Make sure your shit is updated

Make sure your shit is updated.
People spreading malware through subtitles.
blog.checkpoint.com/2017/05/23/hacked-in-translation/

Other urls found in this thread:

welivesecurity.com/2016/08/30/osxkeydnap-spreads-via-signed-transmission-application/
twitter.com/NSFWRedditVideo

Why can't they spread malware through overwatch or some other cancerous stuff?

The Cartel is so incompetent I doubt they have the programming skills to do something like this. We are safe.

You guys laughed at me for watching dubs. Who's laughing now?

>they are trying to get the Sup Forums dude that set up .pantsu

>Kodi, Popcorn Time, strem.io
>no practical exploit for VLC
It's fucking nothing

How does that even work? I like to think I'm fairly computer literate but viruses and shit like that just fuck with my head

Just use linux

give me a quick rundown about this one. How the fuck would they even do that?

I don't watch seasonalshit, so I couldn't care less.

Or just use Mac. It's just works and you can't get viruses

VLC was affected too

mpv doesn't have this problem

Maybe is something about mkv files? Good thing I only watch anime in superior mp4.

Nah OP, explain properly. Ain't going to some other shit site. How do you spread malware through a textfile?

By running an extra encoding on top of the video like subs, you can sometimes get the program to read a line which is actually a command which breaks out of the normal program to run something weird on your computer.

Different exploits for each player.
Popcorn Time renders subtitles as HTML using a non security conscious library, and nothing was stopping people from putting malicious scripts in there. Probably the same for stremio (nobody cares)
Kodi was an archive path traversal, allowing people to craft a zip file that extracts files into wherever.
VLC was a heap overflow that could potentially insert malicious code into memory, but the authors don't provide an example of it working (VLC and other apps take steps to make this type of attack difficult).

There was no POC, and VLC takes steps against buffer overflows such as ASLR. Worth fixing, but there's no evidence that it's practical to exploit.

Does this affect cccp?

If you still use CCCP in 2017, you have bigger problems.

People who know moon are still laughing, as always.

time to update VLC.

thanks, OP.

All I needed to know.

>vlc
>when mpv exists

>vlc
KAKA

>only affects certain players
VLC niggers blown the fuck out again. Hackers can't be fucked programing for autistic players, or maybe they're the same people that use them. Either way, faggots lose again.

>Doesn't effect MPC

Why bother making this thread?

>MPC-HC and mpv not affected
Wow it's fucking nothing. Only plebs gonna get infected by this.

>People still using VLC in the Year Of Our Lord Two Thousand and Seventeen
For what purpose? That fucking Nagato Yuki video has been out for years.

The fuck OP? It's about manually downloaded subtitles from subtitle databases. Got nothing to do with fansubs or Sup Forums unless you download subs from kitsuneko but I seriously doubt anyone is going to fuck around with Japanese subs for Chinese Cartoons.

I just downloaded The Young Pope with separated subs. Should I get worried? I also have VLC in my pc and based from the posted article it already fixed the security issue

Did you WATCH it with VLC you dumbass? If so you deserve what you get. Dogs eat dogfood, after all.

Because they got mindbroken learning it

>using Windows
You deserve all the shit you get

So basically unless CR or Horriblesubs want to hack people, there's really no concern?

Probably not.

Windows is objectively better than Linux for anime. mpv cannot use upscalers as advanced and powerful as NGU. Audio processing options (audio is half the anime sensory experience) are severely limited on Linux compared to Windows.
An anime patrician right now will dual boot Linux and Windows.

Your fault for not using mpv or mpc-hc.

Probably not.
It's more an excuse to update everything, and the bonus is you're covered if you pick up a stray movie from KAT or wherever with dodgy subs that you've set to auto-display.

Of course some idiot might try and spread copy-cat torrents with infected payloads around the usual trackers, hoping some lazy RSS auto-downloaders will pick them up.

I use MPlayerX on Mac though

Did you purchase that Mac for professional reasons?

>VLC

>VLC

>VLC

>>People still using VLC
It's "again".
In 2011 the anime community didn't use VLC.

welivesecurity.com/2016/08/30/osxkeydnap-spreads-via-signed-transmission-application/

So no MPC exploit. Why was this thread made?