OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
[Full-disclosure] Bug in RealPlayer Plus 11

From: fabio ejp (fabioejpyahoo.com)
Date: Tue Dec 22 2009 - 14:43:55 CST


It's possible to execute a local aplication when using RealPlayer Plus 11 Browser. The problem resides in the file rp*****.exe which is loaded everytime a page is viewed.
 
Redirecting this filename with IFEO or overwriting the file makes it possible to execute already installed malware.
 
Note: This is material for new worms since they are on every boot nowadays.
 
Hacxx
http://achada-madeira.olx.pt/item_page.php?Id=63790302&g=6

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/