Web Hack List

Collected research

Exploiting Second Life

Cyber Security Consulting Services

Charlie Miller and Dino Dai Zovi exploit an unpatched QuickTime RTSP flaw through Second Life, which renders embedded media with QuickTime. Walking an avatar onto attacker-owned land with video enabled surrenders the machine; the demo makes the victim pay twelve Linden dollars and shout that she was hacked, then cash out for real money.

Record

Document
Cyber Security Consulting Services
Published by
Independent Security Evaluators
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Independent Security Evaluators, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .