Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

IE users beware: RealPlayer zero-day flaw under attack
ZDNet ^ | October 19th, 2007 | Ryan Naraine

Posted on 10/19/2007 10:18:29 AM PDT by holymoly

Hackers are actively exploiting a zero-day hole in RealNetworks’ RealPlayer media player, a software program installed on tens of millions of Windows computers worldwide.

RealPlayer zero-day flaw under attack

The in-the-wild attacks, which began late last night (October 18), targets a previously unknown and unpatched ActiveX vulnerability in the way RealPlayer interacts with Microsoft’s Internet Explorer browser.

The flaw is causing drive-by malware downloads when an IE user simply browsers to a maliciously rigged Web page, according to an alert issued by anti-virus vendor Symantec.

The issue affects an ActiveX object installed by RealPlayer, accessible over the web using Internet Explorer. By instantiating the object and invoking a specific method and attacker is able to corrupt process memory and execute arbitrary code with the privileges of the browser. The attack currently known to be in-the-wild has been confirmed to download malicious code to the compromised host.

According to sources tracking this threat, the attacks are limited in nature and appear to be targeting specific organizations. Some government agencies, including NASA, have reportedly banned the use of Internet Explorer in response to this incident.

“The malware appears to be spreading through a large variety of common and highly-respected Internet sites, however it does not appear these sites are themselves infected. The affected sites are serving solely as a mechanism to attract potential victims.”

Confirmed vulnerable: RealPlayer versions 6.0.14.544, 6.0.14.550 (11 Beta), 6.0.12.1662 (10.5), 6.0.12, 6.0.11, and 6.0.10.

TEMPORARY MITIGATION:

In the absence of a patch from RealPlayer, users might want to consider uninstalling the software immediately. Or, use an alternative Web browser (Mozilla Firefox or Opera) for Web surfing.

Symantec also recommends:



TOPICS: News/Current Events; Technical
KEYWORDS: activex; ie; msie; realplayer
Navigation: use the links below to view more comments.
first 1-2021-40 next last
In the absence of a patch from RealPlayer, users might want to consider uninstalling the software immediately. Or, use an alternative Web browser...

Firefox

Opera

Seamonkey

1 posted on 10/19/2007 10:18:31 AM PDT by holymoly
[ Post Reply | Private Reply | View Replies]

To: holymoly

Or an alternate OS like Linux ;-)


2 posted on 10/19/2007 10:20:45 AM PDT by fremont_steve (Milpitas - a great place to be FROM!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: holymoly

I’ve been avoiding RealPlayer for years, for reasons I don’t even clearly recall. I think it was because they became a PITA with all their spam and reminder popups or something to that effect.


3 posted on 10/19/2007 10:22:18 AM PDT by Nervous Tick
[ Post Reply | Private Reply | To 1 | View Replies]

To: holymoly

Don’t use RealPlayer at all. I believe it’s owned by Maria Cantwell, the flaming leftist democrat in the US Senate or some other notable leftist.


4 posted on 10/19/2007 10:23:06 AM PDT by Ron in Acreage (Conservative 1st, republican sometime)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce
Hackers are actively exploiting a zero-day hole in RealNetworks’ RealPlayer media player, a software program installed on tens of millions of Windows computers worldwide.

PING

5 posted on 10/19/2007 10:23:07 AM PDT by SubGeniusX (The People have UNENUMERATED RIGHTS ... the Govt. does NOT have UNENUMERATED POWERS)
[ Post Reply | Private Reply | To 1 | View Replies]

To: holymoly

Not a problem for me- I use Firefox and never had a use for RealPlayer.


6 posted on 10/19/2007 10:24:06 AM PDT by Squawk 8888 (Is human activity causing the warming trend on Mars?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: holymoly

I haven’t touched realplayer since 2000


7 posted on 10/19/2007 10:24:09 AM PDT by Crazieman (The Democrat Party: Culture of Treason)
[ Post Reply | Private Reply | To 1 | View Replies]

To: holymoly

Use Real Alternative instead. It does not alway work. But I just figure that if a web site demands using Real player with so many better choices out there then why visit that web site. Real player is a bloated piece of spy ware. It has been so for years.


8 posted on 10/19/2007 10:25:25 AM PDT by Revel
[ Post Reply | Private Reply | To 1 | View Replies]

To: Nervous Tick

You’re not missing anything. The only thing it can do that the other players can’t is play RealMedia content. Anything on rm that’s worth playing is also available in other formats.


9 posted on 10/19/2007 10:26:15 AM PDT by Squawk 8888 (Is human activity causing the warming trend on Mars?)
[ Post Reply | Private Reply | To 3 | View Replies]

To: fremont_steve

    In hoc signo vinces!

;o)
10 posted on 10/19/2007 10:26:16 AM PDT by LIConFem (Thompson 2008. Lifetime ACU Rating: 86 -- Hunter 2008 (VP) Lifetime ACU Rating: 92)
[ Post Reply | Private Reply | To 2 | View Replies]

To: Revel

Real Alternative (Uses and old version of windows media player):

http://www.free-codecs.com/download/Real_Alternative.htm


11 posted on 10/19/2007 10:26:52 AM PDT by Revel
[ Post Reply | Private Reply | To 8 | View Replies]

To: holymoly

I don’t have to worry. I use Windows Media Player................


12 posted on 10/19/2007 10:27:57 AM PDT by Red Badger ( We don't have science, but we have consensus.......)
[ Post Reply | Private Reply | To 1 | View Replies]

To: holymoly
good thing I have version 10.5.

Or are they talking about build not version?

13 posted on 10/19/2007 10:28:06 AM PDT by Just another Joe (Warning: FReeping can be addictive and helpful to your mental health)
[ Post Reply | Private Reply | To 1 | View Replies]

To: holymoly

14 posted on 10/19/2007 10:28:29 AM PDT by mysterio
[ Post Reply | Private Reply | To 1 | View Replies]

To: holymoly

< sigh > Something to do when I get home I guess.

Yet another reason to get a Mac.


15 posted on 10/19/2007 10:28:55 AM PDT by FourtySeven (47)
[ Post Reply | Private Reply | To 1 | View Replies]

To: fremont_steve

Has nothing to do with the OS. It’s the browser specifically IE.


16 posted on 10/19/2007 10:29:19 AM PDT by tomh68
[ Post Reply | Private Reply | To 2 | View Replies]

To: holymoly

In English please? :-)

I use Firefox but IE occasionally because some websites don’t work in Firefox (like my daughter’s soccer website)—if I go to “Add/Remove Programs” what should I remove? RealPlayer by itself? Or are other aspects needing to be removed as well?

My husband HATES “MicroShaft” as he calls it, but 90% of the programs/applications I use aren’t available on Linux yet—soon though I hope!!


17 posted on 10/19/2007 10:32:29 AM PDT by pillut48 (CJ in TX --Soccer Mom and proud RUSH REPUBLICAN! WIN, FRED, WIN!!!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: holymoly

Real Player turned into malware itself years ago.


18 posted on 10/19/2007 10:33:34 AM PDT by VeniVidiVici (No buy China!!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: holymoly
# Block access to the IPs 83.149.65.105 and 66.199.254.193, as these IP addresses were observed partaking in the attack and have also been observed by honeypots perpetrating other malicious activity.
# Set the kill bit on the Class identifier (CLSID) FDC7A535-4070-4B92-A0EA-D9994BCC0DC5 (Microsoft instructions for setting kill bit).

I'm sure glad that IE is easy to use and configure than other operating systems. /sarcasm

19 posted on 10/19/2007 10:37:52 AM PDT by PAR35
[ Post Reply | Private Reply | To 1 | View Replies]

To: VeniVidiVici
Real Player turned into malware itself years ago.

Eyup. It simply became a terrible product slated more at pushing advertising.

Pretty much Windows Media or Quik Time today.
20 posted on 10/19/2007 10:39:04 AM PDT by zencat (The universe is not what it appears, nor is it something else.)
[ Post Reply | Private Reply | To 18 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-40 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson