Was annoying to find the details. Looks like PopcornTime was rendering subtitle text as HTML, inside their app (html/js-based), creating an XSS vector (looking at https://github.com/popcorn-official/popcorn-desktop/commit/a... , https://github.com/butterproject/butter-desktop/pull/602 ). Likely the javascript runtime they're using allows file access and execution of arbitrary executables, enabling the metasploit shel…
If only VLC had been re-written in rust this would never have happened. For shame.
Malicious Subtitles Threaten Kodi, VLC and Popcorn Time Users
191–200 of 234 posts
Re: Malicious Subtitles Threaten Kodi, VLC and Popcorn Time Users
#192Was annoying to find the details. Looks like PopcornTime was rendering subtitle text as HTML, inside their app (html/js-based), creating an XSS vector (looking at https://github.com/popcorn-official/popcorn-desktop/commit/a... , https://github.com/butterproject/butter-desktop/pull/602 ). Likely the javascript runtime they're using allows file access and execution of arbitrary executables, enabling the metasploit shel…
If only VLC had been re-written in rust this would never have happened. For shame.
Re: Malicious Subtitles Threaten Kodi, VLC and Popcorn Time Users
#193Was annoying to find the details. Looks like PopcornTime was rendering subtitle text as HTML, inside their app (html/js-based), creating an XSS vector (looking at https://github.com/popcorn-official/popcorn-desktop/commit/a... , https://github.com/butterproject/butter-desktop/pull/602 ). Likely the javascript runtime they're using allows file access and execution of arbitrary executables, enabling the metasploit shel…
If only VLC had been re-written in rust this would never have happened. For shame.
Re: Malicious Subtitles Threaten Kodi, VLC and Popcorn Time Users
#194Re: Malicious Subtitles Threaten Kodi, VLC and Popcorn Time Users
#195Earlier quoted context omitted.
If only VLC had been re-written in rust this would never have happened. For shame.
Feel free to rewrite VLC in Rust. No one is stopping you.
It is far more effective to sit on my high horse and instruct unenlightened plebs on the one true path to memory-safety.
Re: Malicious Subtitles Threaten Kodi, VLC and Popcorn Time Users
#196Earlier quoted context omitted.
vlc has a bug and yet you talk shit about well developed and fuzzed by google projects. thats why vlc will never be better than mpv.
FFmpeg, VLC, MPlayer, libdvd*, libxvid, x264, libflac, libvorbis and all the other have multimedia library codebases started in the late 90s/early 2000. Noone cared much about security at that times. All those projects are under-funded, done by volunteers, on countless platforms, doing very low-level stuff, and supporting many formats. This has nothing to do with one project or another.
Re: Malicious Subtitles Threaten Kodi, VLC and Popcorn Time Users
#197Re: Malicious Subtitles Threaten Kodi, VLC and Popcorn Time Users
#198Earlier quoted context omitted.
Those are valid reasons not to improve a project, but it doesn't make your project immune to criticism. If you're not going to take the time to make your project better, that's fine, but other people are still free to point out that your project isn't very good or that your project could be much better if you managed your time differently.
Tepix's point was about entitlement, not criticism. "There is no excuse for ___" definitely crosses the line from criticism to entitlement. :^)
Re: Malicious Subtitles Threaten Kodi, VLC and Popcorn Time Users
#199Was annoying to find the details. Looks like PopcornTime was rendering subtitle text as HTML, inside their app (html/js-based), creating an XSS vector (looking at https://github.com/popcorn-official/popcorn-desktop/commit/a... , https://github.com/butterproject/butter-desktop/pull/602 ). Likely the javascript runtime they're using allows file access and execution of arbitrary executables, enabling the metasploit shel…
If only VLC had been re-written in rust this would never have happened. For shame.
Also, you've posted many uncivil and/or unsubstantive comments. We ban accounts for that too, so please don't do that either.