4 ms·
If you load outside data into the program, it has the potential to be exploited. There is no shortage of exploits for editors, media players, etc. that only req
by sp0rk 5y ago
If you load outside data into the program, it has the potential to be exploited. There is no shortage of exploits for editors, media players, etc. that only require the victim to open a specially crafted file.
- tomc1985 5y agoWhat makes you think exploit crafters are waiting around for you to load their random JPG into an old version of Paint Shop Pro? It's not like these exploits are one-size-fits-all
- sp0rk 5y agoWaiting for victims to run your malware is not an active process. It requires no resources on the attacker's part beyond maintaining a server. Maybe it will connect to a server that has been dead for five years or maybe it's pointing towards a domain name that the attacker still maintains. Maybe instead of a trojan, it's a cryptolocker or old school destructive malware. I don't know why anybody would want to gamble with something like this. Also, some of the exploits are one-size-fits-all because they target the underlying libraries that the software is using.
- tomc1985 5y agoYes but the mechanics of exploit crafting aren't generic at the slightest. Everything is bespoke. Which means that for the random bystander the probability that your specific-combination-of-old-software-and-data being exploited is extremely low. If you've reason to be paranoid, sure. And if you're trolling old warez archives with software contemporary to the time, sure. But otherwise? The odds are too low and the possibility space too high for anyone to bother
- romwell 5y ago>Waiting for victims to run your malware is not an active process. Except that's not what we are talking about. The old piece of software here is known to not be malware. >I don't know why anybody would want to gamble with something like this. Everything you do in life is a gamble. Everything is a risk. And the risk of opening an external file in a common format that just happens to have a carefully crafted exploit for extremely uncommon, outdated software that you happen to use to open it is so, so, low, that the risk of the computer exploding in your face on power-up becomes significant compared to that. Yet people aren't deterred from booting up their machines just because there was this laptop one time that did explode.
- passivate 5y agoWell, if you're facing a targeted attack like that, there is little you can do anyway. They will survey the hardware/software you use and find/purchase a vulnerability to exploit. Its always wise to treat any software (new or old) with caution.