Security Software Zone Security Software Zone
Home Contact Us
Search in
Forum SecurityToolbox Submit Software
Security Software Zone Login
Security Software Categories
News - Articles - Reviews
Free Newsletter
Join our mailing list and receive
security software news and
advice from our experts.
Submit
  Security Software Zone » Software Reviews » General Security » Apple's QuickTime movie player flaw

Apple's QuickTime movie player flaw

Category: General Security
Published: 03/18/2007, 17:38  
Editor: Remus Zoica
 
Print article
Send to a friend
Search in reviews

A vulnerability in Apple's QuickTime movie player which makes a computer download and run a Javascript has beed discovered recently.  A MySpace account is exploiting the flaw to extract information about users visiting the page and is sending it to a remote server. The web page has an embedded invisible QuickTime video that uses one Javascript to download and execute a second Javascript, acting as a spyware program, according to the researcher, Didier Stevens. His findings can be seen at the adress http://didierstevens.wordpress.com/2007/03/12/p0wned-by-a-qt-movie/ .

McAfee VirusScan will mark the first script as malware and identify it as JS/SpaceTalk Trojan. Both the QuickTime movie file, titled tys4.mov, and the second script are downloaded from a server at profileawareness.com. That's also the site that collects the user data. When an infected site is viewed, a hidden embedded QuickTime movie is played which takes advantage of the HREF Tracks features in QuickTime to download and execute a JavaScript file from an external site. The JS/SpaceStalk is executed using a known insecure feature in QuickTime called HREF Tracks. Data about the user viewing the page is collected by the script and uploaded back to the author.As the website being communicated to is normally controlled by the malware author, any script being downloaded and executed can be remotely modified and the behavior of these new scripts altered to perform further malicious actions. Apple and MySpace both had their share of security lapses in the recent past.

Last week Apple released an update to fix a variety of bugs in QuickTime and MySpace has also solved a series of exploits which have been the result of rogue Javascripts.

For example, in 2005, a user named Samy inserted a script into his profile page that allowed him to scoop up millions of friends. And in July, a banner ad posted on the social networking site infected more than a million users with spyware.

The Register tried to contact both companies for comment but did not hear back. McAfee was the only antivirus provider to detect the script at the time he posted his finding. You can find more about the trojan at the website http://vil.nai.com/vil/content/v_141428.htm, his description being modified on 03/16/2007. The risk is considered to be low for home users. Information on the vulnerability which is being exploited can be found here: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0059

Bookmark to:
Add 'Apple's QuickTime movie player flaw' to Del.icio.us Add 'Apple's QuickTime movie player flaw' to digg Add 'Apple's QuickTime movie player flaw' to FURL Add 'Apple's QuickTime movie player flaw' to reddit Add 'Apple's QuickTime movie player flaw' to Technorati Add 'Apple's QuickTime movie player flaw' to Yahoo My Web Add 'Apple's QuickTime movie player flaw' to Stumble Upon Add 'Apple's QuickTime movie player flaw' to Google Bookmarks Add 'Apple's QuickTime movie player flaw' to RawSugar Add 'Apple's QuickTime movie player flaw' to Squidoo Add 'Apple's QuickTime movie player flaw' to Spurl Add 'Apple's QuickTime movie player flaw' to Netvouz Add 'Apple's QuickTime movie player flaw' to Rojo Add 'Apple's QuickTime movie player flaw' to Bloglines Add 'Apple's QuickTime movie player flaw' to Tailrank
Add comment
Security Software Zone is not responsible for the content of these User comments. The views and opinions expressed are those of the individual poster and not the Security Software Zone.
User comments (0):

There is no comment for this review.

 
Reviews related to Apple's QuickTime movie player flaw
 

Automatic Forwards Of Email And Adds New Administrative Controls
 VersaEdge Software LLC, an email forwarding company, announced today major new features added to the email forwarding VersaForward Service. New administrative controls allow users to control settings such as advanced text reduction, custom filtering, pausing forwarding, spam blocking, and forwarding destinations.
Read More >
04/18/2008, 11:22
 

Brand Protection Service Enhanecd by Cyveillance
 The world leader in cyber intelligence, Cyveillance, announced that it has added industry leading malware protection capabilities to its Cyveillance Brand Protection™ service. These enhancements safeguard Internet users from Web sites, blogs, and other online channels that criminals leverage to distribute malware and attract visitors through unauthorized use of well-known brands.
Read More >
08/25/2008, 12:41
 

Joseph J. Grano, Jr. in the Board of Directors at Ethoca
     The leader in collaborative fraud management, Ethoca, announced today the appointment of Joseph J. Grano, Jr., former chairman and CEO of UBS PaineWebber and former chairman of the U.S. Homeland Security Advisory Council to the company's board of directors.
Read More >
03/11/2008, 17:50
 

Easy access your computer's Windows password settings.
 Elcomsoft System Recovery is completely self-contained, allowing you to access each of your computers without the need for third-party or proprietary software.
Read More >
03/13/2007, 18:37
 

Best home router password protection - Casual Webattack could target personal home routers
 Researchers say attackers could take over home router using JavaScript code.If you haven't changed the password on your home router, you should do it now!
Read More >
02/23/2007, 16:34

Sponsored