HomeSecurityBlu-rays are not safe

Blu-rays are not safe

Blu-ray

British hacker Stephen Tomkinson has found two ways of camouflaged attacks through the well-known and popular Blu-ray discs.

The first method relies on a Java implementation within CyberLink's popular PowerDVD software. PowerDVD plays DVDs on computers and creates menus using Java, but the way it uses Oracle code allows it to bypass Windows security checks.

The result, as the NCC team consultant reports, is that it is possible to insert executable files into Blu-ray discs so that they run automatically at startup, even when this command has been disabled by Windows security settings.

Users have no reason to suspect that the disc with the movie spinning in their drive is running some malicious script that puts their system at risk.

The second method borrows part of hacker Malcom Stagg's Blu-ray rooting , which exploits the capabilities of the debugger code to boot from an external USB. A Java Xlet can be used to play a TCP stream in net.inf.

"From here we can put a script in to run executable files from the otherwise limited environment of Blu-ray," says Tomkinson.

Of course, one must first determine the model of DVD player that the system has installed, which is easy if one sees a computer security report.

Tomkinson's advice to users is to avoid playing Blu-ray discs from unofficial sources and of course to have auto-play disabled and not allow Internet connection for extra material that may be available in the options menu.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS