Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

IE users beware: RealPlayer zero-day flaw under attack
ZDNet ^ | October 19th, 2007 | Ryan Naraine

Posted on 10/19/2007 10:18:29 AM PDT by holymoly

Hackers are actively exploiting a zero-day hole in RealNetworks’ RealPlayer media player, a software program installed on tens of millions of Windows computers worldwide.

RealPlayer zero-day flaw under attack

The in-the-wild attacks, which began late last night (October 18), targets a previously unknown and unpatched ActiveX vulnerability in the way RealPlayer interacts with Microsoft’s Internet Explorer browser.

The flaw is causing drive-by malware downloads when an IE user simply browsers to a maliciously rigged Web page, according to an alert issued by anti-virus vendor Symantec.

The issue affects an ActiveX object installed by RealPlayer, accessible over the web using Internet Explorer. By instantiating the object and invoking a specific method and attacker is able to corrupt process memory and execute arbitrary code with the privileges of the browser. The attack currently known to be in-the-wild has been confirmed to download malicious code to the compromised host.

According to sources tracking this threat, the attacks are limited in nature and appear to be targeting specific organizations. Some government agencies, including NASA, have reportedly banned the use of Internet Explorer in response to this incident.

“The malware appears to be spreading through a large variety of common and highly-respected Internet sites, however it does not appear these sites are themselves infected. The affected sites are serving solely as a mechanism to attract potential victims.”

Confirmed vulnerable: RealPlayer versions 6.0.14.544, 6.0.14.550 (11 Beta), 6.0.12.1662 (10.5), 6.0.12, 6.0.11, and 6.0.10.

TEMPORARY MITIGATION:

In the absence of a patch from RealPlayer, users might want to consider uninstalling the software immediately. Or, use an alternative Web browser (Mozilla Firefox or Opera) for Web surfing.

Symantec also recommends:



TOPICS: News/Current Events; Technical
KEYWORDS: activex; ie; msie; realplayer
In the absence of a patch from RealPlayer, users might want to consider uninstalling the software immediately. Or, use an alternative Web browser...

Firefox

Opera

Seamonkey

1 posted on 10/19/2007 10:18:31 AM PDT by holymoly
[ Post Reply | Private Reply | View Replies]

To: holymoly

Or an alternate OS like Linux ;-)


2 posted on 10/19/2007 10:20:45 AM PDT by fremont_steve (Milpitas - a great place to be FROM!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: holymoly

I’ve been avoiding RealPlayer for years, for reasons I don’t even clearly recall. I think it was because they became a PITA with all their spam and reminder popups or something to that effect.


3 posted on 10/19/2007 10:22:18 AM PDT by Nervous Tick
[ Post Reply | Private Reply | To 1 | View Replies]

To: holymoly

Don’t use RealPlayer at all. I believe it’s owned by Maria Cantwell, the flaming leftist democrat in the US Senate or some other notable leftist.


4 posted on 10/19/2007 10:23:06 AM PDT by Ron in Acreage (Conservative 1st, republican sometime)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce
Hackers are actively exploiting a zero-day hole in RealNetworks’ RealPlayer media player, a software program installed on tens of millions of Windows computers worldwide.

PING

5 posted on 10/19/2007 10:23:07 AM PDT by SubGeniusX (The People have UNENUMERATED RIGHTS ... the Govt. does NOT have UNENUMERATED POWERS)
[ Post Reply | Private Reply | To 1 | View Replies]

To: holymoly

Not a problem for me- I use Firefox and never had a use for RealPlayer.


6 posted on 10/19/2007 10:24:06 AM PDT by Squawk 8888 (Is human activity causing the warming trend on Mars?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: holymoly

I haven’t touched realplayer since 2000


7 posted on 10/19/2007 10:24:09 AM PDT by Crazieman (The Democrat Party: Culture of Treason)
[ Post Reply | Private Reply | To 1 | View Replies]

To: holymoly

Use Real Alternative instead. It does not alway work. But I just figure that if a web site demands using Real player with so many better choices out there then why visit that web site. Real player is a bloated piece of spy ware. It has been so for years.


8 posted on 10/19/2007 10:25:25 AM PDT by Revel
[ Post Reply | Private Reply | To 1 | View Replies]

To: Nervous Tick

You’re not missing anything. The only thing it can do that the other players can’t is play RealMedia content. Anything on rm that’s worth playing is also available in other formats.


9 posted on 10/19/2007 10:26:15 AM PDT by Squawk 8888 (Is human activity causing the warming trend on Mars?)
[ Post Reply | Private Reply | To 3 | View Replies]

To: fremont_steve

    In hoc signo vinces!

;o)
10 posted on 10/19/2007 10:26:16 AM PDT by LIConFem (Thompson 2008. Lifetime ACU Rating: 86 -- Hunter 2008 (VP) Lifetime ACU Rating: 92)
[ Post Reply | Private Reply | To 2 | View Replies]

To: Revel

Real Alternative (Uses and old version of windows media player):

http://www.free-codecs.com/download/Real_Alternative.htm


11 posted on 10/19/2007 10:26:52 AM PDT by Revel
[ Post Reply | Private Reply | To 8 | View Replies]

To: holymoly

I don’t have to worry. I use Windows Media Player................


12 posted on 10/19/2007 10:27:57 AM PDT by Red Badger ( We don't have science, but we have consensus.......)
[ Post Reply | Private Reply | To 1 | View Replies]

To: holymoly
good thing I have version 10.5.

Or are they talking about build not version?

13 posted on 10/19/2007 10:28:06 AM PDT by Just another Joe (Warning: FReeping can be addictive and helpful to your mental health)
[ Post Reply | Private Reply | To 1 | View Replies]

To: holymoly

14 posted on 10/19/2007 10:28:29 AM PDT by mysterio
[ Post Reply | Private Reply | To 1 | View Replies]

To: holymoly

< sigh > Something to do when I get home I guess.

Yet another reason to get a Mac.


15 posted on 10/19/2007 10:28:55 AM PDT by FourtySeven (47)
[ Post Reply | Private Reply | To 1 | View Replies]

To: fremont_steve

Has nothing to do with the OS. It’s the browser specifically IE.


16 posted on 10/19/2007 10:29:19 AM PDT by tomh68
[ Post Reply | Private Reply | To 2 | View Replies]

To: holymoly

In English please? :-)

I use Firefox but IE occasionally because some websites don’t work in Firefox (like my daughter’s soccer website)—if I go to “Add/Remove Programs” what should I remove? RealPlayer by itself? Or are other aspects needing to be removed as well?

My husband HATES “MicroShaft” as he calls it, but 90% of the programs/applications I use aren’t available on Linux yet—soon though I hope!!


17 posted on 10/19/2007 10:32:29 AM PDT by pillut48 (CJ in TX --Soccer Mom and proud RUSH REPUBLICAN! WIN, FRED, WIN!!!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: holymoly

Real Player turned into malware itself years ago.


18 posted on 10/19/2007 10:33:34 AM PDT by VeniVidiVici (No buy China!!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: holymoly
# Block access to the IPs 83.149.65.105 and 66.199.254.193, as these IP addresses were observed partaking in the attack and have also been observed by honeypots perpetrating other malicious activity.
# Set the kill bit on the Class identifier (CLSID) FDC7A535-4070-4B92-A0EA-D9994BCC0DC5 (Microsoft instructions for setting kill bit).

I'm sure glad that IE is easy to use and configure than other operating systems. /sarcasm

19 posted on 10/19/2007 10:37:52 AM PDT by PAR35
[ Post Reply | Private Reply | To 1 | View Replies]

To: VeniVidiVici
Real Player turned into malware itself years ago.

Eyup. It simply became a terrible product slated more at pushing advertising.

Pretty much Windows Media or Quik Time today.
20 posted on 10/19/2007 10:39:04 AM PDT by zencat (The universe is not what it appears, nor is it something else.)
[ Post Reply | Private Reply | To 18 | View Replies]

To: Red Badger

>> I don’t have to worry. I use Windows Media Player................

LOL! Yep, no vulnerabilities there!

But I don’t want to be disrespectful of Windows Media Player because it plays a valuable role in the compu-ecosystem. Windows needs to be rebooted regularly, and the weekly Microsoft updates to WMP remind (!) me to do that.


21 posted on 10/19/2007 10:40:56 AM PDT by Nervous Tick
[ Post Reply | Private Reply | To 12 | View Replies]

To: Nervous Tick

I think it comes down to “ReadPlayer simply sucks”.


22 posted on 10/19/2007 10:41:17 AM PDT by A_Tradition_Continues (THE NEXT GENERATION CONSERVATIVE)
[ Post Reply | Private Reply | To 3 | View Replies]

To: A_Tradition_Continues
Whenever I am asked to 'tweak' or clean up a computer, I always remove Real Player unless the user has a specific reason for using it.
I've always hated real player.
There was once a time when it was a very very invasive application that was a serious pain to remove from the OS. It was quite a few years ago, but I have seen real player re-install itself with hidden installation files and a batch process set to run on startup.
23 posted on 10/19/2007 10:50:29 AM PDT by z3n
[ Post Reply | Private Reply | To 22 | View Replies]

To: holymoly

RealPlayer was a pioneer in the early days, but it got more and more bloated, and they also got into the habit of using it to install spyware and other programs on your computer without asking permission.

Very much like AOL.

Plus the fact that they are somewhere to the left of Lenin. Maria Cantwell had plenty of leftist company when she was there.


24 posted on 10/19/2007 10:55:29 AM PDT by Cicero (Marcus Tullius)
[ Post Reply | Private Reply | To 1 | View Replies]

To: pillut48
if I go to “Add/Remove Programs” what should I remove? RealPlayer by itself?

If the article is correct, that should do it.

To be honest, I haven't used RealPlayer in many, many years, since it essentially became a form of spyware. I haven't used MSIE since version 4.

BTW I sometimes use Opera for sites that don't work and/or display correctly with Firefox. You might consider giving it a try.

25 posted on 10/19/2007 10:58:13 AM PDT by holymoly (Thompson/Hunter 2008)
[ Post Reply | Private Reply | To 17 | View Replies]

To: holymoly

Our software here has repeatedly blocked this Malware stuff the past couple of days.


26 posted on 10/19/2007 11:01:14 AM PDT by Badeye ('Ron Paul joined 88 Democrats.....")
[ Post Reply | Private Reply | To 1 | View Replies]

To: LIConFem
In hoc signo vinces!

;o)

Et in hoc, quoque.


27 posted on 10/19/2007 11:26:54 AM PDT by Gorzaloon (Food imported from China = "Cesspool + Flavor-Straw")
[ Post Reply | Private Reply | To 10 | View Replies]

To: All

You need Real Player for BBC 4. Outrageous, isn’t it?


28 posted on 10/19/2007 11:27:08 AM PDT by paristwelve (.......the Laws of Nature and of Nature's God entitle them)
[ Post Reply | Private Reply | To 26 | View Replies]

To: holymoly

Interesting indeed. A few weeks back RealPlayer completely locked up on me after I was at a site that was behaving suspiciously. So, I immediately deinstalled it and ran malware cleansing ops. That was probably it. A-OK right now.


29 posted on 10/19/2007 11:58:19 AM PDT by GOP_1900AD (Stomping on "PC," destroying the Left, and smoking out faux "conservatives" - Take Back The GOP!)
[ Post Reply | Private Reply | To 1 | View Replies]

bump


30 posted on 10/19/2007 12:01:50 PM PDT by Non-Sequitur (Save Fredericksburg. Support CVBT.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: rdb3; chance33_98; Calvinist_Dark_Lord; PenguinWry; GodGunsandGuts; CyberCowboy777; Salo; Bobsat; ..

31 posted on 10/19/2007 1:11:14 PM PDT by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

To: holymoly

I don’t use RealPlayer. It’s junk, AFAICT.


32 posted on 10/19/2007 1:12:12 PM PDT by TChris (Cartels (oil, diamonds, labor) are bad. Free-market competition is good.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

Just an FYI: FireFox 2.0.0.8 is out today.


33 posted on 10/19/2007 5:09:06 PM PDT by Salo
[ Post Reply | Private Reply | To 31 | View Replies]

To: PAR35
I'm sure glad that IE is easy to use and configure than other operating systems. /sarcasm

No doubt. I should hold on to this post as a reference the next time some bozo starts talking about Linux not being "ready" for the desktop. 

Let's look at that again, shall we...

 


Symantec also recommends:

 


Yeah. Windows is  easy to use.

34 posted on 10/20/2007 12:43:16 AM PDT by zeugma (Ubuntu - Linux for human beings)
[ Post Reply | Private Reply | To 19 | View Replies]

To: zeugma

I’ve been playing with computers since the CP/M days (longer, if you count punching paper tape in basic and cards in Fortran), I manually edit my registries when needed; I’m not totally computer illiterate. But I have no idea on how to set a kill bit in XP. As for blocking ports, Symantic isn’t exactly ‘user friendly’.


35 posted on 10/20/2007 8:20:20 AM PDT by PAR35
[ Post Reply | Private Reply | To 34 | View Replies]

To: zeugma

Last night, I had my wife, who has never even seen Linux, install Ubuntu Gutsy (7.10) on an old Dell (GX-150) 128MB/10GB. When if finished she said...you mean that’s it? LOL

Yeah, Linux is too hard, and winblows is easy.


36 posted on 10/20/2007 7:07:50 PM PDT by papasmurf (sudo apt - get install FRed Thompson)
[ Post Reply | Private Reply | To 34 | View Replies]

To: pillut48
Hi.

Could you tell me some of the programs you need to use? You'd be surprised what it available, for free, to use on Linux...Ubuntu especially.

I'd be happy to search for suitable replacements for you.

Also, there are free "virtual" machines available that will run windows inside of Linux, allowing you to keep your old software. I use "VirtualBox" for my proprietary business applications. It's all point and click, too.

You can take Ubuntu Linux for a FREE test ride. Just go to Ubuntu's FREE CD program and request a free cd to be sent to you at no charge. When you get the CD, just pop it in and let it load. It's called a LIVE! CD, which means the program doesn't install anything, it runs off of the CD itself. It's a bit slower, because it's running off of the CD, but it is fully functional...you can even see all of the FREE software available and how easy it is to install FREE software.

Trust me, Ubuntu Linux is very easy to use, even the updates are easier (and safer) than windoesn't's. :)

Good luck!
37 posted on 10/20/2007 7:21:12 PM PDT by papasmurf (sudo apt - get install FRed Thompson)
[ Post Reply | Private Reply | To 17 | View Replies]

To: papasmurf

Thanks, papasmurf—the husband tried ubuntu but didn’t like it (don’t ask me why! :-) I’ve been on computers since the late 80’s, Apples and Windows—all of my applications are windows based, and there aren’t equals to the programs (graphic design, photo manipulation, movie making) that I’ve used for years, and truthfully, I just don’t have the energy to relearn new programs all over again. And yes, I’ve heard of GIMP, but it just doesn’t have what I need *yet*—who knows what the future holds? :-)


38 posted on 10/20/2007 7:40:23 PM PDT by pillut48 (CJ in TX --Soccer Mom and proud RUSH REPUBLICAN! WIN, FRED, WIN!!!)
[ Post Reply | Private Reply | To 37 | View Replies]

To: holymoly

Poor WinDoze users.... how much TIME do you spend on this kinda stuff?

Get a Mac... and you can run any windows program on Mac if you REALLY have some special need to...


39 posted on 10/20/2007 8:09:02 PM PDT by RachelFaith (Doing NOTHING... about the illegals already here IS Amnesty !!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: holymoly

RealNetworks has issued a patch for this vulnerability that users can download here - http://service.real.com/realplayer/security/191007_player/en/

For more information about these patches and how the new RealPlayer has been improved, please visit the RealPlayer blog at www.realplayer.com/blog.

Matt Spragins
Real Networks


40 posted on 10/25/2007 12:38:12 PM PDT by MattSpragins
[ Post Reply | Private Reply | To 1 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson