of Koying's SPMC.. which IMO is better than the official V16.1, at least on Android.
*
I think you have never try open a srt files before. have a look with notepad. smile.gif
TSOCMAX
post May 24 2017, 11:44 PM

Enthusiast
*****
Senior Member
858 posts

Joined: Jan 2003


QUOTE(voncrane @ May 24 2017, 11:41 PM)
Why yes I have.. Have you stopped to manually scroll through each and every line?....i used to, back then when I ran such on my PC.. Now, there's a dedicated media box and nothing personal is on it.. So they can have a go at it.. Network is frequently monitored for unusual traffic.. Work related..  smile.gif

Oh poor innocent fella.. There are txt, pdfs or docx or jpg files which when opened, do open as "intended"... and yet, a bunch of things are happening ever so silently in the background... Bruh, I would know.. I wear a white hat.  innocent.gif
*
That's good to know you monitor everything. at least you know the subtitle script is not so complicated, if there are any suspicious code just delete the files. LOL

This post has been edited by OCMAX: May 24 2017, 11:53 PM
TSOCMAX
post May 24 2017, 11:46 PM

Enthusiast
*****
Senior Member
858 posts

Joined: Jan 2003


QUOTE(Baconateer @ May 24 2017, 11:33 PM)
This is a serious matter.

Updated my VLC player to the latest version because I always download subs manually.
*
I don't use VLC but I'm curious why they didn't mention MX-player?

QUOTE(voncrane @ May 25 2017, 12:05 AM)
Yes, loopholes are either found by the good or bad guys.. We hope they are found by the good guys and a fix is implemented before the loophole is exploited. That's the ideal scenario. Now, there have been many cases where the bad guys have a good time (could be years in a couple instances) till a patch comes out.. That isn't going to stop anytime soon, if ever. So we'll cross said bridge when we get there. For now, there's a fix freely available.. Those who can? It'd be unwise not to use. For those who can't  icon_rolleyes.gif ..

Another common misconception... That cuz running Android equals being 100% vulnerable to attacks.. I've been with Android since its early "Donut" & "Eclair" days and nine devices till date, not once have I ever been hit by a virus or malware.. not even among those in my circles.. Back when I got my HTC HD2, I tossed the WM OS out and replaced it with Android, booting off not NAND, but an SD card.. Ah memories.. smile.gif
I trust the Android OS and its ecosystem.. Why? The power of open source and its community.. I'd choose hundreds of thousands of eyes combing through the source code each day over those under Apple's control. Are there more malware/viruses written for Android than its walled counterpart iOS? Yes, simply because its more rewarding.. Cuz duh! Why write a malicious file for a less popular OS when the undisputed King is right there.. Same applies to the Windows OS. However (and this is a huge one), this does not in any way mean that iOS isn't impregnable, and it's very dangerous for such users to assume that it is..

I believe we've gone off topic for a bit.. Perhaps continue in the other thread you created..  smile.gif

Edit: Here are some bubble busters...  biggrin.gif
Fake Bitcoin Apps Emerge in Apple iTunes App Store.
Apple Lists Top 25 Apps Compromised by XcodeGhost Malware.
Apple Squashes App That Warned When Your iPhone Was Hacked.
Then there's jailbreaking.. Which isn't a default action majority of iOS users will take..
*
Is good that you have so much confident with android. So do you buy anything in playstore using your credit card? Did you used that account for all your android devices for google login and not using a fake account for normal usage?

As for my concerned on android platform we don't need to talk about history. We just have to patched a loophole.

I wonder you read the case whereby the FBI wanted to read the iPhone data from a terrorist? They go into court for that purposes but apple rejected and they ended up paying hundreds of thousand for a security firm to break into the phone. As for JB. it is the end user who select the risk. It is well known the risk it can causes or else you don't JB.

This post has been edited by OCMAX: May 25 2017, 12:24 AM
TSOCMAX
post May 25 2017, 08:41 AM

Enthusiast
*****
Senior Member
858 posts

Joined: Jan 2003


QUOTE(voncrane @ May 25 2017, 12:26 AM)
I use VLC & Kodi on the PC... I do have MX Player installed on the Media box but very rarely use it.. In fact, it's Kodi about 98% of the time. Not sure why MX Player wasn't mentioned.. Can't be because it's not popular enough.. Perhaps they too are working on the fix or have already patched it and none the wiser?  hmm.gif

There are two parts to the 2nd question...
1. My phone and tablet are more for official than leisure purposes.. This get the official gmail account and card for purchases.. Now, it's even better as I use mobile networks allow charging to one's account and pay later. So card option has been taken off.  smile.gif .Apps are purchased from the Play Store or downloaded from the likes of F-Droid, which is a completely free and open source Android app repository... If I have to install Third-party apps outside these sources, I get it directly from the source and at most, those are 2 or 3.. Proprietary apps come to mind..

2. The fiery pit: Exclusively for media consumption on the big screen-box thingy in the living room.. This guy gets nothing personal on it. Not even a personal Dropbox account  laugh.gif .. Has all sorts of hackery & patches & questionable apps installed and uninstalled.. Nothing ever gets purchased on it. I don't even expose my Netflix account to it, that is run exclusively via the isolated Smart TV app. I wouldn't consider the gmail account as a fake account... Just another for TV only account email... You know like how people have work and personal email accounts..  tongue.gif

The world's most secure smartphones are running the Android OS.. Not iOS/Blackberry OS/Firefox's, etc... Android's... Do check them out when you have some time..;
*Silent Circle's Blackphone 2 and
*Blackberry's PRIV
*
You see! that's the thing. We will take precaution not to exposed our official account in the Android box setup because that's a risk and used a fake account instead (meaning the account has nothing. NO credit detail, purchased, contact, email sync etc........) . But these has become a failure of the android system structure compared with Apple. I have no concerned about using my apple ID with my apple TV. Whatever songs, movies, apps, games that I bought or free download from itune over the years are shared with all my apple devices and family. I have no concern if I lost or damaged any of these devices because once I replace with another apple device unit and key in my apple ID. everything will be restore back exactly as the last back-up.

I'm not trying to say apple are much better. Just that I have more confident using it. The latest loophole in Android we patched are very much like Teamviewer without end user knowledge. it not only affected the android TV boxes but all devices that installed Kodi, popcorn, VLC etc....... Is very dangerous.
QUOTE
Yes, I did follow that case and here's what happened.. If you think the US government or that of other countries, didn't prior to that time have the means to break into Apple's devices.. Well, I'll ask you to go back to what made Edward Snowden do what he did and why he remains a wanted person till date. World government officials have tremendous cash and human resources at their disposal and at the top of each and every one of their lists, National security ranks the highest.. To the average consumer, Apple can claim that theirs is the most protected OS.. But we in the system know fully well that the more sheltered an OS is, the less secure it often is.. That's just a basic security fact... If mere "mortals" can jailbreak every single major iOS version in the past.. Ask the Chinese authorities if they don't already have a backdoor into the latest iOS firmware and watch their response..  biggrin.gif

These are very hard to predict. It happen to Iran before. Whereby their Nuclear reactor hardware were sabotage and control by CIA. Is possible..... anything can happen but if that happen. Not only apple product. whatever product that came out from these country are at risk. LOL

Best is to go back to stone age. hahahaaaa laugh.gif

As for Edward Snowden. No matter how you see the case. He is a traitor. If that happen to any Country, that country will label him as traitor for sure.

This post has been edited by OCMAX: May 25 2017, 04:37 PM
TSOCMAX
post May 25 2017, 08:55 AM

Enthusiast
*****
Senior Member
858 posts

Joined: Jan 2003


QUOTE
Sorry, does this means kodi 17= Krypton?
Jarvis will be vulnerable?

QUOTE(AVFAN @ May 25 2017, 01:19 AM)
Yes.
*
You see that's the problems. Those User still using these older devices felt betray. Android and KODI abandon them letting them at risk. I can accept if they don't update the apps for future feature but for security risk? A NO NO!

These people will have to trust whoever come out with a patch and who can verify that the patch are safe that is not coming out from the official side?

The only thing left are to used these Android TV box wisely. Take whatever precaution you think is the best for you. Used wisely and smart BUT used at your own risk.

Bottom link. Even I have patched and update to the latest apk. I'll take extra precaution!


Cheers!

This post has been edited by OCMAX: May 25 2017, 05:21 PM
TSOCMAX
post May 25 2017, 11:24 PM

Enthusiast
*****
Senior Member
858 posts

Joined: Jan 2003


QUOTE(voncrane @ May 25 2017, 11:05 PM)
The only reason why I do not have personally identifiable information on my Android media box (Neo U1) is cuz that device is bombarded with apps that are sourced from questionable sources


These is what I tried to say. because there are so many free download and easy access and install to any of the android devices. It become a risk.

I'm not throwing out the android devices just that it doesn't give me the confident to utilize the system. Not like apple.


To me. Apple still more secured. LOL laugh.gif

btw! Is sad to see older device that thousands of people are still using label as "crappy devices" and abandon with security risk by those android/Kodi devs. rclxub.gif

This post has been edited by OCMAX: May 25 2017, 11:44 PM
TSOCMAX
post May 26 2017, 07:18 AM

Enthusiast
*****
Senior Member
858 posts

Joined: Jan 2003


QUOTE(voncrane @ May 26 2017, 01:46 AM)

You still couldn't get me. What I say is they left them out with Security risk. It's okay if they think the older or lower end hardware cannot use for the latest feature that they are moving forward but leaving them at risk without helping them to tackle the security loophole that they created.

That's a genius. laugh.gif

laugh.gif I owned Android hp too. I know how crappy it is if running only with untouched stock apps. laugh.gif 99% users owned an Android phones install 3rd party apps because is easy to access. I can't speak for others why they bought an android phone. as for me it's because of the easy access apps.

all the android devices can download Kodi, Popcorn Time and VLC from playstore? So If the stock devices did not install any aheem apps but installed these apps that are affected with the loophole not having any risk without patching? NO!

Oh! I have anther old & clean OS android phones. Only installed or can installed Kodi Javis 16.1. But now at risk due to NO security patch. LOL laugh.gif I only speak for myself and guaranty none. NO patch available currently. LOL laugh.gif laugh.gif laugh.gif

This post has been edited by OCMAX: May 26 2017, 11:17 AM
TSOCMAX
post May 26 2017, 08:25 AM

Enthusiast
*****
Senior Member
858 posts

Joined: Jan 2003


QUOTE(GuyM @ May 26 2017, 08:07 AM)
Thank you for the concern on users such as myself whose having Q16 running on 4.4.2 that's not compatible with Kodi 17.3
*
These is one example and too bad for hundreds thousands of like TM white box and my poor old clean android phone. rclxub.gif

This post has been edited by OCMAX: May 26 2017, 09:51 AM
TSOCMAX
post May 26 2017, 01:22 PM

Enthusiast
*****
Senior Member
858 posts

Joined: Jan 2003


LOL! Blame the owner that you have an old device running below new spec. That's none of their business. laugh.gif laugh.gif laugh.gif

One person is so happy with thousand having risk. That's your problems. LOL laugh.gif laugh.gif laugh.gif

Ops! I didn't buy the android phone. It was free given by Maxis package but wait that's my problems too because is an old spec.

Oh! I remember that's a statement if the Android phone only used playstore apps are guaranty safe. But now I'm at risk due to low end spec. Oppps.. is end user fault. LOL laugh.gif laugh.gif laugh.gif

This post has been edited by OCMAX: May 26 2017, 01:29 PM
TSOCMAX
post May 26 2017, 02:03 PM

Enthusiast
*****
Senior Member
858 posts

Joined: Jan 2003


As for me. I leave no choice but to take precaution not to used the subtitle from the apps option for my older devices.

People are not so stupid to buy a back dated gadgets. Is stupid to abandon the old devices which is still working well. Just used wisely and smart.

1. Don't use you official google account to log into these devices. To me is risky.
2. I'll download the subtitle manually if I needed, scan with your anti-virus/Malwarebytes before unzip the SRT files to check the contents. (not asking you guys to follow)
3. Don't simply install addons/apk that you don't know. (I have removed the apk I shared earlier, better don't take the risk)
4. Even that's a patch to closed this security loopholes. Check who is providing
5. Used a VPN.


To be frank. I lost more confident with Android.

Cheers! smile.gif

This post has been edited by OCMAX: May 27 2017, 11:39 AM
TSOCMAX
post May 26 2017, 03:15 PM

Enthusiast
*****
Senior Member
858 posts

Joined: Jan 2003


QUOTE(voncrane @ May 26 2017, 03:11 PM)
Excellent precautions for those who are unable to get upgrade... Now you are talking.. The user takes action and not wait around pointing fingers..  tongue.gif .. .As for people being "stupid" to buy back-dated gadgets.. haha.. Even the iphone 7 is already back-dated.. I hang around device threads, you'll be amazed at how much "stupidity" is out there..

Okay... enjoy the prison disguised as a "secure garden"...  laugh.gif  icon_rolleyes.gif
*
That's my first suggest but people think is useless. LOL laugh.gif laugh.gif laugh.gif

You have to see there's so many people being stuck at these issue. Who doesn't know to buy another devices but some people just not willing to give up the working unit.

You can poison others. Not me. LOL laugh.gif

This is an SRT files sample open with notepad. If you see any suspicious text from the page. deleted the file.

user posted image

Tha's no pdf,img in the subtittle zip file. there will be only one files name srt. If there's other type of files in the zip. delete the subtitle zip file.


Just sharing.

Cheers!

This post has been edited by OCMAX: May 27 2017, 11:40 AM
TSOCMAX
post May 26 2017, 03:27 PM

Enthusiast
*****
Senior Member
858 posts

Joined: Jan 2003


QUOTE(voncrane @ May 26 2017, 03:22 PM)
Ehh.. Cut off one head and two will take its place.. Vive la révolution!
No lah.. Not useless.. First choice is upgrade, else you've got it all covered. No worries, give the community some time and the patch for Jarvis should surface.. Same like with the HTTPS V2 issue, FTMC and SPMC to the rescue...

Bro.. I'm also not eager to give up my trusty Note 3.. That's why, custom ROM, Kernel, etc.. Few months back, swapped out the battery with a new one for less than RM150.. Back to SOT of 4 hours+.. It's reborn!!  flex.gif . How to swap out battery with newer devices these days all tightly sealed?  doh.gif .. I sincerely hope it doesn't just die on me..  sweat.gif

Really.. I sell so hard.. No poison? sads..  tongue.gif
*
I stop using android phones for years because I don't like the platform but I owned 3 of them. 2 got it free, one I bought for my son.

One of the free unit I used for my DRONE live flight view. laugh.gif

Imagine. I didn't install any other apps but only DJI apps the unit also hang. LOL laugh.gif


About samsung phone battery. I have a friend that repair hp. he told me that's a lot of samsung phone battery will causes the screen to crack if it started to wobble.


This post has been edited by OCMAX: May 26 2017, 03:37 PM
TSOCMAX
post May 26 2017, 03:44 PM

Enthusiast
*****
Senior Member
858 posts

Joined: Jan 2003


QUOTE(voncrane @ May 26 2017, 03:38 PM)
What's the device? If they are handing it out for free.. Its either a crappy device in the first place or... You are so honorable (read as wealthy) that they've made or hope to make at least RM4K off you before the year ends... In which case, they gave say 2 free Galaxy S8+ units.. My money is on the latter.. brows.gif
*
If you have a cooperated account with multiple numbers. they might give you free. Need to check with my niece.

about my free phone. It's HTC lousy model. hahahaaa laugh.gif

I select that phone because is 6" last time. I intended to used it for my DRONE but ended up I cannot used due to the phone hang. my flight view will be lost/gone and I might lost my drone direction. Even the drone has home landing mode is risky.

This post has been edited by OCMAX: May 26 2017, 03:56 PM
TSOCMAX
post May 26 2017, 03:49 PM

Enthusiast
*****
Senior Member
858 posts

Joined: Jan 2003


QUOTE(voncrane @ May 26 2017, 03:38 PM)
I know its the future.. but i'm no fan of having sealed batteries in mobile phones.. We've seen bad batteries swell up and do damage.. At least with a removable back cover, all i have to do is replace the offending battery. I haven't and hope not to experience such. Battery's intact and AMOLED screen remains as gorgeous as ever... *knocks on wood.
*
He told me because the battery has too much glue stick near the screen and once it wobble it force it's way up and crack the screen. Something like that. smile.gif
TSOCMAX
post May 26 2017, 05:03 PM

Enthusiast
*****
Senior Member
858 posts

Joined: Jan 2003


QUOTE(voncrane @ May 26 2017, 04:17 PM)
Your drone can lose its direction to my place any day..  tongue.gif

Eh, HTC...  laugh.gif .. IMO, the HTC HD2 (2009) was the last real phone that HTC came up with.. It shipped with Windows Mobile V6.5, but due to its (at the time) beasty hardware, It was very moddable and as a result able to handle multiple OSes (Windows phone 7 & 8, Android, Windows XP, even Windows RT..) and to top it off, it can dual-boot OSes  rclxub.gif  notworthy.gif .. Last year, someone was even able to get Android Nougat working on the HTC HD2...  notworthy.gif
Oh I see.. Poor build quality then.. Like the Note 7 fiasco.. A smaller unpopular company would have collapsed. Well, Samsung has another chance to prove themselves as leaders. They better not screw up the Note 8 as I'm eyeing to get one for me HM...
*
Didn't check the model but is two years old. now I only used the HTC to test with Kodi since it's running on Android 4.3 OS. The funny is this phone works well with Kodi and a few others movies apps. I disable everything before installing these apps and leave all the space for KODI. It works. Just for the fun. LOL


As for the DRONE it won't go too far (I set to 5km) Once the connection lost between the Drone and remote control it will triggered to home mode and come back to base and land itself. laugh.gif

I heard Note 7 will be release again, Samsung got the model approved again. smile.gif

This post has been edited by OCMAX: May 26 2017, 05:04 PM

 

Change to:
| Lo-Fi Version
0.0213sec    0.38    6 queries    GZIP Disabled
Time is now: 26th November 2025 - 04:17 AM