Forum
  • Search
  • Member List
  • Calendar
Hello There, Guest! Login Register — Login with Facebook
Thread Closed 
 
Thread Rating:
  • 0 Votes - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Threaded Mode | Linear Mode
Solved: Remote control vulnerability found in Kodi :(
24th May, 2017, 10:37 AM
Post: #1
Exnor Offline
Registered
Posts: 362
Joined: Aug 2013
Reputation: 8
Remote control vulnerability found in Kodi :(
According to CheckPoint Security it's possible to take remote control of any machine running Kodi up to 17.1 (and other media players also...)

I've read some comments that Kodi 17.2 source is available to compile on Github and removes this vulnerability.

Any thoughts ?

:) :)
Find all posts by this user
24th May, 2017, 11:13 AM
Post: #2
Nachteule Offline
Administrator
******
Posts: 2,405
Joined: Dec 2014
Reputation: 122
RE: Remote control vulnerability found in Kodi :(
(24th May, 2017 10:37 AM)Exnor Wrote:  According to CheckPoint Security it's possible to take remote control of any machine running Kodi up to 17.1 (and other media players also...)

I've read some comments that Kodi 17.2 source is available to compile on Github and removes this vulnerability.

Any thoughts ?

Please be patient, 17.2 has been commited 10hrs ago Smile New version will be available ASAP
Find all posts by this user
25th May, 2017, 12:50 AM
Post: #3
Exnor Offline
Registered
Posts: 362
Joined: Aug 2013
Reputation: 8
RE: Remote control vulnerability found in Kodi :(
(24th May, 2017 11:13 AM)Nachteule Wrote:  Please be patient, 17.2 has been commited 10hrs ago Smile New version will be available ASAP

Lol i'm good. I don't use subtitles Tongue I just wanted to know if you guys knew about this issue and to spread awareness about it.

:) :)
Find all posts by this user
25th May, 2017, 02:07 AM
Post: #4
Nachteule Offline
Administrator
******
Posts: 2,405
Joined: Dec 2014
Reputation: 122
RE: Remote control vulnerability found in Kodi :(
I was aware of this commit, but did not know anything about remote control of any machine running Kodi up to 17.1

But anyway, 17.2 is currently build on our vps and btw, if you're using the standard addon repos, this will never happen Dodgy
Find all posts by this user
25th May, 2017, 08:39 AM
Post: #5
Exnor Offline
Registered
Posts: 362
Joined: Aug 2013
Reputation: 8
RE: Remote control vulnerability found in Kodi :(
(25th May, 2017 02:07 AM)Nachteule Wrote:  I was aware of this commit, but did not know anything about remote control of any machine running Kodi up to 17.1

But anyway, 17.2 is currently build on our vps and btw, if you're using the standard addon repos, this will never happen Dodgy

But according to Checkpoint the vulnerability is used (exploited?) by loading an external subtitle file, they even demo using opensubtitles.org.
So even without using any addon anyone might be at risk if the subs file is "tampered" right?

:) :)
Find all posts by this user
25th May, 2017, 11:04 PM
Post: #6
Nachteule Offline
Administrator
******
Posts: 2,405
Joined: Dec 2014
Reputation: 122
RE: Remote control vulnerability found in Kodi :(
Yeah, maybe it is possible, but they did not report that this has ever happened.

For me this article sounds more like hot air Angel

Anyway, 17.2 has been built and is available for update Smile
Find all posts by this user
26th May, 2017, 09:27 AM
Post: #7
Exnor Offline
Registered
Posts: 362
Joined: Aug 2013
Reputation: 8
RE: Remote control vulnerability found in Kodi :(
Nice Smile

Well the recent ransomware based on smb bug did not happen until the exploit was made public so... it doesn't hurt to be careful right ?
Don't want my Pi being hijack to a botnet Tongue

:) :)
Find all posts by this user
6th Jun, 2017, 08:12 PM
Post: #8
katesey Offline
Newcomer
Posts: 2
Joined: May 2017
Reputation: 0
RE: Remote control vulnerability found in Kodi :(
(26th May, 2017 09:27 AM)Exnor Wrote:  Nice Smile

Well the recent ransomware based on smb bug did not happen until the exploit was made public so... it doesn't hurt to be careful right ?
Don't want my Pi being hijack to a botnet Tongue

Only last year, about six hundred thousand Britons found much of their personal information online for only £19, following a hack and the resulting data breach on the British telecommunications firm TalkTalk. The situation gets even worse since British travellers too aren’t spared by these digital fugitives. Learn More

https://www.purevpn.com/blog/how-to-protect-personal-information-online/
Find all posts by this user
5th Dec, 2022, 05:27 PM
Post: #9
sitinsidious Offline
Banned
Posts: 1
Joined: Dec 2022
RE: Remote control vulnerability found in Kodi :(
(6th Jun, 2017 08:12 PM)katesey Wrote:  Only last year, about six hundred thousand Britons found much of their personal information online for only £19, following a hack and the resulting data breach on the British telecommunications firm TalkTalk. The situation gets even worse since British travellers too aren’t spared by these digital fugitives. Learn More
basket random

https://www.purevpn.com/blog/how-to-protect-personal-information-online/
Privacy of personal information is an issue in all countries
Find all posts by this user
« Next Oldest | Next Newest »
Thread Closed 


  • View a Printable Version
  • Send this Thread to a Friend
  • Subscribe to this thread
Forum Jump:

Current time: 10th May, 2025, 08:40 AM Powered By MyBB, © 2002-2025 MyBB Group.