<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: 0DAY: QuickTime pwns Firefox</title>
	<atom:link href="http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox/</link>
	<description>Information Security Think Tank</description>
	<pubDate>Fri, 21 Nov 2008 20:28:04 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.3</generator>
		<item>
		<title>By: Google Chrome Options &#124; GNUCITIZEN</title>
		<link>http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox/#comment-123763</link>
		<dc:creator>Google Chrome Options &#124; GNUCITIZEN</dc:creator>
		<pubDate>Thu, 18 Sep 2008 13:50:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox#comment-123763</guid>
		<description>[...] far too many applications that misbehave when launching links. QuickTime is one of them. Remember QuickTime Pwns Firfox? Mozilla has discontinued the -chrome command line option in order to prevent similar attacks from [...]</description>
		<content:encoded><![CDATA[<p>[...] far too many applications that misbehave when launching links. QuickTime is one of them. Remember QuickTime Pwns Firfox? Mozilla has discontinued the -chrome command line option in order to prevent similar attacks from [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: More on GIFARS and Other Dangerous Attacks &#124; GNUCITIZEN</title>
		<link>http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox/#comment-123180</link>
		<dc:creator>More on GIFARS and Other Dangerous Attacks &#124; GNUCITIZEN</dc:creator>
		<pubDate>Mon, 04 Aug 2008 06:45:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox#comment-123180</guid>
		<description>[...] way you look at it, SUN has to do something about the issue. Perhaps, what Firefox did to prevent this exploit from working.   &#187; more &#124; &#187; comments rss &#124; posted by pdp &#124; syndication and [...]</description>
		<content:encoded><![CDATA[<p>[...] way you look at it, SUN has to do something about the issue. Perhaps, what Firefox did to prevent this exploit from working.   &raquo; more | &raquo; comments rss | posted by pdp | syndication and [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: radioxid</title>
		<link>http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox/#comment-118391</link>
		<dc:creator>radioxid</dc:creator>
		<pubDate>Tue, 08 Apr 2008 13:05:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox#comment-118391</guid>
		<description>The alert doesn't work anymore on FF 20013...</description>
		<content:encoded><![CDATA[<p>The alert doesn&#8217;t work anymore on FF 20013&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sachinKT</title>
		<link>http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox/#comment-115935</link>
		<dc:creator>sachinKT</dc:creator>
		<pubDate>Wed, 05 Mar 2008 18:33:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox#comment-115935</guid>
		<description>i dont know but some hacks are not working...</description>
		<content:encoded><![CDATA[<p>i dont know but some hacks are not working&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Technology latest news &#187; Blog Archive &#187; Mozilla fixes QuickTime flaw in Firefox (InfoWorld)</title>
		<link>http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox/#comment-115752</link>
		<dc:creator>Technology latest news &#187; Blog Archive &#187; Mozilla fixes QuickTime flaw in Firefox (InfoWorld)</dc:creator>
		<pubDate>Sat, 01 Mar 2008 09:39:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox#comment-115752</guid>
		<description>[...] bug in the way the Firefox browser works with QuickTime media files.       The flaw, which was reported last week by hacker Petko Petkov, gives attackers a way to run unauthorized commands on a [...]</description>
		<content:encoded><![CDATA[<p>[...] bug in the way the Firefox browser works with QuickTime media files.       The flaw, which was reported last week by hacker Petko Petkov, gives attackers a way to run unauthorized commands on a [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tapasman</title>
		<link>http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox/#comment-77761</link>
		<dc:creator>tapasman</dc:creator>
		<pubDate>Tue, 27 Nov 2007 17:30:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox#comment-77761</guid>
		<description>opps IE 6 and QT 6.0</description>
		<content:encoded><![CDATA[<p>opps IE 6 and QT 6.0</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tapasman</title>
		<link>http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox/#comment-77760</link>
		<dc:creator>tapasman</dc:creator>
		<pubDate>Tue, 27 Nov 2007 17:29:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox#comment-77760</guid>
		<description>sweet so none of these execute on my system,*shaking fist ala Homer* unless you have something hidden. thanks for the info and sorry you did not get credit for it. I know how you feel I have discovered close to 10 new unknown virueses and hacks and got no credit, oh well atleast my co-workers know.</description>
		<content:encoded><![CDATA[<p>sweet so none of these execute on my system,*shaking fist ala Homer* unless you have something hidden. thanks for the info and sorry you did not get credit for it. I know how you feel I have discovered close to 10 new unknown virueses and hacks and got no credit, oh well atleast my co-workers know.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pissedoff?</title>
		<link>http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox/#comment-75869</link>
		<dc:creator>pissedoff?</dc:creator>
		<pubDate>Fri, 23 Nov 2007 09:24:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox#comment-75869</guid>
		<description>your beyonce is not malicious?what about this received by AV?:

Threat: Bloodhound.Exploit.161</description>
		<content:encoded><![CDATA[<p>your beyonce is not malicious?what about this received by AV?:</p>
<p>Threat: Bloodhound.Exploit.161</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Assyren</title>
		<link>http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox/#comment-73920</link>
		<dc:creator>Assyren</dc:creator>
		<pubDate>Mon, 19 Nov 2007 20:46:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox#comment-73920</guid>
		<description>IÂ´m using Windows XP sp2 IE
but itÂ´s not working the song 1.mp3 is runing but the calc.exe is not working i use this code 






what should i change so it will work ?
thanx</description>
		<content:encoded><![CDATA[<p>IÂ´m using Windows XP sp2 IE<br />
but itÂ´s not working the song 1.mp3 is runing but the calc.exe is not working i use this code </p>
<p>what should i change so it will work ?<br />
thanx</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Francoise MAHENC</title>
		<link>http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox/#comment-66385</link>
		<dc:creator>Francoise MAHENC</dc:creator>
		<pubDate>Tue, 06 Nov 2007 21:56:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox#comment-66385</guid>
		<description>What do I do now? One week ago, I got a Trojan, my Word documents were erratic, the Firewall antivirus detected nothing..MS were of no help beyond checking that my softwares were legal. I first got a paid Plus version of my AdAware, which promptly got erratic too, but detected and deleted a MRU. After I had tried to watch a YouTube [professional] video, I had noticed a QT icone come out of nowhere [my son installed iTunes on my laptop, which I never use - and Yes, I browse as an administrator, not knowing any better].  After AdAware, I also switched to Firefox, feeling fed-up with MS generally, and from checking on NoScript, I now got on your QT bug page - it tallies. WHAT DO I DO NOW? I guess this is of no interest to you [except as further proof on Windows users being morons!]but please direct me to people who can answer me: you are the only source of clear information I could get till now. Sorry to bother you, thank you for your activity - and thank you in advance if you can direct me. Francoise Mahenc</description>
		<content:encoded><![CDATA[<p>What do I do now? One week ago, I got a Trojan, my Word documents were erratic, the Firewall antivirus detected nothing..MS were of no help beyond checking that my softwares were legal. I first got a paid Plus version of my AdAware, which promptly got erratic too, but detected and deleted a MRU. After I had tried to watch a YouTube [professional] video, I had noticed a QT icone come out of nowhere [my son installed iTunes on my laptop, which I never use - and Yes, I browse as an administrator, not knowing any better].  After AdAware, I also switched to Firefox, feeling fed-up with MS generally, and from checking on NoScript, I now got on your QT bug page - it tallies. WHAT DO I DO NOW? I guess this is of no interest to you [except as further proof on Windows users being morons!]but please direct me to people who can answer me: you are the only source of clear information I could get till now. Sorry to bother you, thank you for your activity - and thank you in advance if you can direct me. Francoise Mahenc</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tech News &#187; Blog Archive &#187; Firefox Update Patches Quicktime Flaw</title>
		<link>http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox/#comment-65561</link>
		<dc:creator>Tech News &#187; Blog Archive &#187; Firefox Update Patches Quicktime Flaw</dc:creator>
		<pubDate>Mon, 05 Nov 2007 20:53:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox#comment-65561</guid>
		<description>[...] flaw is technically in Quicktime and affects the Internet Explorer as well, though Petkov says on his blog that IEâ€™s security policies make the flaw less [...]</description>
		<content:encoded><![CDATA[<p>[...] flaw is technically in Quicktime and affects the Internet Explorer as well, though Petkov says on his blog that IEâ€™s security policies make the flaw less [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alanat News &#187; Unpatched QuickTime Bug Threatens Firefox</title>
		<link>http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox/#comment-64453</link>
		<dc:creator>Alanat News &#187; Unpatched QuickTime Bug Threatens Firefox</dc:creator>
		<pubDate>Fri, 02 Nov 2007 23:14:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox#comment-64453</guid>
		<description>[...] D. Petkov, a penetration tester, &#171;www.gnucitizen.org&#187; that the &#8220;vulnerability can lead to a full compromise of the browser and maybe even [...]</description>
		<content:encoded><![CDATA[<p>[...] D. Petkov, a penetration tester, &laquo;www.gnucitizen.org&raquo; that the &#8220;vulnerability can lead to a full compromise of the browser and maybe even [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Oldboy</title>
		<link>http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox/#comment-61235</link>
		<dc:creator>Oldboy</dc:creator>
		<pubDate>Wed, 24 Oct 2007 20:31:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox#comment-61235</guid>
		<description>Real through this vulnerability to load exe through the URL?</description>
		<content:encoded><![CDATA[<p>Real through this vulnerability to load exe through the URL?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Firefox 2.0.0.7 QuickTime-related Issue &#124; Slaptijack</title>
		<link>http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox/#comment-59656</link>
		<dc:creator>Firefox 2.0.0.7 QuickTime-related Issue &#124; Slaptijack</dc:creator>
		<pubDate>Fri, 19 Oct 2007 17:43:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox#comment-59656</guid>
		<description>[...] issue, first reported by Petko D. Petkov, could allow a remote attacker to launch Firefox with the privileges of the local user. This would [...]</description>
		<content:encoded><![CDATA[<p>[...] issue, first reported by Petko D. Petkov, could allow a remote attacker to launch Firefox with the privileges of the local user. This would [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: More on the URI Protocol Handing Flaw (WinXP+IE7) &#171; Visible Procrastinations</title>
		<link>http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox/#comment-57396</link>
		<dc:creator>More on the URI Protocol Handing Flaw (WinXP+IE7) &#171; Visible Procrastinations</dc:creator>
		<pubDate>Fri, 12 Oct 2007 03:02:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox#comment-57396</guid>
		<description>[...] Flaw&#160;(WinXP+IE7)   Published October 12th, 2007   microsoft , security       First we had the Quick time QTL/URI issue, then the Acrobat URI and rumors of more exploits which were all 3rd party problems from the [...]</description>
		<content:encoded><![CDATA[<p>[...] Flaw&nbsp;(WinXP+IE7)   Published October 12th, 2007   microsoft , security       First we had the Quick time QTL/URI issue, then the Acrobat URI and rumors of more exploits which were all 3rd party problems from the [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: electrobrain &#187; Blog Archive &#187; Schwachstelle im &#8216;QuickTime-Plugin&#8217;</title>
		<link>http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox/#comment-56624</link>
		<dc:creator>electrobrain &#187; Blog Archive &#187; Schwachstelle im &#8216;QuickTime-Plugin&#8217;</dc:creator>
		<pubDate>Tue, 09 Oct 2007 08:20:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox#comment-56624</guid>
		<description>[...] Originalmeldung: http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox [...]</description>
		<content:encoded><![CDATA[<p>[...] Originalmeldung: <a href="http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox" rel="nofollow">http://www.gnucitizen.org/blog.....ns-firefox</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Two Updates + Two Unpatched Vulnerabilities&#160;-&#160;TrendLabs &#124; Malware Blog - by Trend Micro</title>
		<link>http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox/#comment-56416</link>
		<dc:creator>Two Updates + Two Unpatched Vulnerabilities&#160;-&#160;TrendLabs &#124; Malware Blog - by Trend Micro</dc:creator>
		<pubDate>Mon, 08 Oct 2007 16:48:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox#comment-56416</guid>
		<description>[...] the latest QuickTime version 7.2.0.240 (still unpatched). Related Links: Mozilla Vulnerability Page Petko D. Petkov&#8217;s Blog CVE [...]</description>
		<content:encoded><![CDATA[<p>[...] the latest QuickTime version 7.2.0.240 (still unpatched). Related Links: Mozilla Vulnerability Page Petko D. Petkov&#8217;s Blog CVE [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Apple fixes Quicktime flaw on Windows Vista, XP - VISTA.BLORGE.com</title>
		<link>http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox/#comment-54976</link>
		<dc:creator>Apple fixes Quicktime flaw on Windows Vista, XP - VISTA.BLORGE.com</dc:creator>
		<pubDate>Thu, 04 Oct 2007 08:39:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox#comment-54976</guid>
		<description>[...] situation prompted Petkov to post proof-of-concept exploit in his blog last month. According to Petkov, â€œthe result of this vulnerability can lead to full compromise of [...]</description>
		<content:encoded><![CDATA[<p>[...] situation prompted Petkov to post proof-of-concept exploit in his blog last month. According to Petkov, â€œthe result of this vulnerability can lead to full compromise of [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: je</title>
		<link>http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox/#comment-53743</link>
		<dc:creator>je</dc:creator>
		<pubDate>Sat, 29 Sep 2007 15:37:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox#comment-53743</guid>
		<description>This was fixed with the release of version 2.0.0.7, though.</description>
		<content:encoded><![CDATA[<p>This was fixed with the release of version 2.0.0.7, though.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: T e c h n o L o g i c &#187; 2.0.0.7: Firefoxâ€™a QuickTime yamasÄ±</title>
		<link>http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox/#comment-53456</link>
		<dc:creator>T e c h n o L o g i c &#187; 2.0.0.7: Firefoxâ€™a QuickTime yamasÄ±</dc:creator>
		<pubDate>Fri, 28 Sep 2007 16:53:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox#comment-53456</guid>
		<description>[...] aÃ§Ä±ÄŸÄ±nÄ± yamÄ±yor. GeÃ§en hafta Petko Petkov isimli bir bilgisayar korsanÄ± tarafÄ±ndan tespit edilen ve Firefoxâ€™un QuickTime media dosyalarÄ±yla Ã§alÄ±ÅŸmasÄ± sÄ±rasÄ±nda ortaya Ã§Ä±kan kritik [...]</description>
		<content:encoded><![CDATA[<p>[...] aÃ§Ä±ÄŸÄ±nÄ± yamÄ±yor. GeÃ§en hafta Petko Petkov isimli bir bilgisayar korsanÄ± tarafÄ±ndan tespit edilen ve Firefoxâ€™un QuickTime media dosyalarÄ±yla Ã§alÄ±ÅŸmasÄ± sÄ±rasÄ±nda ortaya Ã§Ä±kan kritik [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
