apple
Report a problem

QuickTime hack allows Second Life currency theft

Steven Parker   on 05 December 2007 - 11:10 · 7 comments & 5237 views

Advertisement (Why?)
Security researchers Dino Dai Zovi and Charlie Miller have found a way to exploit an unpatched QuickTime vulnerability to steal Linden Dollars from users in the Second Life virtual world.

Dai Zovi (the hacker behind the CanSecWest MacBook Pro hijack) and Miller (creator of the first iPhone code execution exploit) cooked up the QuickTime/Second Life attack during an investigation of the security of online games.

It works against QuickTime 7.3 (the latest) and Second Life 1.18.4(3).”All the victim has to do is have video enabled and enter a piece of land owned by the attacker,” Miller said, noting that any Second Life player wandering near the attacker will have their pockets picked and then yell “I got hacked!”

View: Full Article @ ZDNet Zero Day

Post a comment · Send to friend Comments · There are 7 additional comments
#1 williamhook on 05 Dec 2007 - 11:20
Typo.

It works against QuickTime 7.3 (the latest) and Second Life 1.18.4(3).”All the victim has to do is have video enabled and enter a piece of land owned by the attacker,” Miller said, nothing that any Second Life player wandering near the attacker will have their pockets picked and then yell “I got hacked!”

That "h" should not be there.
(1 reply) #2 Beastage on 05 Dec 2007 - 11:57
And these are the guys that code the world's "greatest os"
#2.1 guruparan on 05 Dec 2007 - 15:54
Quote - (Beastage said @ #2)
And these are the guys that code the world's "greatest os"


lol
(1 reply) #3 RAID 0 on 05 Dec 2007 - 19:19
For the love of God! Is there ANYTHING this program can't exploit?
#3.1 Tzimisce on 05 Dec 2007 - 21:54
+1
#4 billyea on 06 Dec 2007 - 02:57
It explains all the problems of this world now!
#5 whocares78 on 07 Dec 2007 - 00:11
"it just works" when it works, when it doesn't it just lets hackers in

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)