Report: RealPlayer Under Attack

LOS ANGELES – Security experts are warning of a massive and coordinated attack by Chinese hackers currently underway that uses malicious code to exploit a serious vulnerability in the RealPlayer platform.

While RealPlayer is not as widely used on adult entertainment websites as are other video technologies, such as Windows Media Player and Adobe’s Flash Video, the attack is still cause for concern amongst website operators.

The vulnerability was reported by security expert Evgeny Legerov of GLEG Ltd., and according to SANS’ Scott Fendley involves “JavaScript obfuscations, multiple I-frame redirectors to and from internal pages, and scripts within the domains.”

An unspecified error that can cause a buffer overflow in the handling of playlist names is blamed for the vulnerability, which can allow remote hackers to execute arbitrary code; inflict denial of service attacks; or even completely control affected systems.

There is currently no reported remedy for this vulnerability other than limiting user’s multimedia playback to systems other than RealPlayer.

According to SANS, the attacks are coming from files named 0.js and r.htm, and hosted on the uc8010.com, ucmal.com and rnmb.net domains; although files and domains are subject to change as the problem is being pursued.

Blocking these domains is highly recommended, as is removing the RealPlayer software.

“The campaign's success entirely relies on the eventual presence of RealPlayer on the infected machine,” Dancho Danchev, an Internet security consultant, said.

According to SANS, the embedded exploits are turning up on social networking sites such as MySpace and have compromised numerous websites, including governmental and educational sites, as well as the website of security software vendor CA.

Related:  

Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

MyMember.site Integrates FSC's 'PrivateAV' Age Verification Solution

MyMember.site has integrated Free Speech Coalition's PrivateAV age verification tool into its website-building platform.

Pearl Industry Network Launches Creator Networking App Beta

Industry trade group Pearl Industry Network (PiN) has launched beta testing for the PiN Member App, a networking and collaboration tool for content creators.

FSC: W.V. Age Verification Law Takes Effect June 12

The Free Speech Coalition has issued a reminder notice that West Virginia's age verification law takes effect on June 12, 2026.

Pineapple Support Taps Brad Mitchell, Jean-Micheal Veen for Senior Leadership Positions

Pineapple Support has named Brad Mitchell as its new board president and Jean-Micheal Veen as technology and development chair.

Polish Government Proposes AV Mandate for Adult Sites

Poland’s Council of Ministers on Tuesday endorsed a proposed national law that would require sites and platforms to age-verify users to prevent minors from accessing adult content online.

Brazil Launches Complaints Page for AV Violations

Brazil’s National Data Protection Authority (ANPD) on Monday debuted a portal where citizens can report possible violations of the country’s Digital Statute for Children and Adolescents (Digital ECA), which requires adult websites to age-verify users located in Brazil.

FSC Launches 'Speak Out' Media Campaign for Creators

The Free Speech Coalition (FSC) has announced the launch of FSC Speak Out, a media campaign for content creators to tell their stories.

Pineapple Support, Stripchat to Host LGBTQ Support Group

Pineapple Support and Stripchat are hosting a free online support group for LGBTQ+ individuals within the adult industry, titled "LGBTQ and Proud."

Pornhub Awards Fiesta: A Night of Music, Dancing and Camaraderie

The eighth annual Pornhub Awards transformed Los Candiles Night Club in Glassell Park into a celebration of glamour, glitter, fashion and fame Wednesday night, as performers, creators and industry insiders toasted the year’s winners and danced late into the night while Diplo and Midnight Mary kept the party pulsing from behind the decks.

Ukrainian Parliament Rejects Porn Decriminalization Bill

The Verkhovna Rada, Ukraine’s parliament, on Thursday voted against passage of a bill that would have decriminalized the creation and distribution of pornography in that country — an activity that currently carries a prison sentence of three to five years.

Show More