Security analysts descover serious exploit in Second Life

Posted Dec 2, 2007 at 2:55PM by QJ Staff Listed in: Titles, News Tags: Linden Lab
Ó


Second Life players, be warned: security analysts have spotted a serious exploit in Linden Lab's highly-popular Second Life. This exploit is rooted in Apple's third-party QuickTime media player, which can be used to embed media files into Second Life objects.

Without sounding too tech-y, here's what the exploit does: once a victim plays the malicious media file altered to hack Second Life avatars, the hacker is not only granted complete access to the victim's Second Life avatar, but also to the victim's computer as well.

You can check out the video at the bottom of this article to see an example of how the attacker freezes the victim's avatar and manipulates the hapless victim into handing out 12 Linden Dollars.

The security analysts as Security Evaluators have notified Second Life about this exploit. Until it is patched, it is recommended not to use the QuickTime application, and uncheck the "Play Streaming Video When Available" option in the Preferences' Audio & Video section.



Via Security Evaluators

Comments

No Comments, be the first to Comment

Add New Comment




You must be logged in to post comments




 
 
 
Add QJ.NET
Add to My Yahoo!
Google Reader Subscribe with Bloglines
Add  to your Kinja digest Subscribe in NewsGator Online
Subscribe with Pluck RSS reader Add 'www.qj.net' to Newsburst from CNET News.com
Subscribe with SearchFox RSS del.icio.us www.qj.net
Add to Technorati Favorite! Add to My AOL
furl! it Stumble for Treehugger!