Researchers Find Yet Another Vulnerability in Quicktime - What a Surprise

Security researchers recently agreed to release undisclosed vulnerabilities in Apple and/or Mac products on a daily basis for the entire month of January. I never liked Apple’s products for the simple fact that they report home. Itunes makes you convert your MP3’s to lower quality, and who knows what information is being relayed back to apple. The most recent vulnerability found was in the famous movie player, Quicktime.

The only real way to avoid the vulnerability at this point is to:

1: Uninstall Quicktime (recommended) 2: Uninstall Quicktime 3: Avoid playing Quicktime movies from unknown or non trustworthy sources, including emails from friends & co workers. A lot of malware immediately sends itself to everyone in contact lists, so beware! 4: Did I mention uninstall Quicktime? 5: If you have to leave Quicktime installed, be sure to disable RTSP URL processing until Apple releases a patch.

I’m not sure if the program, or the movie engine itself is vulnerable, but if you perform a google search, there are several alternative which will allow you to play Quicktime movies WITHOUT installing Quicktime. US CERT has already reported a proof on concept does exist, which means this exploit is being taken advantage of. If you think you’re a victim, backup your critical data (images, mp3s, documents, NOT executables), and reinstall windows. You may think I’m kidding, but the folks at 2600 would agree with me.

Malware and Adware have come to the point where detection can be nearly impossible. Programmers can and have developed ways to hide the malicious processes, remove any indication of network traffic, and even encrypt the file & all traffic being sent to and from the client & server. If we’re fortunate enough, I’ll ask my buddy to write up an article detailing how he and a couple co-workers disassembled one of these encrypted buggers, followed through the 16 encrypted IRC networks, and eventually shocked the hell out of the botmaster himself – similar to the way Steve Gibson did, but this particular bot was way trickier.

**note: This vulnerability effects not only Mac OS X, but Windows as well! Once again, uninstall Quicktime, it’s useless.

Stay tuned for more information regarding these vulnerabilities.

Additional Posts Worth Reading

 

1 Comment »

collapse Comment by Guy Patterson
2007-07-16 17:46:53

Florida Car Audio Discussion! Find locals in Florida and Jacksonville just as interested in car audio as you. Florida Car Audio forums aims to provide moderated forums with only the best information to help you win sound pressure level competitions. For the best Florida car audio and SPL discussion, sign up and start participating today!

 
Name (required)


E-mail (required - never shown publicly)


URI - Web Site Address






Subscribe

Site of The Day

Sponsors

Categories

Recent Comments

  • Arthur: I can’t even be an Ebay affiliate. Tried various ways but still declined. Any help or suggestions?
  • chicago web design: I can’t imagine that these will last very long before Google banishes them all. But for now...
  • D.Ksyte: Anyone involved with cron job scheduling might find this resource useful. Cron Sandbox at HxPI is an...
  • FoNiX: “…decode md5″ is not possible, only bruteforce: generate hash and compare with original.
  • Z@$#: plz plz decript this hash for me any one….its really important…. 2CAD28C7C619F27DDE7B83C4999795BA
  • Joe: Thanks for writing this up. I tried the second method…however after the debian install the screen looks...
  • Scott: Was this issue ever resolved? I just started having a problem a couple weeks ago. I don’t do any kind of...
  • Prashant Patel: I had integrated Sp3 in Xp But finding one problem. In the Task Manager Process windows many services...
  • Ed: This looks like a real ‘leet’ linux command but it misses the point. Why would a hacker keep the name of...
  • Sudesh: My account was disabled but I followed their guideline and in one sec it was back on :) Here is the...

Top Commentators

Miscellaneous

  • Add to Technorati Favorites