Turn off your subtitles

Post Reply
jachin99

Posts: 1294
Joined: Wed Feb 24, 2016 3:36 pm
Location:

HTPC Specs: Show details

Turn off your subtitles

#1

Post by jachin99 » Wed May 24, 2017 7:07 pm

Someone is spreading malware through subtitles. I had a thought the other day about how do I really know I can trust the metadata being downloaded from the internet? Don't get me wrong, I'm still going to do it but this at least made me think I should look into the various sources of information that metadata providers get their information from. The good news for us is that the site doesn't list WMC as an effected program.

http://blog.checkpoint.com/2017/05/23/h ... anslation/

User avatar
Crash2009

Posts: 4357
Joined: Thu May 17, 2012 12:38 am
Location: Ann Arbor, Michigan

HTPC Specs: Show details

#2

Post by Crash2009 » Fri May 26, 2017 6:18 am

As I recall, my subtitles turn on when I mute the sound. Must be somewhere to disable them if you chose to.

User avatar
mcewinter

Posts: 999
Joined: Thu Jun 30, 2011 8:33 pm
Location: Chicago

HTPC Specs: Show details

#3

Post by mcewinter » Fri May 26, 2017 12:06 pm

I'm pretty sure the players affected actually download the subtitles which excludes MC since they're sourced locally.

Space

Posts: 2840
Joined: Sun Jun 02, 2013 9:44 pm
Location:

HTPC Specs: Show details

#4

Post by Space » Fri May 26, 2017 3:26 pm

Crash2009 wrote:As I recall, my subtitles turn on when I mute the sound. Must be somewhere to disable them if you chose to.
Subtitles are not the same as Closed Captions. Closed Captions would probably not be affected by this, unless hackers somehow break in to the cable company or network and mess with them in the source video. And even if they could do that, Closed Captions are more simple than subtitles and probably would not have the more complicated coding that makes these exploits possible (although the use of common code may still makes them vulnerable).

This exploit is primarily with subtitles that are downloaded from third party websites, since usually anyone can upload subtitles for any show to those sites (and you end up downloading those subtitle either manually or automatically for use with your ripped/downloaded videos). If someone with malicious intent uploads a specially crafted subtitle file to one of those sites, and you download it and use it, that is where your system can be compromised.

Just because WMC was not mentioned does not mean it is not vulnerable to this. But it doesn't mean it is either... People don't usually spend time testing for vulnerabilities in "abandoned" software such as WMC.

Post Reply