|
Answered And Solved Questions A good place to check before you post your question. All answered / solved posts are archived here. |
| LinkBack | Thread Tools | Search this Thread | Display Modes |
| |||
[NOT A SECURITY HOLE ACTUALLY] BSPlayer security hole BSPlayer 2.27 Buil 959 I guess someone has discovered a security hole and testing it now. Doubleclicking plays avi and then starts a unrar command ... How can playing avi start a unrar program????? whatever it may start then????? I uploaded an avi segment 576x352 distorted to 240.avi (130k) to http://www.sendspace.com/file/iijwmz (clean) The file was "repaired" to 576x352.avi and uploaded by another forum member and uploaded http://www.sendspace.com/file/eanxuj (not suspcious, until played with BS Player) Now when started with doubleclick, the "repaired" avi plays with BSPlayer and then visibly unpacks the closest rar (which is a music mp3 album) into user temp folder which starts to play when 1-2 second video stops. Right now doen't seem to have done any harm to system but needs checking ... when I have time. |
| |||
:?: :?: :?: just tried with v2.31 and no rar-unpacking happened.. :? (I tried to put the file in the same folder as other RARs, ZIPs and also created a RAR file with the exact same name as the avi file) Try to scan your system for some sort of viruses by using a good antivirus program..
__________________ BSP SkinMaker (v1.07) the one and only Skin Editor for BSplayer BSP Definitions Manager (v1.02) BS.Player's FAQ (by BSPeter) | Italian language file (v2.57 build 1051) |
| |||
Thanks Tizio for support I have tried several times, it's the same each time. 1-2 sec avi and bsplayer skin looking small window opens where next rar in the folder is unrared to temp folder which starts to play next. Is there any unraring function embedded into BSPlayer??? Op system is Windows XP. I'm trying to find any other trace. There is a lot of network traffic, therefore right now I'm not sure if it tries to connect to somewhere. NAV 2008 doesn't alert neither. But sure is - the file looks the same stretched and isn't repaired, so I guess purpose of upload was something else :-) |
| |||
Yes, in BSplayer there's an unraring feature since v2.10.939 (for uncompressed rars) and improved since v2.25.955 (for compressed rars)
__________________ BSP SkinMaker (v1.07) the one and only Skin Editor for BSplayer BSP Definitions Manager (v1.02) BS.Player's FAQ (by BSPeter) | Italian language file (v2.57 build 1051) |
| |||
BTw. it seems that BS has a built in unzip function which starts , when Playlist - always add files in current directory to playlist option is active. It unrars zip and from rar plays music direct without unraring files. So the avi may be harmless. |
| |||
If you enabled the option to load every file in current folder, I think it's normal that it tries to unrar media files and start to play them ;) Don't worry, that file is harmless
__________________ BSP SkinMaker (v1.07) the one and only Skin Editor for BSplayer BSP Definitions Manager (v1.02) BS.Player's FAQ (by BSPeter) | Italian language file (v2.57 build 1051) |
| ||||
BS.Player can playback compressed and uncompressed rar's Also, if you uncheck the option Add all files from folder to PL, then the BS.Player will play only selected file and will not try to add any files from that folder to PL (and subsequently open archives and try to playback any multimedia content from them).
__________________ |Android translations | Technical help for PRO users | BS.Player-Subtitles.com | BSPeter's Help2Help | F. A. Q - Wiki | BSP Games |
Tags |
hole, security |
| |