7 ms·
I don't care how broad your definition is, it shouldn't include the mp4 files in my hard drive.
by kwonkicker 5y ago
I don't care how broad your definition is, it shouldn't include the mp4 files in my hard drive.
- geofft 5y agoEr, doesn't that assume that the mp4 files on your hard drive can't genuinely be infected with viruses? Why is that assumption true?
- Xylakant 5y agoEspecially given how common media files are as an attack vector.
- gruez 5y agoAre they? Compared to other forms (eg. trojans or browser/os 0days) they're not really common. I suspect you have a better chance of getting infected from a site asking you to download a "codec", than you have of the site serving you a malformed media file.
- Xylakant 5y agohttps://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=jpeg https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=jpeg returns 390 results. And that’s jpeg alone. It’s fairly common that you see some sort of media file format parsing bug to lead to command execution.
- gruez 5y agoBut how many of those are actually exploited, and how does that compare to the other vectors I mentioned? Media file exploits seem in same class of exploits as spectre/rowhammer. You hear about them often (not as often as spectre/rowhammer, but I frequently see security fixes being mentioned in media player changelogs), but you rarely hear about attacks that use them.
- anthk 5y agopledge(4)ing an image or video viewer under OpenBSD doesn't look difficult at all. Also, you can convert your PNG images to Farbleld (+.gz | +.xz) without losing quality. And the farbleld image format it's more difficult to exploit.
- geofft 5y agoI think running pledge(2) on Windows is quite difficult. :) (At least, I'm assuming the question here is "What should Windows Defender do?" I agree that the answer to "What should OpenBSD's built-in antivirus do?" is "Literally not even exist," which it already does.)
- npteljes 5y agoHow so? Everything that's interacted with by a computer can be exploited - in case of media files, here's[0] one example that gets talked about. I understand your frustration about flagging your harmless files as malicious, but it really shows just how difficult is to properly detect malware. [0] https://security.stackexchange.com/questions/97856/can-simply-decompressing-a-jpeg-image-trigger-an-exploit https://security.stackexchange.com/questions/97856/can-simpl...
- magicalhippo 5y agoI think most users would be happy to avoid getting infected via content files like videos and pictures[1][2]. Us power users can always just configure the exception list. [1]: https://docs.microsoft.com/en-us/security-updates/SecurityBulletins/2008/ms08-052 https://docs.microsoft.com/en-us/security-updates/SecurityBu... [2]: https://www.kb.cert.org/vuls/id/297462 https://www.kb.cert.org/vuls/id/297462