Category
Film
Tv show
Documentary
Stand-up Comedy
Short Film
View All
Genres
Action
Adventure
Animation
Biography
Comedy
Crime
Documentary
Drama
Family
Fantasy
Film-Noir
Game-Show
History
Horror
Kids
Music
Musical
Mystery
News
Reality-TV
Political
Romance
Sci-Fi
Social
Sports
Talk-Show
Thriller
War
Western
View All
Language
Hindi
Telugu
Tamil
Malayalam
Kannada
Abkhazian
Afar
Afrikaans
Akan
Albanian
Amharic
Arabic
Aragonese
Armenian
Assamese
Avaric
Avestan
Aymara
Azerbaijani
Bambara
Bashkir
Basque
Belarusian
Bengali
Bhojpuri
Bislama
Bosnian
Breton
Bulgarian
Burmese
Cantonese
Catalan
Chamorro
Chechen
Chichewa; Nyanja
Chuvash
Cornish
Corsican
Cree
Croatian
Czech
Danish
Divehi
Dutch
Dzongkha
English
Esperanto
Estonian
Ewe
Faroese
Fijian
Finnish
French
Frisian
Fulah
Gaelic
Galician
Ganda
Georgian
German
Greek
Guarani
Gujarati
Haitian; Haitian Creole
Haryanvi
Hausa
Hebrew
Herero
Hiri Motu
Hungarian
Icelandic
Ido
Igbo
Indonesian
Interlingua
Interlingue
Inuktitut
Inupiaq
Irish
Italian
Japanese
Javanese
Kalaallisut
Kanuri
Kashmiri
Kazakh
Khmer
Kikuyu
Kinyarwanda
Kirghiz
Komi
Kongo
Korean
Kuanyama
Kurdish
Lao
Latin
Latvian
Letzeburgesch
Limburgish
Lingala
Lithuanian
Luba-Katanga
Macedonian
Malagasy
Malay
Maltese
Mandarin
Manipuri
Manx
Maori
Marathi
Marshall
Moldavian
Mongolian
Nauru
Navajo
Ndebele
Ndonga
Nepali
Northern Sami
Norwegian
Norwegian Bokmål
Norwegian Nynorsk
Occitan
Ojibwa
Oriya
Oromo
Ossetian; Ossetic
Other
Pali
Persian
Polish
Portuguese
Punjabi
Pushto
Quechua
Raeto-Romance
Rajasthani
Romanian
Rundi
Russian
Samoan
Sango
Sanskrit
Sardinian
Serbian
Serbo-Croatian
Shona
Sindhi
Sinhalese
Slavic
Slovak
Slovenian
Somali
Sotho
Spanish
Sundanese
Swahili
Swati
Swedish
Tagalog
Tahitian
Tajik
Tatar
Thai
Tibetan
Tigrinya
Tonga
Tsonga
Tswana
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Venda
Vietnamese
Volapük
Walloon
Welsh
Wolof
Xhosa
Yi
Yiddish
Yoruba
Zhuang
Zulu
View All
Release year
2026
1900
Rating
Good
Satisfactory
Passable
Poor
Skip
Yet to Review
View All
Platform
Addatimes platform logo
ALT Balaji platform logo
Aha Video platform logo
Airtel Xstream platform logo
Amazon platform logo
Apple Tv Plus platform logo
Book My Show platform logo
Crunchyroll platform logo
Curiosity Stream platform logo
Discovery Plus platform logo
Jio Hotstar platform logo
Epic On platform logo
ErosNow platform logo
Film Rise platform logo
Firstshows platform logo
Gemplex platform logo
Google Play platform logo
GudSho platform logo
GuideDoc platform logo
Hoichoi platform logo
Hungama platform logo
Jio Cinema platform logo
KLiKK platform logo
Koode platform logo
Mubi platform logo
MX Player platform logo
Lionsgate Play platform logo
Manorama MAX platform logo
Movie Saints platform logo
Nee Stream platform logo
Netflix platform logo
Oho Gujarati platform logo
Planet Marathi OTT platform logo
Rooster Teeth platform logo
Roots Video platform logo
Saina Play platform logo
Shemaroo Me platform logo
Shreyas ET platform logo
Simply South platform logo
Sony LIV platform logo
Spark OTT platform logo
Sun NXT platform logo
TVFPlay platform logo
Tata Sky platform logo
Tubi platform logo
ULLU platform logo
Viki platform logo
Viu platform logo
Voot platform logo
Youtube platform logo
Yupp Tv platform logo
Zee Plex platform logo
Zee5 platform logo
iTunes platform logo
Other platform logo
ETV Win platform logo
Chaupal platform logo
Ultra Jhakaas platform logo
Tentkotta platform logo
Ultra Play platform logo
View All
Close icon
Search

Major Security Bug Found in This Streaming Platform’s System

By Binged Bureau - Jul 10, 2020 @ 04:07 pm
Major Security Bug Found in This Streaming Platform’s System

Major-Security-Bug-Found-in-This-Streaming-Platform's-SystemDavid Wells at Tenable Research recently discovered a critical security vulnerability in MXPlayer an Indian video player app and OTT platform. The platform’s penetration in the market can be gauged by the fact that it has over 500M downloads on Google Play. The app originally was only a media file player but after being acquired by Times Internet it became a free online content streaming platform.

The app makes it to the list of most used video streaming platform in India and that is more so the reason of concern with the finding of the vulnerability. The issue is not in the video streaming service but the MX Transfer feature that the app provides for wireless transfer of media content. According to Wells, this video sharing feature is a direct phone-to-phone file sharing feature which had a path traversal vulnerability in it.

According to the report, “MX Player transfers video files between two phones by setting one of the phones (“receiver”) into hotspot mode, while the other phone (“sender”) authenticates via shared password and sends the video over this connection. When the receiver puts their phone in “Hotspot” mode, the password for this Hotspot is base64 encoded and broadcasted publicly as a discoverable bluetooth device. This means if an attacker is within the receiver’s bluetooth range, the password to the phone’s Hotspot can be compromised”. This is known as ‘Remote code execution vulnerability’.

Since MX Players file transfer protocol allows multiple files to be transferred in a single session it offers a gateway for the interloper to barge in and transfer files that carries malware payload. These files or applications can be controlled remotely and can be used to install other files, snoop or steal private files stored on the device and send them to remote servers belonging to the hackers.

This test was performed using Android smartphones Pixel 3 and Pixel 3 XL. However, it was not disclosed whether the iOS version of MXPlayer was vulnerable to remote code exploit or not.

Very little vendor communication on patch progress and updates was received from MXPlayer when the security research firm disclosed the vulnerability issue to them. Although later on the path traversal issue was found fixed in the v1.24.5 update released on July 6.

It is advisable that all those who gave MXPlayer installed in their phones to update it manually to the latest version available ASAP.

We’re hiring!

We are hiring two full-time junior to mid-level writers with the option to work remotely. You need to work a 5-hour shift and be available to write. Interested candidates should email their sample articles to [email protected]. Applications without a sample article will not be considered.