Official BS.Player forums  

Go Back   Official BS.Player forums > Main forum > Answered And Solved Questions
Register FAQ Calendar Today's Posts Search

Answered And Solved Questions A good place to check before you post your question. All answered / solved posts are archived here.

 
 
LinkBack Thread Tools Search this Thread Display Modes
Prev Previous Post   Next Post Next
  #1 (permalink)  
Old 23rd September 2008
Junior Member
BS.player Regular User
 
Join Date: Mar 2007
Posts: 15
Rep Power: 0
robert334 is an unknown quantity at this point
Default [NOT A SECURITY HOLE ACTUALLY] BSPlayer security hole

How can command embedded into Avi?
BSPlayer 2.27 Buil 959
I guess someone has discovered a security hole and testing it now.
Doubleclicking plays avi and then starts a unrar command ...
How can playing avi start a unrar program????? whatever it may start then?????

I uploaded an avi segment 576x352 distorted to 240.avi (130k) to
http://www.sendspace.com/file/iijwmz (clean)


The file was "repaired" to 576x352.avi and uploaded by another forum member and uploaded
http://www.sendspace.com/file/eanxuj (not suspcious, until played with BS Player)

Now when started with doubleclick, the "repaired" avi plays with BSPlayer and then visibly unpacks the closest rar (which is a music mp3 album) into user temp folder which starts to play when 1-2 second video stops.

Right now doen't seem to have done any harm to system but needs checking ... when I have time.
Reply With Quote
 

Tags
hole, security


Posting Rules


All times are GMT +1. The time now is 10:31 AM.


Powered by vBulletin® Version 3.8.9
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
Search Engine Optimization by vBSEO 3.6.0 PL2
Ad Management plugin by RedTyger

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20