→ HELLDIVER: 就覺得很奇怪 SRT應該只是文字檔 沒有執行程式的作用 05/26 20:26
推 TobyH4cker: 安安 kodi的漏洞是另一個 當然不同於字幕 05/26 21:12
你的意思是字幕檔本身也有漏洞?
推 ltyintw: 我還以為srt檔裡面可以加入URL參數,讓播放器的字幕有特 05/26 22:03
→ ltyintw: 讓播放器可以從網路下載字幕特效 05/26 22:04
→ ilanese: youtube上駭客利用字幕檔來控制對方電腦的示範,但還是不 05/26 22:39
→ ilanese: 清楚其真正原理為何? 05/26 22:39
這就原文的影片啊,
簡單的執行Kodi選擇字幕然後就被控制了,
完全沒有提到是什麼類型的字幕…
Kodi v17.2 修復說明底下還有一段就是回應 Hacked in Translation
↖ 超連結該文
You may have read in the news that malicious subtitle zip files could
potentionally infect and harm your media player including Kodi. When Check
Point researchers uncovered this flaw they contacted us up front to let us
know about this flaw. Our developers fixed this secuity gap and have added
the fix to this v17.2 release.
Kodi v17.3 https://goo.gl/A2NHyB 又追加了一段
To be clear this possible vunrability is only present when you first enable a
subtitle dowload add-on and then actually download zipped subtitles. Any
subtitles that you already have as text file, are embedded in the video
stream or are included with you DVD or Blurays are safe.
受影響的只有下載的ZIP字幕,
其他文字格式的字幕、串流影片內嵌字幕、DVD、BD都安全。
MPC-HC的回應也是人家拿 Hacked in Translation 那篇去問的,
也是提到不會從ZIP檔案中執行非字幕檔案,所以不受影響。
這樣看下來很明顯就是撥放器有漏洞去載入ZIP夾帶檔案造成的吧!
※ 編輯: mkz6 (122.116.86.145), 05/26/2017 23:39:04
推 ChakraLinux: MPC-HC: 抱歉我們的播放器太笨,所以沒中招科科 05/27 01:23
推 TobyH4cker: 我是說只有kodi是zip如你貼的那樣 06/10 12:19