You are here: silicon.com > Software > Malware

Malware

QuickTime flaw could fuel Second Life stealing

Watch out for the "evil pink box"

Tags: second life, bank, security, linden lab

By Robert Vamosi

Published: 18 February 2008 08:22 GMT

Researchers have shown how exploiting a flaw within QuickTime could allow an attacker could steal from other users in Second Life.

Security A to Z

From antivirus to zero-day, click here for silicon.com's alphabetical guide to security.

Charlie Miller of Independent Security Evaluators and Dino Dai Zovi, turned their attention to Second Life during a computer hacking conference in the US.

While Second Life does not install QuickTime, it invites users to install the player if they want to see multimedia files within Second Life.

What Miller and Zovi realised is that while direct communication between an attacker and a victim within Second Life passes through the servers at Linden Lab - the maker of Second Life - multimedia objects are actually stored elsewhere. Hence, an object with a multimedia link could inject malicious code. In this case, researchers exploited a recent flaw within RTSP tunnelling.

For their demonstration, they created "the most evil pink box you will ever see". They could have linked their malicious code to attributes of an avatar's hair, clothes or anything else.

In the demo, the researchers were able to show that their avatar became infected when it came too near the pink box. The code they used raided the avatar's Linden dollars and emptied the bank account. On the internet, an attacker can get one dollar for every 275 Linden dollars stolen, so there is a financial incentive to these attacks and other future attacks.

Original article: Exploiting QuickTime flaws in 'Second Life' from CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Lingo/Multimedia Programmer, Bham, 30k

If you have strong experience with Lingo/Macromedia Director/Adobe Flash/Actionscript then contact us today! Excellent opportunity exists within a ...

Embedded Engineer! Hants! 35k Embedded PIC! Out of Box products!

An exciting position for an SME organisation in the Hampshire area is available. The company is organised to undertake contracts on a prime and ...

Software Test Engineer, QA To 30k

I am currently looking to recruit a software test engineer with white box testing experince. You will be active in White box script creation for ...

CIO Agenda 2008
The exclusive silicon.com CIO Agenda 2008 survey looks at the CIO's tech shopping list for the year, examines whether IT budgets are rising or falling and reveals what the pain points are for tech chiefs this year. Find out more in our latest special report.





Quick Sitemap Links: