Feeds

Malware goes to the movies

Dangerous liaisons

SANS - Survey on application security programs

Online attackers have started to experiment with embedding malicious code or links to such code in different video formats.

On Tuesday, anti-virus firm McAfee warned Windows users that the company had discovered a worm, dubbed W32/Realor, actively infecting Real Media files. The infected video files do not contain an exploit for the RealOne or Real players, but a hyperlink that points to a malicious website. When infected files are opened, the victim is referred to the web ite, which attempts to compromise their computer using a previously patched flaw in Internet Explorer.

There are numerous disadvantages to using video files to carry malicious code, but using the technique may allow attackers to take advantage of users' expectations, said Craig Schmugar, senior threat researcher with McAfee's anti-virus emergency response team.

"A chunk of people generally regard video files as safe, where they might treat screensavers and Office documents with some caution," Schmugar said.

While W32/Realor had not spread far, the incident came the same day that Microsoft distributed a patch for five security vulnerabilities in Adobe's Flash Player - software that is frequently used to play video streamed from popular internet sites. A week earlier, users of the social networking site MySpace attempted to use links in video files to surreptitiously install adware on visitors' computers.

The attention is unsurprising. Vulnerability researchers, for one, have increasingly focused on media players. In 2006, 19 medium and high-severity flaws were found in Apple's QuickTime Player, two in RealOne and Real Player, another two in Microsoft's Windows Media Player, and three in Adobe's Flash Player, according to the National Vulnerability Database. SecurityFocus sought comment from all four companies. Apple and Microsoft did not respond to the request, while RealNetworks could not provide a spokesperson in time for this article.

To date, actual video files have rarely been used as a vector of attack - typically, video plays only an incidental role. Many mass-mailing email viruses, such as the Kama Sutra or Blackmal worm, attempt to lure victims by offering an attachment that masquerades as a video. In other incidents, a Windows virus shipped on Apple video iPods and the virus - again, Blackmal - sent out to subscribers of Google's Video mailing list.

Yet, the increasing popularity of video downloads and streaming internet video - as demonstrated by the $1.6bn valuation that Google placed on internet video startup YouTube - will likely mean that online attackers will increasingly find ways to utilise the digital media as a method of compromising PCs, security experts said.

"It is my belief that most malware targets the 'large audience'," said Val Smith, co-founder of OffensiveComputing.net. "So following that, I do think that YouTube is, and will be, a target...As soon as someone comes up with a good and simple video malware kit - if they haven't already - then I think we start to see this become a problem."

Video and other media files to which people frequently link could use unique methods to boost infection rates. Malicious code could use true viral marketing, for example, using the reputation systems of community-oriented video sites such as YouTube to attempt to make infected videos more popular. The MySpace worm Samy used such techniques to build a massive friends list for the MySpace user, "Samy."

Google has processes in place to make such attacks difficult, the company said in a statement emailed to SecurityFocus.

"We work constantly to prevent people from misusing our services to distribute malicious software," Google said in the statement. "When we become aware of an instance where this happens, we take immediate action to limit user exposure.

High performance access to file storage

More from The Register

next story
Parent gabfest Mumsnet hit by SSL bug: My heart bleeds, grins hacker
Natter-board tells middle-class Britain to purée its passwords
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Mounties always get their man: Heartbleed 'hacker', 19, CUFFED
Canadian teen accused of raiding tax computers using OpenSSL bug
Samsung Galaxy S5 fingerprint scanner hacked in just 4 DAYS
Sammy's newbie cooked slower than iPhone, also costs more to build
Snowden-inspired crypto-email service Lavaboom launches
German service pays tribute to Lavabit
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Call of Duty 'fragged using OpenSSL's Heartbleed exploit'
So it begins ... or maybe not, says one analyst
prev story

Whitepapers

Top three mobile application threats
Learn about three of the top mobile application security threats facing businesses today and recommendations on how to mitigate the risk.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
SANS - Survey on application security programs
In this whitepaper learn about the state of application security programs and practices of 488 surveyed respondents, and discover how mature and effective these programs are.