Wilders Security Forums  

Go Back   Wilders Security Forums > Software, Hardware and General Services > sandboxing & virtualization
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old August 13th, 2012, 01:44 PM
Doodler Doodler is offline
Frequent Poster
 
Join Date: Dec 2007
Posts: 204
Default Torrent questions

I download movies and tv shows (typically .avi format) from torrent web sites, usually only the 'better' ones, like KickAss Torrents...and I review the ratings and comments before selecting the torrent to try to select presumably good ones. I don't download pron (not sure if that matters).

When I download the movies, I am always sandboxed (Sandboxie). I recover those .avi's out of my sandbox to a special folder on my "real" hard drive and whenever I play those movies I do so via a sandboxed Windows Media Player or sandboxed VLC.

Other than the above, my surfing habits are very conservative and safe...and always sandboxed as well.

Questions: Can malware hide in .avi files? If so, how commonplace is it?

By asking the question, I'm trying to assess my risk factor. I also have Panda Cloud Anti Virus (free) on my Win7 system and I image it every other week.
  #2  
Old August 19th, 2012, 03:22 PM
tomazyk's Avatar
tomazyk tomazyk is offline
Frequent Poster
 
Join Date: Dec 2006
Location: Slovenia
Posts: 601
Default Re: Torrent questions

Hi!

To answer your question: yes, malware can be hidden inside avi and other media files. Usually it would be as some kind of exploit for media player. This kind of malware is IMO really rare and infection is quite unlikely.

What can you do to prevent this kind of malware:
1. Update your software - media players.
2. Open files under Sandboxie supervision (which you already do).
3. Instal EMET and enforce mitigations to media players.
4. Download torrents with good "reputation".

I don't run my torrent client under SBIE (too much data in sandbox) and also don't open files in sandboxed media player. I use only Standard user account and EMET for those files and never got any problems or infections.
I think that your security practice is safe and your risk factor is low.
__________________
ESET Nod32 AV • Sandboxie • EMET • OpenDNS
My security setup in detail
• Always remember you're unique, just like everyone else •

  #3  
Old August 20th, 2012, 12:59 PM
Doodler Doodler is offline
Frequent Poster
 
Join Date: Dec 2007
Posts: 204
Default Re: Torrent questions

Appreciate the comments, tomazyk.
 

Wilders Security Forums > Software, Hardware and General Services > sandboxing & virtualization « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 05:48 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums