You are here: silicon.com > Software > Malware

Malware

QuickTime flaw could fuel Second Life stealing

Watch out for the "evil pink box"

Tags: bank, security, linden lab, second life

By Robert Vamosi

Published: 18 February 2008 08:22 GMT

Researchers have shown how exploiting a flaw within QuickTime could allow an attacker could steal from other users in Second Life.

Security A to Z

From antivirus to zero-day, click here for silicon.com's alphabetical guide to security.

Charlie Miller of Independent Security Evaluators and Dino Dai Zovi, turned their attention to Second Life during a computer hacking conference in the US.

While Second Life does not install QuickTime, it invites users to install the player if they want to see multimedia files within Second Life.

What Miller and Zovi realised is that while direct communication between an attacker and a victim within Second Life passes through the servers at Linden Lab - the maker of Second Life - multimedia objects are actually stored elsewhere. Hence, an object with a multimedia link could inject malicious code. In this case, researchers exploited a recent flaw within RTSP tunnelling.

For their demonstration, they created "the most evil pink box you will ever see". They could have linked their malicious code to attributes of an avatar's hair, clothes or anything else.

In the demo, the researchers were able to show that their avatar became infected when it came too near the pink box. The code they used raided the avatar's Linden dollars and emptied the bank account. On the internet, an attacker can get one dollar for every 275 Linden dollars stolen, so there is a financial incentive to these attacks and other future attacks.

Original article: Exploiting QuickTime flaws in 'Second Life' from CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Nick Heath Your top HR tech priorities for next year revealed How to make human resources IT work for you

Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business


  • Jobs
Multimedia Designer

An excellent and exciting opportunity is available for a Multimedia Designer available to start ASAP and commute to Oxford on a daily basis. This ...

Software Multimedia Engineer

Our client is a leading fabless semiconductor company for wireless communications and digital multimedia solutions.Company Overview:The company is a ...

Set Top Box Project Manager

Our International telecommunications client is currently searching for experienced Set Top Box Project Managers with at least 5 years experience. You ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: