EntropiaForum.com
Go Back   EntropiaForum.com > Information > About Entropia Universe > Security
Notice
Security Discussion relation to Entropia Universe account security.

Reply
 
LinkBack Thread Tools
Old 02-17-2008, 16:49   #1
Young
YoBuk Weak  
  Activity Longevity
0/2015/20
Posts: 14
Gender: Male Ingame: Male
Avatar Name:
Yewall 'Yo' Buk
Soc: Shadow of the Beast
EFD: 1,606.34
Reputation: Weak
Fame: 0 Achievements: 0
Exploiting QuickTime flaws in 'TWMNBN'

I saw this article on a hacking conference that says money can be lifted off avatars using a streaming video flaw. Since EU also uses streaming video for ads the same hack could be used here. I'm turning off streaming video until MA or some tech people here on the forum look into.

Streaming Media vulnerability

Buk

Last edited by YoBuk; 02-17-2008 at 16:51. Reason: fix URL
YoBuk is offline Reply With Quote
Old 02-17-2008, 16:57   #2
711
EntropiaForum Owner/Admin
711's Avatar
711 Outstanding711 Outstanding711 Outstanding711 Outstanding711 Outstanding711 Outstanding711 Outstanding711 Outstanding711 Outstanding711 Outstanding711 Outstanding711 Outstanding711 Outstanding711 Outstanding711 Outstanding711 Outstanding711 Outstanding  
  Activity Longevity
6/2012/20
Posts: 3,190
Blog Entries: 5
Gender: Male Ingame: Male
Location: EntropiaForum
EFD: 167,452.01
Reputation: Outstanding
Fame: 15 Achievements: 2
Flower

Quote:
Originally Posted by YoBuk View Post
I saw this article on a hacking conference that says money can be lifted off avatars using a streaming video flaw. Since EU also uses streaming video for ads the same hack could be used here. I'm turning off streaming video until MA or some tech people here on the forum look into.

Streaming Media vulnerability

Buk
As far as I know Entropia does not use any Quicktime technology, but rather Bink Video, so I don't think this is really a concern for EntropiaUniverse participants.
711 is offline Reply With Quote
Old 02-17-2008, 17:01   #3
Old Alpha
Casay's Avatar
Casay AbleCasay AbleCasay AbleCasay AbleCasay AbleCasay AbleCasay AbleCasay AbleCasay Able  
  Activity Longevity
4/2013/20
Posts: 838
Gender: Female Ingame: Female
Avatar Name:
Casay Casay Onyx
Soc: Damage Inc.
Location: USA
EFD: 10,786.75
Reputation: Able
Fame: 660 Achievements: 9
Style: Zychion Battle
Medicine

Quote:
Originally Posted by 711 View Post
As far as I know Entropia does not use any Quicktime technology, but rather Bink Video, so I don't think this is really a concern for EntropiaUniverse participants.
Thanks for clarifying for us and putting minds at ease so fast!
Casay is offline Reply With Quote
Old 02-17-2008, 17:06   #4
Young
YoBuk Weak  
  Activity Longevity
0/2015/20
Posts: 14
Gender: Male Ingame: Male
Avatar Name:
Yewall 'Yo' Buk
Soc: Shadow of the Beast
EFD: 1,606.34
Reputation: Weak
Fame: 0 Achievements: 0

Thanks for the reply 711, I went to the Wiki link you gave preparing to feel all better, but the last sentence made me feel it would be even easier to hack then Quick time.

"The codec places emphasis on lower decoding requirements over other video codecs with specific optimizations for the different computer game consoles it supports"

Last edited by YoBuk; 02-17-2008 at 17:06. Reason: speling
YoBuk is offline Reply With Quote
Old 02-17-2008, 17:09   #5
Guardian
Dura Killer Poor  
  Activity Longevity
1/205/20
Posts: 281
Gender: Male Ingame: Male
Location: India breathing Entropia
EFD: 500.64
Reputation: Poor
Fame: 8 Achievements: 1

Videos are stored on servers in EU & then the videos gets streamed to the client in EU.
SL is completely different environment & as 711 said EU uses Bink.
__________________
Dura Killer is offline Reply With Quote
Old 02-17-2008, 17:19   #6
Elite
EntropiaForum Senior Member, click here for more information.
aridash Advancedaridash Advancedaridash Advancedaridash Advancedaridash Advancedaridash Advancedaridash Advancedaridash Advancedaridash Advancedaridash Advancedaridash Advancedaridash Advancedaridash Advancedaridash Advanced  
  Activity Longevity
9/2016/20
Posts: 4,554
Gender: Male Ingame: Male
Soc: Skillin' Villains
Location: United Kingdom of Great Britain and Northern Ireland
EFD: 47,712.70
Reputation: Advanced
Fame: 2 Achievements: 2
Adj Stark

even if media were streamed using Quicktime, i dont think this would have any direct impact since we dont have the user generated content in EU that SL does. You cant access someones Ped card as you might in SL to take a payment for a service.

Everyone should be far more concerned about the use of this Quicktime vulnerability for general virus/trojan/keyloggers. If you have Quicktime get patched asap and be carefull where quicktime movies come from before opening.
__________________
OFFICIALLY a Pirate

consider a cockup before a conspiracy
aridash is offline Reply With Quote
Old 02-17-2008, 17:20   #7
711
EntropiaForum Owner/Admin
711's Avatar
711 Outstanding711 Outstanding711 Outstanding711 Outstanding711 Outstanding711 Outstanding711 Outstanding711 Outstanding711 Outstanding711 Outstanding711 Outstanding711 Outstanding711 Outstanding711 Outstanding711 Outstanding711 Outstanding711 Outstanding  
  Activity Longevity
6/2012/20
Posts: 3,190
Blog Entries: 5
Gender: Male Ingame: Male
Location: EntropiaForum
EFD: 167,452.01
Reputation: Outstanding
Fame: 15 Achievements: 2
Flower

Quote:
Originally Posted by YoBuk View Post
Thanks for the reply 711, I went to the Wiki link you gave preparing to feel all better, but the last sentence made me feel it would be even easier to hack then Quick time.

"The codec places emphasis on lower decoding requirements over other video codecs with specific optimizations for the different computer game consoles it supports"
Well, consider the other parts of the article:

Bink technology has been used in over 3600 games, and there have not been any reports of major issues related to hacking as the article you provided describes.

I would thus say your concerns about the potential of an EU avatar being hacked via this method pretty unlikely, especially considering that the database transactions are probably totally unrelated to avatar and video animations.


Quote:
Originally Posted by aridash View Post
Everyone should be far more concerned about the use of this Quicktime vulnerability for general virus/trojan/keyloggers. If you have Quicktime get patched asap and be carefull where quicktime movies come from before opening.
Good point aridash. It is much more likely that someone gets hacked via some other vulnerability (e.g. this Quicktime alert), which could allow a trojan or keylogger to be installed, and ultimately potentially compromise one's EU username and passwords.

As always, security best practices should always be employed on any PC used for monetary or highly sensitive communications. Further, every participant in EU with an avatar worth more than say 1000 PED should invest in a Gold Card to increase the security of their account.
711 is offline Reply With Quote
Old 02-17-2008, 18:00   #8
Young
YoBuk Weak  
  Activity Longevity
0/2015/20
Posts: 14
Gender: Male Ingame: Male
Avatar Name:
Yewall 'Yo' Buk
Soc: Shadow of the Beast
EFD: 1,606.34
Reputation: Weak
Fame: 0 Achievements: 0

Thanks, its all good to know, the article really surprised me at how game code could be manipulated from a object and infect the avatar.

EU's has a more secure approach, PED cards are Own Avatar activated and Video Streams from their servers.
YoBuk is offline Reply With Quote
Reply

Bookmarks

Thread Tools
 
EntropiaTracker.com Loot Trends
Hunting Loot: - -12.92 % Mining Loot: + 19.9 % Crafting Loot: - -19.14 %

~ Entropia Universe | Entropia Radio | Entropia Wiki | Entropia Tracker | Entropians IM ~

All times are GMT. The time now is 21:35. | Calypso Time: 21:35

Copyright ©2005 - 2008, EntropiaForum.com.
Entropia Universe is a registered trademark of Mindark PE AB.
All other copyrights and trademarks are property of their respective owners.
Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.