Web Hack List

Other nomination

Exploiting Second Life

Charlie Miller and Dino Dai Zovi exploit an unpatched QuickTime RTSP flaw through Second Life, which renders embedded media with QuickTime. Walking an avatar onto attacker-owned land with video enabled surrenders the machine; the demo makes the victim pay twelve Linden dollars and shout that she was hacked, then cash out for real money.

Record

Published by
Independent Security Evaluators

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Independent Security Evaluators, first published at the original source. Preserved copies are kept so the citation survives its host.