<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Backdooring MP3 Files</title>
	<atom:link href="http://www.gnucitizen.org/blog/backdooring-mp3-files/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/blog/backdooring-mp3-files/</link>
	<description>Cutting-edge Think tank &#124; Ethical Hacker Outfit</description>
	<pubDate>Fri, 04 Jul 2008 17:21:02 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
		<item>
		<title>By: Mary</title>
		<link>http://www.gnucitizen.org/blog/backdooring-mp3-files/#comment-118170</link>
		<dc:creator>Mary</dc:creator>
		<pubDate>Sun, 06 Apr 2008 15:44:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-mp3-files#comment-118170</guid>
		<description>Hi, thanks. but my Kaspersky AV blocks this files :(</description>
		<content:encoded><![CDATA[<p>Hi, thanks. but my Kaspersky AV blocks this files :(</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Info World &#187; Blog Archive &#187; After attacks, Apple fixes QuickTime bug</title>
		<link>http://www.gnucitizen.org/blog/backdooring-mp3-files/#comment-86422</link>
		<dc:creator>Info World &#187; Blog Archive &#187; After attacks, Apple fixes QuickTime bug</dc:creator>
		<pubDate>Fri, 14 Dec 2007 14:14:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-mp3-files#comment-86422</guid>
		<description>[...] Media Link (QTL) file format used by the media player. Security researchers have recently been looking at the way QuickTime works with these files as a potential source of new [...]</description>
		<content:encoded><![CDATA[<p>[...] Media Link (QTL) file format used by the media player. Security researchers have recently been looking at the way QuickTime works with these files as a potential source of new [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tapasman</title>
		<link>http://www.gnucitizen.org/blog/backdooring-mp3-files/#comment-77755</link>
		<dc:creator>tapasman</dc:creator>
		<pubDate>Tue, 27 Nov 2007 17:14:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-mp3-files#comment-77755</guid>
		<description>I get a broken file, when using IE6 and QT 6.0.</description>
		<content:encoded><![CDATA[<p>I get a broken file, when using IE6 and QT 6.0.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ari</title>
		<link>http://www.gnucitizen.org/blog/backdooring-mp3-files/#comment-74719</link>
		<dc:creator>Ari</dc:creator>
		<pubDate>Tue, 20 Nov 2007 22:58:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-mp3-files#comment-74719</guid>
		<description>Nice work ! But Kaspersky AV blocks these backdoored mp3 files.</description>
		<content:encoded><![CDATA[<p>Nice work ! But Kaspersky AV blocks these backdoored mp3 files.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: IT Security mobile edition</title>
		<link>http://www.gnucitizen.org/blog/backdooring-mp3-files/#comment-49346</link>
		<dc:creator>IT Security mobile edition</dc:creator>
		<pubDate>Sat, 15 Sep 2007 13:37:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-mp3-files#comment-49346</guid>
		<description>[...] of concept exploit. The vulnerability itself, however, is apparently not newly discovered: it was first reported almost a full year ago. Unfortunately, the announcement of the proof of concept exploit misuses the term &#8220;0 day [...]</description>
		<content:encoded><![CDATA[<p>[...] of concept exploit. The vulnerability itself, however, is apparently not newly discovered: it was first reported almost a full year ago. Unfortunately, the announcement of the proof of concept exploit misuses the term &#8220;0 day [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: 0ole</title>
		<link>http://www.gnucitizen.org/blog/backdooring-mp3-files/#comment-49025</link>
		<dc:creator>0ole</dc:creator>
		<pubDate>Fri, 14 Sep 2007 11:13:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-mp3-files#comment-49025</guid>
		<description>Doesn't works on Mac OS X with the latest Quicktime updates.
Might be a Windows Quicktime only problem then.</description>
		<content:encoded><![CDATA[<p>Doesn&#8217;t works on Mac OS X with the latest Quicktime updates.<br />
Might be a Windows Quicktime only problem then.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ryan Naraine&#8217;s Zero Day mobile edition</title>
		<link>http://www.gnucitizen.org/blog/backdooring-mp3-files/#comment-48376</link>
		<dc:creator>Ryan Naraine&#8217;s Zero Day mobile edition</dc:creator>
		<pubDate>Wed, 12 Sep 2007 17:13:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-mp3-files#comment-48376</guid>
		<description>[...] released details on vulnerabilities in Apple&#8217;s QuickTime media player to show how movie and .mp3 files can be backdoored to hack into [...]</description>
		<content:encoded><![CDATA[<p>[...] released details on vulnerabilities in Apple&#8217;s QuickTime media player to show how movie and .mp3 files can be backdoored to hack into [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Severe QuickTime vulnerability in Firefox disclosed : Mozilla Links</title>
		<link>http://www.gnucitizen.org/blog/backdooring-mp3-files/#comment-48334</link>
		<dc:creator>Severe QuickTime vulnerability in Firefox disclosed : Mozilla Links</dc:creator>
		<pubDate>Wed, 12 Sep 2007 14:33:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-mp3-files#comment-48334</guid>
		<description>[...] is the third time GNUCITIZEN discloses this same vulnerability: it was initially disclosed about a year ago and again some months [...]</description>
		<content:encoded><![CDATA[<p>[...] is the third time GNUCITIZEN discloses this same vulnerability: it was initially disclosed about a year ago and again some months [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: 0DAY: QuickTime pwns Firefox &#124; GNUCITIZEN</title>
		<link>http://www.gnucitizen.org/blog/backdooring-mp3-files/#comment-48302</link>
		<dc:creator>0DAY: QuickTime pwns Firefox &#124; GNUCITIZEN</dc:creator>
		<pubDate>Wed, 12 Sep 2007 12:06:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-mp3-files#comment-48302</guid>
		<description>[...] to say a few things. Last year I disclosed two highly critical QuickTime vulnerabilities here and here. The first vulnerability was fixed but the second one was completely ignored. I tried to bring the [...]</description>
		<content:encoded><![CDATA[<p>[...] to say a few things. Last year I disclosed two highly critical QuickTime vulnerabilities here and here. The first vulnerability was fixed but the second one was completely ignored. I tried to bring the [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: yamzzz</title>
		<link>http://www.gnucitizen.org/blog/backdooring-mp3-files/#comment-2205</link>
		<dc:creator>yamzzz</dc:creator>
		<pubDate>Thu, 11 Jan 2007 07:27:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-mp3-files#comment-2205</guid>
		<description>nice!!!!!!!!!!</description>
		<content:encoded><![CDATA[<p>nice!!!!!!!!!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GNUCITIZEN &#187; DANGER, DANGER, DANGER</title>
		<link>http://www.gnucitizen.org/blog/backdooring-mp3-files/#comment-1776</link>
		<dc:creator>GNUCITIZEN &#187; DANGER, DANGER, DANGER</dc:creator>
		<pubDate>Wed, 03 Jan 2007 09:03:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-mp3-files#comment-1776</guid>
		<description>[...] The WEB has gone crazy. I know that this is not news for some of you but you will be surprised to what extend this craziness has just developed. It seams that the entire WEB is falling apart and someone has to do something otherwise we risk to lose too much. Among the traditional QuickTime Movie, QTL, Flash, Image, HTML and PDF backdoors, there is another one trivially achievable with high degree of impact. [...]</description>
		<content:encoded><![CDATA[<p>[...] The WEB has gone crazy. I know that this is not news for some of you but you will be surprised to what extend this craziness has just developed. It seams that the entire WEB is falling apart and someone has to do something otherwise we risk to lose too much. Among the traditional QuickTime Movie, QTL, Flash, Image, HTML and PDF backdoors, there is another one trivially achievable with high degree of impact. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Top Web Hacks of 2006 &#187; Hack Report</title>
		<link>http://www.gnucitizen.org/blog/backdooring-mp3-files/#comment-1740</link>
		<dc:creator>Top Web Hacks of 2006 &#187; Hack Report</dc:creator>
		<pubDate>Tue, 02 Jan 2007 03:07:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-mp3-files#comment-1740</guid>
		<description>[...] 1. Web Browser Intranet Hacking / Port Scanning - (with JavaScript and with HTML-only and the improved model) 2. Internet Explorer 7 &#8220;mhtml:&#8221; Redirection Information Disclosure 3. Anti-DNS Pinning and Circumventing Anti-Anti DNS pinning 4. Web Browser History Stealing - (with CSS, evil marketing, JS login-detection, and authenticated images) 5. Backdooring Media Files (QuickTime, Flash, PDF, Images, Word [2], and MP3&#8217;s) 6. Forging HTTP request headers with Flash 7. Exponential XSS 8. Encoding Filter Bypass (UTF-7, Variable Width, US-ASCII) 9. Web Worms - (AdultSpace, MySpace, Xanga) 10. Hacking RSS Feeds [...]</description>
		<content:encoded><![CDATA[<p>[...] 1. Web Browser Intranet Hacking / Port Scanning - (with JavaScript and with HTML-only and the improved model) 2. Internet Explorer 7 &#8220;mhtml:&#8221; Redirection Information Disclosure 3. Anti-DNS Pinning and Circumventing Anti-Anti DNS pinning 4. Web Browser History Stealing - (with CSS, evil marketing, JS login-detection, and authenticated images) 5. Backdooring Media Files (QuickTime, Flash, PDF, Images, Word [2], and MP3&#8217;s) 6. Forging HTTP request headers with Flash 7. Exponential XSS 8. Encoding Filter Bypass (UTF-7, Variable Width, US-ASCII) 9. Web Worms - (AdultSpace, MySpace, Xanga) 10. Hacking RSS Feeds [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: abcas</title>
		<link>http://www.gnucitizen.org/blog/backdooring-mp3-files/#comment-1433</link>
		<dc:creator>abcas</dc:creator>
		<pubDate>Sat, 23 Dec 2006 11:34:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-mp3-files#comment-1433</guid>
		<description>usefull cuzz it happened 2 me every tim i just explore a file with mp3 in it the explorer closes and starts again and when i scanned my comp i found the amount pf viruses = 2 the amount of songs (mp3 files) but i really cant fix it can u help me ????</description>
		<content:encoded><![CDATA[<p>usefull cuzz it happened 2 me every tim i just explore a file with mp3 in it the explorer closes and starts again and when i scanned my comp i found the amount pf viruses = 2 the amount of songs (mp3 files) but i really cant fix it can u help me ????</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Planeta cPanel &#187; Top 10 Web Hacks of 2006</title>
		<link>http://www.gnucitizen.org/blog/backdooring-mp3-files/#comment-1253</link>
		<dc:creator>Planeta cPanel &#187; Top 10 Web Hacks of 2006</dc:creator>
		<pubDate>Sat, 16 Dec 2006 02:18:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-mp3-files#comment-1253</guid>
		<description>[...] Backdooring Media Files (QuickTime, Flash, PDF, Images, Word, and MP3&#8217;s) [...]</description>
		<content:encoded><![CDATA[<p>[...] Backdooring Media Files (QuickTime, Flash, PDF, Images, Word, and MP3&#8217;s) [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GNUCITIZEN &#187; Backdooring Images</title>
		<link>http://www.gnucitizen.org/blog/backdooring-mp3-files/#comment-1236</link>
		<dc:creator>GNUCITIZEN &#187; Backdooring Images</dc:creator>
		<pubDate>Fri, 15 Dec 2006 05:02:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-mp3-files#comment-1236</guid>
		<description>[...] OK, we’ve covered how to backdoor Flash, QuickTime, QuickTime Link, PDF and simple HTML files, but we haven’t discussed how to backdoor images yet. In this post I am going to outline some of the techniques available for maliciously infecting Image (Picture) files with JavaScript code. I must worn you that what you are about to read is not intended to describe new issues but rather to clarify and provide scenarios where the discussed attack vectors can be implemented. [...]</description>
		<content:encoded><![CDATA[<p>[...] OK, we’ve covered how to backdoor Flash, QuickTime, QuickTime Link, PDF and simple HTML files, but we haven’t discussed how to backdoor images yet. In this post I am going to outline some of the techniques available for maliciously infecting Image (Picture) files with JavaScript code. I must worn you that what you are about to read is not intended to describe new issues but rather to clarify and provide scenarios where the discussed attack vectors can be implemented. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dinis Cruz Blog &#187; Blog Archive &#187; Firefox Dump</title>
		<link>http://www.gnucitizen.org/blog/backdooring-mp3-files/#comment-1231</link>
		<dc:creator>Dinis Cruz Blog &#187; Blog Archive &#187; Firefox Dump</dc:creator>
		<pubDate>Fri, 15 Dec 2006 01:29:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-mp3-files#comment-1231</guid>
		<description>[...] Backdooring MP3 Files [...]</description>
		<content:encoded><![CDATA[<p>[...] Backdooring MP3 Files [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Almonaster</title>
		<link>http://www.gnucitizen.org/blog/backdooring-mp3-files/#comment-441</link>
		<dc:creator>Almonaster</dc:creator>
		<pubDate>Thu, 02 Nov 2006 18:52:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-mp3-files#comment-441</guid>
		<description>Some more data: I gave the links a click using Firefox 1.5 - the backdoors did nothing, the genuine tune played. I use the NoScript extension, so I tried disabling that - same result.</description>
		<content:encoded><![CDATA[<p>Some more data: I gave the links a click using Firefox 1.5 - the backdoors did nothing, the genuine tune played. I use the NoScript extension, so I tried disabling that - same result.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/backdooring-mp3-files/#comment-173</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Mon, 02 Oct 2006 06:07:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-mp3-files#comment-173</guid>
		<description>this issue is also present in Windows Media Player Clasic with QuickTime Alternative. I wasn't able to execute it from the browser but there was no problem when files were opened from the desktop.</description>
		<content:encoded><![CDATA[<p>this issue is also present in Windows Media Player Clasic with QuickTime Alternative. I wasn&#8217;t able to execute it from the browser but there was no problem when files were opened from the desktop.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Omar Khan&#8217;z &#187; Backdooring MP3 Files</title>
		<link>http://www.gnucitizen.org/blog/backdooring-mp3-files/#comment-164</link>
		<dc:creator>Omar Khan&#8217;z &#187; Backdooring MP3 Files</dc:creator>
		<pubDate>Thu, 28 Sep 2006 05:08:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-mp3-files#comment-164</guid>
		<description>[...] http://www.gnucitizen.org/blog/backdooring-mp3-files/ ? [...]</description>
		<content:encoded><![CDATA[<p>[...] <a href="http://www.gnucitizen.org/blog/backdooring-mp3-files/" rel="nofollow">http://www.gnucitizen.org/blog.....mp3-files/</a> ? [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Da PingMachine.org Website &#187; Archive du blog &#187; Une backdoor dans un MP3</title>
		<link>http://www.gnucitizen.org/blog/backdooring-mp3-files/#comment-155</link>
		<dc:creator>Da PingMachine.org Website &#187; Archive du blog &#187; Une backdoor dans un MP3</dc:creator>
		<pubDate>Tue, 26 Sep 2006 13:18:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-mp3-files#comment-155</guid>
		<description>[...] Décidemment, c&#8217;est sans limites&#8230; Backdooring MP3 Files [...]</description>
		<content:encoded><![CDATA[<p>[...] Décidemment, c&#8217;est sans limites&#8230; Backdooring MP3 Files [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
