Report: RealPlayer Under Attack

LOS ANGELES – Security experts are warning of a massive and coordinated attack by Chinese hackers currently underway that uses malicious code to exploit a serious vulnerability in the RealPlayer platform.

While RealPlayer is not as widely used on adult entertainment websites as are other video technologies, such as Windows Media Player and Adobe’s Flash Video, the attack is still cause for concern amongst website operators.

The vulnerability was reported by security expert Evgeny Legerov of GLEG Ltd., and according to SANS’ Scott Fendley involves “JavaScript obfuscations, multiple I-frame redirectors to and from internal pages, and scripts within the domains.”

An unspecified error that can cause a buffer overflow in the handling of playlist names is blamed for the vulnerability, which can allow remote hackers to execute arbitrary code; inflict denial of service attacks; or even completely control affected systems.

There is currently no reported remedy for this vulnerability other than limiting user’s multimedia playback to systems other than RealPlayer.

According to SANS, the attacks are coming from files named 0.js and r.htm, and hosted on the uc8010.com, ucmal.com and rnmb.net domains; although files and domains are subject to change as the problem is being pursued.

Blocking these domains is highly recommended, as is removing the RealPlayer software.

“The campaign's success entirely relies on the eventual presence of RealPlayer on the infected machine,” Dancho Danchev, an Internet security consultant, said.

According to SANS, the embedded exploits are turning up on social networking sites such as MySpace and have compromised numerous websites, including governmental and educational sites, as well as the website of security software vendor CA.

Related:  

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Report: UK Moving Ahead with Plan to Outlaw 'Choking' Content

The BBC and other sources are reporting that the U.K. government will follow through on criminalizing “choking” content, a plan that was announced earlier this year.

Italy to Require Age Verification for Adult Sites

Italian media regulator AGCOM has announced that all sites and platforms hosting adult content will be required to implement age verification systems starting Nov. 12 to prevent access by users under 18.

'MILFlicious' Launches Through YourPaysitePartner

MILFlicious.com has officially launched through YourPaysitePartner (YPP).

Op-Ed: The Guardian's XBIZ Amsterdam Podcast Dismisses Creators' Experiences

British newspaper The Guardian’s podcast coverage of XBIZ Amsterdam 2025 purports to investigate the power dynamics of today’s online adult industry. Instead, it ignores creators’ voices, airs tired and outdated preconceptions about the business, and rehashes the unsupported claims of anti-pornography crusaders.

Eva Maxim, BranditScan Launch 'Killer' Promo

Eva Maxim and BranditScan have partnered for the Killer Creator Giveaway promotion.

2026 XBIZ Exec Awards Nominees for Online Industry Announced

XBIZ is pleased to announce the nominees for the online industry edition of the 2026 XBIZ Exec Awards, set to be presented as part of the annual XBIZ Honors ceremony on Wednesday, Jan. 14 in conjunction with the XBIZ 2026 digital media conference.

AEBN Publishes Report on POV Trends

AEBN has published a report on POV and gonzo categories from its straight and gay theaters.

Joybear Pictures to Launch 'I Really Love' Studio Imprint

Joybear Pictures has announced that its new studio imprint, I Really Love, will launch in January.

Pineapple Support to Host 'Life Transitions' Support Group

Pineapple Support is hosting a free online support group on navigating transitional and liminal spaces.

CamSoda Launches 'Trick or Tease' AI Companions

CamSoda has launched its Halloween-themed Trick or Tease AI companions.

Show More