<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Backdooring QuickTime Movies</title>
	<atom:link href="http://www.gnucitizen.org/blog/backdooring-quicktime-movies/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/blog/backdooring-quicktime-movies/</link>
	<description>Information Security Think Tank</description>
	<lastBuildDate>Sat, 02 Feb 2013 17:50:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.1</generator>
	<item>
		<title>By: Persistent Bi-directional Communication Channels &#124; GNUCITIZEN</title>
		<link>http://www.gnucitizen.org/blog/backdooring-quicktime-movies/comment-page-1/#comment-130746</link>
		<dc:creator>Persistent Bi-directional Communication Channels &#124; GNUCITIZEN</dc:creator>
		<pubDate>Wed, 11 May 2011 10:12:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-quicktime-movies#comment-130746</guid>
		<description>[...] Request Forgery and social engineering but also by altering media content such as Flash, Music and Video formats. More over this can be now done from the browser if data URLs are supported. Attackers may [...]</description>
		<content:encoded><![CDATA[<p>[...] Request Forgery and social engineering but also by altering media content such as Flash, Music and Video formats. More over this can be now done from the browser if data URLs are supported. Attackers may [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MySpace QuickTime Worm Follow-up &#124; GNUCITIZEN</title>
		<link>http://www.gnucitizen.org/blog/backdooring-quicktime-movies/comment-page-1/#comment-130630</link>
		<dc:creator>MySpace QuickTime Worm Follow-up &#124; GNUCITIZEN</dc:creator>
		<pubDate>Mon, 09 May 2011 17:01:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-quicktime-movies#comment-130630</guid>
		<description>[...] 7th, 2006 MySpace was hit by a worm in a semi-automatic manner. This time the worm propagated via a QuickTime flaw found a couple of months ago. This shouldn&#8217;t be a surprise to anyone. It is quite serious that this attack vector was [...]</description>
		<content:encoded><![CDATA[<p>[...] 7th, 2006 MySpace was hit by a worm in a semi-automatic manner. This time the worm propagated via a QuickTime flaw found a couple of months ago. This shouldn&#8217;t be a surprise to anyone. It is quite serious that this attack vector was [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Top 10 web hacks trong n&#259;m 2006 - CÃ´ng nghá»‡ sá»‘</title>
		<link>http://www.gnucitizen.org/blog/backdooring-quicktime-movies/comment-page-1/#comment-127660</link>
		<dc:creator>Top 10 web hacks trong n&#259;m 2006 - CÃ´ng nghá»‡ sá»‘</dc:creator>
		<pubDate>Thu, 30 Jul 2009 17:21:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-quicktime-movies#comment-127660</guid>
		<description>[...] Media Files (QuickTime, Flash, PDF, Images, Word [2], and [...]</description>
		<content:encoded><![CDATA[<p>[...] Media Files (QuickTime, Flash, PDF, Images, Word [2], and [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: student0911</title>
		<link>http://www.gnucitizen.org/blog/backdooring-quicktime-movies/comment-page-1/#comment-126080</link>
		<dc:creator>student0911</dc:creator>
		<pubDate>Mon, 23 Feb 2009 10:55:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-quicktime-movies#comment-126080</guid>
		<description>Whenever I read about how QuickTime makes cyberspace more scary or dangerous (JS is JS; I have JS enabled in my browser, but I won&#039;t use IE outside the LAN; I just wish I could tell my browser to not load scripts from 3rd-party servers), it reminds me that the most dangerous thing about QuickTime movies is that the site with the most best hijacker-exculpatory 9/11 video evidence, 911blimp.net, chose to use QT (because, like a VCR, it lets the viewer pause and go frame-by-frame in either direction using the keyboard arrow keys) to present its videos.  So, to the extent that people can be made to be extra reluctant to even open a .mov file, that helps keep the evidence (and danger to the actual perpetrators) as well-suppressed as it&#039;s been.

BTW, that site (like this one) uses JS, harmlessly, but its QT videos do not contain any embedded code or scripts of any kind.</description>
		<content:encoded><![CDATA[<p>Whenever I read about how QuickTime makes cyberspace more scary or dangerous (JS is JS; I have JS enabled in my browser, but I won&#8217;t use IE outside the LAN; I just wish I could tell my browser to not load scripts from 3rd-party servers), it reminds me that the most dangerous thing about QuickTime movies is that the site with the most best hijacker-exculpatory 9/11 video evidence, 911blimp.net, chose to use QT (because, like a VCR, it lets the viewer pause and go frame-by-frame in either direction using the keyboard arrow keys) to present its videos.  So, to the extent that people can be made to be extra reluctant to even open a .mov file, that helps keep the evidence (and danger to the actual perpetrators) as well-suppressed as it&#8217;s been.</p>
<p>BTW, that site (like this one) uses JS, harmlessly, but its QT videos do not contain any embedded code or scripts of any kind.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Google AJAX Feed API Dangers &#124; GNUCITIZEN</title>
		<link>http://www.gnucitizen.org/blog/backdooring-quicktime-movies/comment-page-1/#comment-125876</link>
		<dc:creator>Google AJAX Feed API Dangers &#124; GNUCITIZEN</dc:creator>
		<pubDate>Sun, 08 Feb 2009 18:30:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-quicktime-movies#comment-125876</guid>
		<description>[...] someone finds a vulnerability they need to wait for a vendor patch. For example, I released the QuickTime XSS vulnerability mainly because I knew that the issue was related to a feature rather than a bug. I [...]</description>
		<content:encoded><![CDATA[<p>[...] someone finds a vulnerability they need to wait for a vendor patch. For example, I released the QuickTime XSS vulnerability mainly because I knew that the issue was related to a feature rather than a bug. I [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: AttackAPI 0.8 is OUT &#124; GNUCITIZEN</title>
		<link>http://www.gnucitizen.org/blog/backdooring-quicktime-movies/comment-page-1/#comment-125027</link>
		<dc:creator>AttackAPI 0.8 is OUT &#124; GNUCITIZEN</dc:creator>
		<pubDate>Fri, 02 Jan 2009 10:11:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-quicktime-movies#comment-125027</guid>
		<description>[...] favorite because it redefines the boundaries of today’s computer security. Don’t open any mp3, QuickTime, PDF, or html file that you don’t trust. It might have one of these installed. Once you are [...]</description>
		<content:encoded><![CDATA[<p>[...] favorite because it redefines the boundaries of today’s computer security. Don’t open any mp3, QuickTime, PDF, or html file that you don’t trust. It might have one of these installed. Once you are [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Google Search API Worms &#124; GNUCITIZEN</title>
		<link>http://www.gnucitizen.org/blog/backdooring-quicktime-movies/comment-page-1/#comment-124982</link>
		<dc:creator>Google Search API Worms &#124; GNUCITIZEN</dc:creator>
		<pubDate>Thu, 01 Jan 2009 19:12:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-quicktime-movies#comment-124982</guid>
		<description>[...] I won&#8217;t be surprised if I see some in the near future. Malicious content in Web Pages, Flash, QuickTime and PDF has suddenly become one of the most common threats we face [...]</description>
		<content:encoded><![CDATA[<p>[...] I won&#8217;t be surprised if I see some in the near future. Malicious content in Web Pages, Flash, QuickTime and PDF has suddenly become one of the most common threats we face [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Backdooring MP3 Files &#124; GNUCITIZEN</title>
		<link>http://www.gnucitizen.org/blog/backdooring-quicktime-movies/comment-page-1/#comment-124981</link>
		<dc:creator>Backdooring MP3 Files &#124; GNUCITIZEN</dc:creator>
		<pubDate>Thu, 01 Jan 2009 18:56:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-quicktime-movies#comment-124981</guid>
		<description>[...] 2006 Recently I published information on how specially crafted HTML (remote and local), Flash and QuickTime (.mov) files can be used by malicious users to target and exploit internal and external networks. Than my [...]</description>
		<content:encoded><![CDATA[<p>[...] 2006 Recently I published information on how specially crafted HTML (remote and local), Flash and QuickTime (.mov) files can be used by malicious users to target and exploit internal and external networks. Than my [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andre</title>
		<link>http://www.gnucitizen.org/blog/backdooring-quicktime-movies/comment-page-1/#comment-72355</link>
		<dc:creator>Andre</dc:creator>
		<pubDate>Sat, 17 Nov 2007 23:21:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-quicktime-movies#comment-72355</guid>
		<description>vbx i am interesting that too.. popup on preview movie its very interesting..</description>
		<content:encoded><![CDATA[<p>vbx i am interesting that too.. popup on preview movie its very interesting..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: vbx</title>
		<link>http://www.gnucitizen.org/blog/backdooring-quicktime-movies/comment-page-1/#comment-65432</link>
		<dc:creator>vbx</dc:creator>
		<pubDate>Mon, 05 Nov 2007 16:20:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-quicktime-movies#comment-65432</guid>
		<description>would like to know if is possible to create the popup alter when the movie is previewed inside a standalone QuickTime player.</description>
		<content:encoded><![CDATA[<p>would like to know if is possible to create the popup alter when the movie is previewed inside a standalone QuickTime player.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Quicktime and Firefox vulnerability - Spyware Sucks</title>
		<link>http://www.gnucitizen.org/blog/backdooring-quicktime-movies/comment-page-1/#comment-48926</link>
		<dc:creator>Quicktime and Firefox vulnerability - Spyware Sucks</dc:creator>
		<pubDate>Thu, 13 Sep 2007 23:59:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-quicktime-movies#comment-48926</guid>
		<description>[...] on, I have to say a few things. Last year I disclosed two highly critical QuickTime vulnerabilities here and here. The first vulnerability was fixed but the second one was completely ignored. I tried to [...]</description>
		<content:encoded><![CDATA[<p>[...] on, I have to say a few things. Last year I disclosed two highly critical QuickTime vulnerabilities here and here. The first vulnerability was fixed but the second one was completely ignored. I tried to [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ryan Naraine&#8217;s Zero Day mobile edition</title>
		<link>http://www.gnucitizen.org/blog/backdooring-quicktime-movies/comment-page-1/#comment-48374</link>
		<dc:creator>Ryan Naraine&#8217;s Zero Day mobile edition</dc:creator>
		<pubDate>Wed, 12 Sep 2007 17:10:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-quicktime-movies#comment-48374</guid>
		<description>[...] (left) released details on vulnerabilities in Apple&#8217;s QuickTime media player to show how movie and .mp3 files can be backdoored to hack into [...]</description>
		<content:encoded><![CDATA[<p>[...] (left) released details on vulnerabilities in Apple&#8217;s QuickTime media player to show how movie and .mp3 files can be backdoored to hack into [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: 0DAY: QuickTime pwns Firefox &#124; GNUCITIZEN</title>
		<link>http://www.gnucitizen.org/blog/backdooring-quicktime-movies/comment-page-1/#comment-48301</link>
		<dc:creator>0DAY: QuickTime pwns Firefox &#124; GNUCITIZEN</dc:creator>
		<pubDate>Wed, 12 Sep 2007 12:06:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-quicktime-movies#comment-48301</guid>
		<description>[...] on, I have to say a few things. Last year I disclosed two highly critical QuickTime vulnerabilities here and here. The first vulnerability was fixed but the second one was completely ignored. I tried to [...]</description>
		<content:encoded><![CDATA[<p>[...] on, I have to say a few things. Last year I disclosed two highly critical QuickTime vulnerabilities here and here. The first vulnerability was fixed but the second one was completely ignored. I tried to [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: roger</title>
		<link>http://www.gnucitizen.org/blog/backdooring-quicktime-movies/comment-page-1/#comment-46172</link>
		<dc:creator>roger</dc:creator>
		<pubDate>Wed, 05 Sep 2007 18:27:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-quicktime-movies#comment-46172</guid>
		<description>yea i need this to work</description>
		<content:encoded><![CDATA[<p>yea i need this to work</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Doc</title>
		<link>http://www.gnucitizen.org/blog/backdooring-quicktime-movies/comment-page-1/#comment-44854</link>
		<dc:creator>Doc</dc:creator>
		<pubDate>Sat, 01 Sep 2007 00:52:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-quicktime-movies#comment-44854</guid>
		<description>Quote [dodgescabin responds: I never use quicktime its not very good] ???

What the f***? - Is that the dumbest sweeping statement ever? It&#039;s like saying cars are not very good - or the sky is not very good!</description>
		<content:encoded><![CDATA[<p>Quote [dodgescabin responds: I never use quicktime its not very good] ???</p>
<p>What the f***? &#8211; Is that the dumbest sweeping statement ever? It&#8217;s like saying cars are not very good &#8211; or the sky is not very good!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dodgescabin</title>
		<link>http://www.gnucitizen.org/blog/backdooring-quicktime-movies/comment-page-1/#comment-44485</link>
		<dc:creator>dodgescabin</dc:creator>
		<pubDate>Thu, 30 Aug 2007 18:37:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-quicktime-movies#comment-44485</guid>
		<description>I never use quicktime its not very good</description>
		<content:encoded><![CDATA[<p>I never use quicktime its not very good</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/backdooring-quicktime-movies/comment-page-1/#comment-27653</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Thu, 07 Jun 2007 19:09:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-quicktime-movies#comment-27653</guid>
		<description>yes... this is right... and this is how it should be</description>
		<content:encoded><![CDATA[<p>yes&#8230; this is right&#8230; and this is how it should be</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Runic</title>
		<link>http://www.gnucitizen.org/blog/backdooring-quicktime-movies/comment-page-1/#comment-27589</link>
		<dc:creator>Runic</dc:creator>
		<pubDate>Thu, 07 Jun 2007 15:20:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-quicktime-movies#comment-27589</guid>
		<description>Starting with QuickTime 7.1.5, you can no longer issue javascript&#058;// URLs or call JavaScript functions from within a QuickTime movie. This feature was removed from QuickTime for security reasons.</description>
		<content:encoded><![CDATA[<p>Starting with QuickTime 7.1.5, you can no longer issue javascript&#58;// URLs or call JavaScript functions from within a QuickTime movie. This feature was removed from QuickTime for security reasons.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sasha</title>
		<link>http://www.gnucitizen.org/blog/backdooring-quicktime-movies/comment-page-1/#comment-19742</link>
		<dc:creator>sasha</dc:creator>
		<pubDate>Fri, 04 May 2007 19:01:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-quicktime-movies#comment-19742</guid>
		<description>How can you get around websense to get to myspace</description>
		<content:encoded><![CDATA[<p>How can you get around websense to get to myspace</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cityboi</title>
		<link>http://www.gnucitizen.org/blog/backdooring-quicktime-movies/comment-page-1/#comment-16717</link>
		<dc:creator>Cityboi</dc:creator>
		<pubDate>Wed, 25 Apr 2007 13:34:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-quicktime-movies#comment-16717</guid>
		<description>How can you get around websense to get to myspace</description>
		<content:encoded><![CDATA[<p>How can you get around websense to get to myspace</p>
]]></content:encoded>
	</item>
</channel>
</rss>
