Showing posts with label exploit. Show all posts
Showing posts with label exploit. Show all posts

Thursday, September 22, 2022

"Media on A Prim" Weakness To Griefing Discovered

 
 It seems the griefers have discovered an exploit in the viewer, and once again the people at Linden Lab, and Firestorm, have to take care of it. While it looked worse than it actually was, it did cause some worry.

A few days ago in the forums, the following was posted in the forums: "New Form of Griefing?"

Today I was at a rental office and noticed a few people hanging around the welcome area, thought nothing of it then suddenly and simultaneously my viewer (Latest Firestorm) opened up search and some offensive words appeared in the text box, as well as a "create new group" window, with some errors appearing on the screen. I quickly left and closed out all these windows.  It was quite a scary experience and I was only one click away from clicking the OK to create a random group at a 100l$ cost.

The post was made by an AmerAaron, who doesn't post on the forums often. And that wasn't the only incident. Earlier in the month, a Stenelaide posted about an incident at a music event.

So tonight I was halfway through my shift as a hostess in a live music venue and I suddenly crashed. I log back in and this mess pops up on my screen, on the singer's screen and on her manager's. A search bar with a nice statement, a friend request and a voice call to the singer. They also managed to block her on my behalf and they asked me to teleport to some random piece of mainland. The owner found two scripts that were dropped. That was awful, how do they manage to execute stuff on our viewer? Is that simple?

After several posts by concerned forum readers, there was finally a response by Whirly Fizzle of Firestorm.

... this form of griefing has been popping up over the last few days. It uses media on a prim (MOAP) to open those floaters on your screen.

If you disable media in the viewer, it will stop it.

Linden Lab issued an emergency ModalHotfix viewer to fix this on Thursday: https://releasenotes.secondlife.com/viewer/6.6.4.575022.html

Firestorm Viewer will have a new beta viewer out, hopefully tomorrow with the fix.
To pick up the Firestorm Beta, please join the "Phoenix-Firestorm Preview Group" & the beta will be sent out in the group notice.

This problem affects all viewers that don't yet have the Linden Lab patch. 

Whirly would go on to say the bug was more annoying than dangerous.

It's just a clever use of viewer media.

Though it seems very scary, all that can be done on unpatched viewers is open up any viewer floater on your screen when the media loads, plus enter custom text into the search window or TOS window etc.

Obviously I don't want to explain how it's done before everyone has the fix. I wish I could because then it would be less scary when you see what 's actually happening. All I will say is the media is not actually directing to an web page at all & it's actually using supported functions in the viewer. I'm surprised no griefer thought of using it this way before. 
 
So please don't worry - it's extremely annoying but ultimately harmless.

I suspect LL patched it quickly because it was causing lots of worry to those that had been hit with it, understandably.
 
 Checking the Phoenix-Firestorm Preview group, there was a new beta viewer that was released just a few days ago, Firestorm Beta build 6.6.5.68062. Checking further on the wiki entry, they had added some features related to the issue.
 
  • Fixed media on a prim looping when it should not.
  • Fixed audio from media on a prim (MOAP) begins to play if object is put into edit mode
  • Fixed the Search floater opening without appropriate search results after performing a search from the NavBar

So it seems the annoyance is on it's way to being solved, though it may be some time before the feature gets put into an official viewer update.

Hat Tip: Cynthia Farshore

Picture by Stenelaide
 
Addition: story at New World Notes 

Bixyl Shuftan

Saturday, May 13, 2017

"Unprecedented" Cyberattack Hits Thousands of Computers In 99 Countries



A massive cyberattack has hit at least 75,000 computers in 99 countries in the past few days. Described as "unprecedented" in scale, the attacks have been infecting both individuals and institutions from home computers to government agencies to businesses to hospitals. In Great Britian alone, at least 48 hospitals, clinics, and other health institutions were affected. Although some surgeries were postponed, there are no reports of deaths yet related to the hacking.

Reports of the malware, called "WannaCry" began coming in on Friday. What happens io infected computers is the files are locked and a picture appears on the screen demanding $300 US dollars worth of Bitcoin within three days for the key to unlock the computer. Unlike typical malware attacks that rely on tricking computer users into opening email attachments or clicking on links, WannaCry is a worm that attacks computers through active online connections through vulnerabilities in system software. WannaCry locks up files, looks for other vulnerable computers to infect, then deletes itself. Most computer experts recommend treating the files as lost, with only the backup files on external hard drives, if any, as recoverable. It is not recommended that people pay the criminals as in past cases of ransomware, the criminals almost never provided any key to recover lost files. It is believed that the reason Bitcoin is the method of payment demanded is because it's transactions can't be traced.

In an ironic twist, the worm may be based on a spyware tool created by the NSA to snoop on people's computers, designed to take advantages of vulnerabilities in Windows software that it had discovered. The program was leaked in April by computer hackers whom had discovered it. The agency will neither confirm or deny their program had anything to do with WannaCry. A lawyer for the American Civil Liberties Union called this "deeply troubling," saying the NSA should have notified Microsoft of the vulnerabilities instead of taking advantage of them, "These attacks underscore the fact that vulnerabilities will be exploited not just by our security agencies, but by hackers and criminals around the world. Patching security holes immediately, not stockpiling them, is the best way to make everyone's digital life safer." Others put the blame less on the NSA and more on institutions for being too slow to update systems, the attack happening two months after Microsoft had a patch available.

One British computer security blogger halted one strain of the malware by accident. Known as "Malware Tech," he decided to investigate the attack, and after an all-night session noticed the strain was trying to contact a specific web address every time it infected a new system. Seeing it was unregistered, he bought it for eight Pounds ($10.69 USD) to see where the attacks were happening. But in doing se, he accidentally triggered a "kill switch" for the strain. But there are still other strains of the worm out there.




A reminder that the computer world is full of dangers.

Sources: BBC, Arstechnica, Nerdgasm

Bixyl Shuftan

Thursday, August 22, 2013

Is Facebook Deleting Second Life Users? Not Many


Last week, some Second Life users of Facebook were worried when there were whispers going around about accounts of Second Life users being deleted. While there seems to be some truth to this, the number seems relatively small. Of the fans of the Second Life Newser page, the number of "Likes" went down by about ten, or about 2 percent of the total.

The issue came up before two years ago when more residents expressed alarm over what to some seemed like a purge of Facebook users using their Second Life names. The issues are much the same now as then: Second Life users either insisting on Internet anonymity or posting under their SL names because that's what they were known as online vs Facebook being *the* social site on the Internet and having an inconsistently enforced policy that people use their "real names," even if everything the user posts about was done under a virtual identity.

Much of the responses are the same now as then, from "just change the name," to accusations of bait and switch. Hamlet Au of New World Notes recommended instead of using account names as Facebook names, create a page for the Second Life account name. He also suggested since Second Life co-founder Cory Ondrejka has become one of Facebook's top engineers and "brought over about had a oxen other Linden engineers to the Facebook team, … any … attention Second Life gets from Facebook's higher ups is more likely to be positive than negative." Facebook itself insists they do not go looking for people to delete, but that most accounts that are taken offline are from complaints by other users.

For yours truly, most of what I post is about Second Life, very little about real life activities, and so my name on the billion member social site remains what it is. It's simpler that way. Also, the number of fans on the Newser page has been growing again. So it appears the deletions are over, for now.



On another note, Facebook recently made International News. A Khalil Shreateh tried to alert them about a weak spot in their security. But he was ignored. His response, using the exploit to post on CEO Mark Zuckerberg's page about the weakness. Naturally, the response came within minutes.

Although there is a million US dollar reward for pointing out vulnerabilities, Facebook refuses to pay Shreateh. The official reason is that he violated the TOS. But as Shreateh is a Palestinian, perhaps Zuckerberg didn't want to appear to be sending money to the antagonists of Israel, America's best friend in the Middle East. Since then however, Shreateh has reportedly gotten a number of IT job offers, plus a sum of money raised by supporters in an effort organized by cybersecurity company BeyondTrust.



Sources: New World Notes, Venturebeat


Bixyl Shuftan