14 ms·
Malicious Subtitles Threaten Kodi, VLC and Popcorn Time Users
- theGimp 9y agoThis is the sourced post http://blog.checkpoint.com/2017/05/23/hacked-in-translation/ http://blog.checkpoint.com/2017/05/23/hacked-in-translation/ The ingenuity that goes into RCE exploits never ceases to amaze (and terrify) me. Can't wait for more details to be released.
- mrmondo 9y agoInterestingly running VLC 2.2.4 on MacOS 10.12 and checking for updates returns 'VLC 2.2.4 is currently the newest version available.', obviously I downloaded 2.2.5.1 from videolan.org but still odd.
- zippoxer 9y agoCan confirm the same on Windows. I downloaded the newest version manually as well.
- jbk 9y ago2.2.6 is deployed.
- anon1385 9y agoSame here. It appears to check http://update.videolan.org/vlc/sparkle/vlc-intel64.xml http://update.videolan.org/vlc/sparkle/vlc-intel64.xml for updates and the newest version listed there is 2.2.4
- jbk 9y agoThe update will be deployed today or tomorrow in the updaters.
- zuck9 9y agoIs that a default behavior or something you chose to do? What if there's a bigger security fix you need to push to people asap?
- jbk 9y agoIt is something that we chose to do. We usually let between 24hours and a few days before doing an upgrade, seeing the possible regressions. From tag to release to updates can take only 4hours, if we want enough mirrors.
- muterad_murilax 9y agoWell, 10 days later and 2.2.4 is still shown as the latest version when trying to upgrade... :/
- pawadu 9y ago> The attack vector relies heavily on the poor state of security in the way various media players process subtitle files and the large number of subtitle formats. Well, last years exploits against iOS, Android and Ubuntu where all related to media metadata processing. It is only natural that the same folks screw up this one too.
- oblio 9y agoWhat same folks? iOS, Android and Ubuntu are not developed by the same people. More than that, it's not like these apps are actually developed by Apple, Google or Canonical. Plus you're dissing some very complex projects. I think you're underestimating the complexity of the work these "same folks" are doing.
- sotojuan 9y agoWhat about mpv? That's my preferred video player.
- m1el 9y agoWhile I too prefer mpv, I suspect that there are plenty of vulns in that player.
- Filligree 9y agoIt's written in C, so I imagine that's almost guaranteed. In this case obscurity helps to protect you, however.
- rossy 9y agompv is not affected, at least by these four vulnerabilities. They all seem to be specific to each video player, rather than affecting shared code or code in open source multimedia libraries.
- resoluti0n 9y agoKodi 17.2 with the fix for this flaw has now been released: https://kodi.tv/article/kodi-v172-minor-bug-fix-and-security-release https://kodi.tv/article/kodi-v172-minor-bug-fix-and-security...
- captainmuon 9y agoWow, that is bad. I'm always amazed by such vectors in supposedly passive formats, like fonts, images, and so on. There is no excuse that these kind of applications are not completely sandboxed. All you need is some kind of DLL, raw data in, raw pixels out. In case of hardware accelerated codecs, raw pixels in, surface pointer in, nothing out. There is no need to be able to access the filesystem, etc.. To render subtitles on top of the video it's the same. I wish a fraction of the energy we put into DRM would go into sandboxing instead.
- jbk 9y agoHa, the famous sandboxing remark. I wish it was that simple! So, let me share some light on the sandboxing for multimedia (I work on VLC). If you sandbox an application like VLC, in the current way of doing sandboxing, which we've done for macOS, WinRT/UWP, and snaps, you still need a lot of permissions. Namely: - you need to be able to open files without user interactions (no file picker), in order to open playlist, MXF or MKV files; - you need the same if ever you have a database of files (media center oriented); - you need raw access to /dev/* to play DVD, CD and other optical disk (and the equivalent on Windows); - you need ioctl on such devices, to pass the MMC for DVD/Bluray; - you need raw access to /dev/v4l* for your webcams and be able to control them; - you need access to the GPU stack, which is running in kernel-mode, btw, to output video and get hw acceleration; - you need access to the audio stack, also in low-level mode; - you need access to the DSP acceleration (not always the GPU); - on linux, you have access to x11 for the 3 above features, which is almost root; - you need access to /etc/ (registry) for proxy informations, fonts configuration and accessibility; - many OpenGL client libraries need access to the /etc too; - you need access to the network, as input and output (think remote control); - you need access to the system settings to disable screensavers, and adjust brightness; - you need access to mounts to be able to see the insertion of DVD/Bluray/USB/SD cards and such; - you need to expose an IPC (think MPRIS on Linux); - you need to unzip, untar, decrypt, decipher and so on; - you need access to the fonts and the fonts configuration (see fontconfig). and I probably forgot one or another case. The point is, all those features have good reasons to exist and very good use cases; but the issue is that for a media player, it will request almost all permissions except GPS and address book. And quite a few of them are very close to kernel mode. So, what is the solution? Probably do a multi-process media player, like Chrome is doing, with parsers and demuxers in a different process, and different ones for decoders and renderers. Knowing that you probably need to IPC several Gb/s between them. I've been working on such a prototype, but it's a lot of work... I accept donations :)
- _jomo 9y agoThese are the VLC commits adressing the issue: https://github.com/videolan/vlc/search?utf8=%E2%9C%93&q=subtitle+OR+subsdec+%22checkpoint.com%22&type=Commits https://github.com/videolan/vlc/search?utf8=%E2%9C%93&q=subt...
- pawadu 9y agoHoly crap, that code doesn't look good. I predict we will see more exploits for this project. Maybe we should stop random people from contributing to complex C projects?
- pjmlp 9y agoThat was my hope when C was just gaining market share outside UNIX, and here we stand now.
- viraptor 9y ago"random people"? You mean there's some select group we know of that doesn't ever write bugs? (DJB doesn't make a group)
- pawadu 9y agoThe main VLC developer is an amazing programmer. But if he uses his time to shave cycles off some SIMD decoding algorithm then boring things like file processing is done by random jr. developer. The problem is that boring stuff can also be very security sensitive.
- aclsid 9y agoYou are more than welcome to contribute and since you have a very strong opinion it seems you know your stuff, so go for it, nobody is charging a dime to work there in any case.
- pawadu 9y ago> you have a very strong opinion it Yes I do, this is internet after all! > seems you know your stuff, Now you lost me :)
- Sujan 9y agoDoes anyone know if the subtitle hosting services added checks for this as well?
- Sujan 9y agoDoes this also work for Android versions of Kodi et al?
- etix 9y agoAndroid does have a sandbox, so impact should be pretty limited if ever exploitable.
- thresh 9y agoClearly VLC should be rewritten in Rust.
- bmh100 9y agoWhile I think Rust would be s good choice, the project could benefit from a rewrite even in the same language.
- pjmlp 9y agoLooking at the bug fixes done in VLC, Ada or Modula-2 would be enough, although there are plenty of options actually. Rust isn't the only alternative to write native code safer than C will ever allow.
- viraptor 9y agoDon't know about Modula, but have you tried Ada? The usability of it is nowhere near modern languages IMO. We learned a lot about nice code since then :-)
- DenisM 9y agoModula 2 is much like C in it's close-to-the-metal performance abilities. On the downside, if you want to call it that, is a more prominent syntax (keywords instead of curlies, upper-case keywords, etc). On the upside it lacks any unsafe operations, except for dealloc. In addition, it has actual modules in lieu of includes, hence it's blazingly fast to compile and/or recompile. It'a a pity it didn't catch on, the language lacked a company to back and promote it. AT&T promoted C, Apple promoted Objective C, Microsoft promoted VB...
- pjmlp 9y ago> Apple promoted Objective C Actually Apple promoted Object Pascal, but then they decided to cater to the growing UNIX market and replaced the Mac OS SDK with C and C++ (PowerPlant) one. https://en.wikipedia.org/wiki/MacApp https://en.wikipedia.org/wiki/MacApp
- pawadu 9y agoSlightly related to this: where can I find data sanitizers for common file formats (PDF, MP3 and so on)?
- chii 9y agowhat counts as sanitizing? How do you know a file is malicious?
- pawadu 9y agoRead data according to spec, drop stuff that is incorrect and write it back. For example if MP3 genre field is 999 bytes long cut it down to 32 bytes.
- Piskvorrr 9y agoEspecially with PDFs, my "sanitization" can be your "stripped away all the fonts and functionality - might as well have given me a plain .TXT", and vice versa.
- rsync 9y ago"might as well have given me a plain .TXT"" Yes, please - that sounds fantastic.
- rsync 9y ago
- ConfucianNardin 9y agoWas annoying to find the details. Looks like PopcornTime was rendering subtitle text as HTML, inside their app (html/js-based), creating an XSS vector (looking at https://github.com/popcorn-official/popcorn-desktop/commit/a9aa8e16610ee8cb23ba4a6452c5a69bf88d9107 https://github.com/popcorn-official/popcorn-desktop/commit/a..., https://github.com/butterproject/butter-desktop/pull/602 https://github.com/butterproject/butter-desktop/pull/602). Likely the javascript runtime they're using allows file access and execution of arbitrary executables, enabling the metasploit shell shown in the demo. For VLC there are a bunch of out of bound reads and heap buffer overflows. f2b1f9e subtitle: Fix potential heap buffer overflow 611398f subtitle: Fix potential heap buffer overflow ecd3173 subsdec: Fix potential out of bound read 62be394 subsdec: Fix potential out of bound read 775de71 subtitle: Fix invalid double increment. The article implies that VLC and the others are affected by the same issue (leading to code execution), but according to available information it seems to be completely different issues. The Kodi issue was a zip archive path traversal (i.e. no protection against zip files extracting files to parent directories).
- jbk 9y ago> The article implies that VLC and the others are affected by the same issue (leading to code execution), but according to available information it seems to be completely different issues. Yes, those are very different issues. From what I understood, one is an XSS (popcorn-time), one is a heap-based buffer overflow (VLC), and one is a zip-transveral (Kodi). And tbh, I don't see how you can exploit the bug for VLC (with ASLR and HEASLR).
- pjmlp 9y agoEasy, you cannot count with an executable being always compiled and executed in an OS with ASLR and HEASLR enabled. So it becomes a game of luck getting some users exploited.
- driverdan 9y agoThank you! I was frustrated when I saw this last night and it didn't contain any details. I assumed buffer overflow but different attacks for each is more interesting.
- greggman 9y agoAFAICT every plugin to Kodi has full machine access. Subtitles of course you don't expect to install malware but I wish plugins ran in a sandbox
- nto 9y agodoes this work on Linux and Mac OS? or is it limited to Windows systems?
- gpvos 9y agoI can't say for these vulns specifically, but in general, if software is vulnerable on one OS, it is very likely also vulnerable on other OSs. The differences aren't that big. Exploits generally have to be written for each OS separately, though.
- jwilk 9y agoWhat does the "IPS Signatures" section mean?
- nurikolan 9y agoProtection signatures for Check Point's IPS: https://www.checkpoint.com/ips-protections-security-gateway-r75-and-above/ https://www.checkpoint.com/ips-protections-security-gateway-...
- sparaker 9y agoIt would be interesting to see which subtitles are using these vulnerabilities and what they are achieving with them. We could estimate how long this has been around.
- kutkloon7 9y agoThe thing that most amazes my about Popcorn Time is how they find the subtitles. It seems to succeed even when I can't find subtitles myself. More related to the article, you would think that subtitles are literally the easiest file format in existence to safely handle. It's incredibly well-defined in terms of textual data and times.
- etix 9y agoThey use a hash function to match subtitles. http://trac.opensubtitles.org/projects/opensubtitles/wiki/HashSourceCodes http://trac.opensubtitles.org/projects/opensubtitles/wiki/Ha...
- tydok 9y agoThe problem isn't only about matching subtitles to movies but also where to look for subtitles, e.g. opensubtitles.org, subscene.com, etc.
- lloydjatkinson 9y agoHollywood is resorting to shitty tactics
- jessaustin 9y agoI would be impressed if this were actually "Hollywood". It's better than e.g. the RIAA lawsuits.
- saagarjha 9y agoI'm not sure where you're getting this from; did you read the article?
- ackfoo 9y agoTreat data as data. Taking the Subrip format as an example, everything starts out fine so long as there is good bounds checking on the purely textual data. Then, however, some dipshit decides to extend the format by adding tags for things like bold, italics, underline etc. This is completely unnecessary for subtitles because the emphasis can be inferred from the dialogue. The unnecessary complexity increase the potential for vulnerabilities. Then some total dickhead decides to add an HTML5 tag, for no reason whatsoever, and it all goes to hell. This is illustrative of the problem with most software: the absence of a clear-headed benevolent dictator to say, "no; you are an idiot; we're not doing that."
- cbr 9y agoThis is completely unnecessary for subtitles because the emphasis can be inferred from the dialogue. Seems useful for deaf people
- emodendroket 9y agoIt also seems like you could use it for applications like karaoke.
- jbk 9y agoThen people add full BASE64 fonts inside the subtitles. Fonts that have a virtual machine in...
- dragonwriter 9y ago> Then, however, some dipshit decides to extend the format by adding tags for things like bold, italics, underline etc. This is completely unnecessary for subtitles because the emphasis can be inferred from the dialogue. Emphasis of an entire line can be inferred, but how can emphasis within a line be inferred when you don't know which utterances within the line correspond to which words in the subtitles (which, if you need subtitles because you don't know the language being spoken, you won't)? While uncommon, I've occasionally seen font variants used for emphasis on professional subtitles for that reason.
- GlobalServices 9y agoIt should be noted that Hitler's "Downfall" was caused in part by malicious subtitles.
- runeks 9y agoCan anyone recommend a video player written in a memory-safe language for OSX that handles MKV files? Or is the simple truth that the problem lies in the parsers, which are shipped as a library written in C, because no sane developer wants to rewrite parsers for 25 different subtitle formats when writing a video player?
- jbk 9y agoThere are none. You can use VLC inside VLC sandbox, but you won't get something perfect.
- deleted 9y ago[deleted]
- OneLessThing 9y agoI did security research on VLC on Windows a year or two ago. I may be remembering incorrectly, but last I recall every module was protected by ASLR. Which means that remote code execution is not likely because there is no scripting or network comms to dynamically create a valid ROP chain. I also didn't check for executable heaps at the time but given that all heaps are non executable (which they really shouldn't be executable in VLC) again I don't see how RCE is possible. Maybe there is some way to validate and therefore brute force addresses? I don't know. But there was no VLC POC and I'm sure they would have made one if they could have. Use VLC it's the most secure media player I've seen.
- foobarrio 9y agoOff topic: I love VLC but can't get it to use hardware acceleration on my late 2015 mac. 4k 60fps @ 40mbps consume all CPU if I try to play a lower compression 150mbps video it studders and all my fans turn on. mpv and quicktime play the same videos with 15-20% CPU. The poor performance of VLC on my macOS makes it a no go for me.
- jbk 9y agoTry 3.0, this is fixed.
- jbk 9y agoThat's also why we're perplexed at the supposedly code execution. Also, the security researcher did not provide a demo for the VLC exploit. Their demo is only on Kodi and popcorntime. But anyway, security issues means releases.
- yegle 9y agoROP: return oriented programming ASLR: Address space layer randomization Having ASLR is not bullet proof to remote code execution, e.g. iOS has ASLR for a long time and can still be jailbroken (which usually involves a code injection etc). The key is info leak, e.g. if you somehow can reliably find the memory location of open() syscall, the memory location of the whole libc can be inferred, and libc is usually large enough to construct a ROP chain. (I haven't work in security area for a long time so correct me if I'm wrong). The researcher unable to provide a POC for vlc could simply mean it's hard due to ASLR, but it's not impossible. Also: I believe ASLR is a compiler option (with a supported OS), it should be relatively easy for Kodi and Popcorn Time to start using ASLR.
- deleted 9y ago[deleted]
- adynatos 9y agoIf Popcorn Time renders all subtitles as HTML, would an exploit work if the subtitles were embedded in video container? Seed latest hit on Pirate Bay, root a lot of boxes. Yikes.
- Filligree 9y agoSpeaking of Popcorn Time, last I heard there were a couple of forks and doubts about the safety of each and every one. Is there any more clarity around the situation now?
- grahams 9y agoThese exploits will go nowhere without a catchy name ala HEARTBLEED... I vote for SUB-DURAL HEMATOMA
- alexvay 9y agoIt's sad that VLC checks updates over HTTP and HTTPS
- jbk 9y agoVLC updates are signed with asymetric encryption. HTTP or HTTPS does not change that.
- sslalready 9y agoHTTPS would increase user privacy by not leaking application details though.
- jbk 9y agoIndeed, but that's not what GP is referring to.
- mplewis 9y agoThis is another reason you should use a tool like a parser generator when you have to parse untrusted data, rather than writing your own parser by hand.
- lanius 9y agoIs Media Player Classic affected?
- buttcoinslol 9y agoNot according to this bug report: https://trac.mpc-hc.org/ticket/6169 https://trac.mpc-hc.org/ticket/6169
- yq 9y agohere is how it looks in real time: https://www.youtube.com/watch?v=vYT_EGty_6A https://www.youtube.com/watch?v=vYT_EGty_6A
- soylentcola 9y agoThis is interesting to me for reasons outside of anything to do with exploits or malware. A while back I had a bit of a brain fart while playing with my Hue bulbs: would there be a way to use the subtitle track for a video to encode time-controlled data that can be sent to/read by another application that sends these values to a set of Hue bulbs or similar devices for synchronized ambient lighting? I figured that subtitles were an obvious place to start because you can download them in small files, play them back alongside a video, and they are designed to be "timed out" to synchronize with a video already. I looked into it for a bit but never really found a way (within my abilities at least) to do anything like this from within a .srt file or similar. I'd be interested in hearing if anyone else has more info on how you might do more with that "framework" than displaying text on screen.