Hackers find holes in media players

  • Associated Press
  • Friday, August 3, 2007 7:36pm
  • Business

LAS VEGAS – Media players in personal computers have serious vulnerabilities that could allow online criminals to attach malicious code and infect computers without the user’s knowledge, a researcher said Thursday.

As a result, audio and video downloads can be turned into digital weapons that hackers could use to hijack or corrupt computers, said David Thiel, senior security consultant with San Francisco-based researcher iSEC Partners.

Thiel, who exposed the flaws on relatively obscure open-source media players during a presentation at the Black Hat hacker conference, said he has found several flaws in popular commercial players. But he declined to provide their brand names because, he says, he is still disclosing the exploits to the companies so they can issue fixes.

He isn’t aware of any current attacks using the vulnerabilities he’s discovered but said they’re hard to track.

ADVERTISEMENT
0 seconds of 0 secondsVolume 0%
Press shift question mark to access a list of keyboard shortcuts
00:00
00:00
00:00
 

“The actual potential for attack is reasonably severe because nobody cares about actually playing videos from YouTube or playing music on Web pages – you can’t get music to stop playing at you,” he said. “Because this stuff is launched automatically, I think the impact could be significant.”

Paul Proctor, a research vice president with Gartner Inc., said Thiel’s findings could pressure companies to investigate flaws in their media players and patch them quickly.

Hackers have targeted media players before, Proctor said, but Thiel’s attacks appear to infiltrate the machines more deeply and circumvent traditional Internet safeguards.

Thiel unveiled a new technique called “fuzzing” – corrupting the files used in applications in a controlled way to find exploitable bugs – to identify weaknesses in various media players.

“This is a new frontier for hacks,” Proctor said. “The straightforward, basic truth is that companies that make media players of all types will have to become as vigilant.”

Thiel and other programmers are exposing security vulnerabilities during the two-day Black Hat conference and will continue doing so at the three-day Defcon convention that starts here Friday. So-called “white hat” hackers present flaws to alert companies that their products are vulnerable to pranks or serious attacks by malicious or “black hat” hackers.

Jeff Moss, director of Black Hat, said conference organizers picked Thiel to present his findings because digital audio and video files are becoming phenomenally popular on YouTube, MySpace and other social networking sites. “This is the next logical place to attack,” Moss said. “People know now not to open strange documents, but they click on MP3s all day long.”

Talk to us

> Give us your news tips.

> Send us a letter to the editor.

> More Herald contact information.

More in Business

A standard jet fuel, left, burns with extensive smoke output while a 50 percent SAF drop-in jet fuel, right, puts off less smoke during a demonstration of the difference in fuel emissions on Tuesday, March 28, 2023 in Everett, Washington. (Olivia Vanni / The Herald)
Sustainable aviation fuel center gets funding boost

A planned research and development center focused on sustainable aviation… Continue reading

FILE — Jet fuselages at Boeing’s fabrication site in Everett, Wash., Sept. 28, 2022. Some recently manufactured Boeing and Airbus jets have components made from titanium that was sold using fake documentation verifying the material’s authenticity, according to a supplier for the plane makers. (Jovelle Tamayo/The New York Times)
Boeing adding new space in Everett despite worker reduction

Boeing is expanding the amount of space it occupies in… Continue reading

Paul Roberts makes a speech after winning the Chair’s Legacy Award on Tuesday, April 22, 2025 in Tulalip, Washington. (Olivia Vanni / The Herald)
Paul Roberts: An advocate for environmental causes

Roberts is the winner of the newly established Chair’s Legacy Award from Economic Alliance Snohomish County.

Laaysa Chintamani speaks after winning on Tuesday, April 22, 2025 in Tulalip, Washington. (Olivia Vanni / The Herald)
Laasya Chintamani: ‘I always loved science and wanted to help people’

Chintamani is the recipient of the Washington STEM Rising Star Award.

Dave Somers makes a speech after winning the Henry M. Jackson Award on Tuesday, April 22, 2025 in Tulalip, Washington. (Olivia Vanni / The Herald)
County Executive Dave Somers: ‘It’s working together’

Somers is the recipient of the Henry M. Jackson Award from Economic Alliance Snohomish County.

Mel Sheldon makes a speech after winning the Elson S. Floyd Award on Tuesday, April 22, 2025 in Tulalip, Washington. (Olivia Vanni / The Herald)
Mel Sheldon: Coming up big for the Tulalip Tribes

Mel Sheldon is the winner of the Elson S. Floyd Award from Economic Alliance Snohomish County

Craig Skotdal makes a speech after winning on Tuesday, April 22, 2025 in Tulalip, Washington. (Olivia Vanni / The Herald)
Craig Skotdal: Helping to breathe life into downtown Everett

Skotdal is the recipient of the John M. Fluke Sr. award from Economic Alliance Snohomish County

Katie Wallace, left, checks people into the first flight from Paine Field to Honolulu on Friday, Nov. 17, 2023 in Everett, Washington. (Olivia Vanni / The Herald)
Executive order makes way for Paine Field expansion planning

Expansion would be a long-range project estimated to cost around $300 million.

Dick’s Drive-In announces opening date for new Everett location

The new drive-in will be the first-ever for Everett and the second in Snohomish County.

Helion's 6th fusion prototype, Trenta, on display on Tuesday, July 9, 2024 in Everett, Washington. (Olivia Vanni / The Herald)
Helion celebrates smoother path to fusion energy site approval

Helion CEO applauds legislation signed by Gov. Bob Ferguson expected to streamline site selection process.

The Coastal Community Bank branch in Woodinville. (Contributed photo)
Top banks serving Snohomish County with excellence

A closer look at three financial institutions known for trust, service, and stability.

Image from Erickson Furniture website
From couch to coffee table — Local favorites await

Style your space with the county’s top picks for furniture and flair.

Support local journalism

If you value local news, make a gift now to support the trusted journalism you get in The Daily Herald. Donations processed in this system are not tax deductible.