<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Backdooring QuickTime Movies</title>
	<atom:link href="http://www.gnucitizen.org/blog/backdooring-quicktime-movies/feed/" rel="self" type="application/rss+xml" />
	<link>/blog/backdooring-quicktime-movies/</link>
	<description>Information Security Think Tank</description>
	<pubDate>Thu, 21 Aug 2008 19:30:47 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.1</generator>
		<item>
		<title>By: Andre</title>
		<link>/blog/backdooring-quicktime-movies/#comment-72355</link>
		<dc:creator>Andre</dc:creator>
		<pubDate>Sat, 17 Nov 2007 23:21:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-quicktime-movies#comment-72355</guid>
		<description>vbx i am interesting that too.. popup on preview movie its very interesting..</description>
		<content:encoded><![CDATA[<p>vbx i am interesting that too.. popup on preview movie its very interesting..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: vbx</title>
		<link>/blog/backdooring-quicktime-movies/#comment-65432</link>
		<dc:creator>vbx</dc:creator>
		<pubDate>Mon, 05 Nov 2007 16:20:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-quicktime-movies#comment-65432</guid>
		<description>would like to know if is possible to create the popup alter when the movie is previewed inside a standalone QuickTime player.</description>
		<content:encoded><![CDATA[<p>would like to know if is possible to create the popup alter when the movie is previewed inside a standalone QuickTime player.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Quicktime and Firefox vulnerability - Spyware Sucks</title>
		<link>/blog/backdooring-quicktime-movies/#comment-48926</link>
		<dc:creator>Quicktime and Firefox vulnerability - Spyware Sucks</dc:creator>
		<pubDate>Thu, 13 Sep 2007 23:59:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-quicktime-movies#comment-48926</guid>
		<description>[...] on, I have to say a few things. Last year I disclosed two highly critical QuickTime vulnerabilities here and here. The first vulnerability was fixed but the second one was completely ignored. I tried to [...]</description>
		<content:encoded><![CDATA[<p>[...] on, I have to say a few things. Last year I disclosed two highly critical QuickTime vulnerabilities here and here. The first vulnerability was fixed but the second one was completely ignored. I tried to [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ryan Naraine&#8217;s Zero Day mobile edition</title>
		<link>/blog/backdooring-quicktime-movies/#comment-48374</link>
		<dc:creator>Ryan Naraine&#8217;s Zero Day mobile edition</dc:creator>
		<pubDate>Wed, 12 Sep 2007 17:10:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-quicktime-movies#comment-48374</guid>
		<description>[...] (left) released details on vulnerabilities in Apple&#8217;s QuickTime media player to show how movie and .mp3 files can be backdoored to hack into [...]</description>
		<content:encoded><![CDATA[<p>[...] (left) released details on vulnerabilities in Apple&#8217;s QuickTime media player to show how movie and .mp3 files can be backdoored to hack into [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: 0DAY: QuickTime pwns Firefox &#124; GNUCITIZEN</title>
		<link>/blog/backdooring-quicktime-movies/#comment-48301</link>
		<dc:creator>0DAY: QuickTime pwns Firefox &#124; GNUCITIZEN</dc:creator>
		<pubDate>Wed, 12 Sep 2007 12:06:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-quicktime-movies#comment-48301</guid>
		<description>[...] on, I have to say a few things. Last year I disclosed two highly critical QuickTime vulnerabilities here and here. The first vulnerability was fixed but the second one was completely ignored. I tried to [...]</description>
		<content:encoded><![CDATA[<p>[...] on, I have to say a few things. Last year I disclosed two highly critical QuickTime vulnerabilities here and here. The first vulnerability was fixed but the second one was completely ignored. I tried to [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: roger</title>
		<link>/blog/backdooring-quicktime-movies/#comment-46172</link>
		<dc:creator>roger</dc:creator>
		<pubDate>Wed, 05 Sep 2007 18:27:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-quicktime-movies#comment-46172</guid>
		<description>yea i need this to work</description>
		<content:encoded><![CDATA[<p>yea i need this to work</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Doc</title>
		<link>/blog/backdooring-quicktime-movies/#comment-44854</link>
		<dc:creator>Doc</dc:creator>
		<pubDate>Sat, 01 Sep 2007 00:52:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-quicktime-movies#comment-44854</guid>
		<description>Quote [dodgescabin responds: I never use quicktime its not very good] ???

What the f***? - Is that the dumbest sweeping statement ever? It's like saying cars are not very good - or the sky is not very good!</description>
		<content:encoded><![CDATA[<p>Quote [dodgescabin responds: I never use quicktime its not very good] ???</p>
<p>What the f***? - Is that the dumbest sweeping statement ever? It&#8217;s like saying cars are not very good - or the sky is not very good!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dodgescabin</title>
		<link>/blog/backdooring-quicktime-movies/#comment-44485</link>
		<dc:creator>dodgescabin</dc:creator>
		<pubDate>Thu, 30 Aug 2007 18:37:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-quicktime-movies#comment-44485</guid>
		<description>I never use quicktime its not very good</description>
		<content:encoded><![CDATA[<p>I never use quicktime its not very good</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>/blog/backdooring-quicktime-movies/#comment-27653</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Thu, 07 Jun 2007 19:09:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-quicktime-movies#comment-27653</guid>
		<description>yes... this is right... and this is how it should be</description>
		<content:encoded><![CDATA[<p>yes&#8230; this is right&#8230; and this is how it should be</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Runic</title>
		<link>/blog/backdooring-quicktime-movies/#comment-27589</link>
		<dc:creator>Runic</dc:creator>
		<pubDate>Thu, 07 Jun 2007 15:20:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-quicktime-movies#comment-27589</guid>
		<description>Starting with QuickTime 7.1.5, you can no longer issue javascript&#58;// URLs or call JavaScript functions from within a QuickTime movie. This feature was removed from QuickTime for security reasons.</description>
		<content:encoded><![CDATA[<p>Starting with QuickTime 7.1.5, you can no longer issue javascript&#58;// URLs or call JavaScript functions from within a QuickTime movie. This feature was removed from QuickTime for security reasons.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sasha</title>
		<link>/blog/backdooring-quicktime-movies/#comment-19742</link>
		<dc:creator>sasha</dc:creator>
		<pubDate>Fri, 04 May 2007 19:01:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-quicktime-movies#comment-19742</guid>
		<description>How can you get around websense to get to myspace</description>
		<content:encoded><![CDATA[<p>How can you get around websense to get to myspace</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cityboi</title>
		<link>/blog/backdooring-quicktime-movies/#comment-16717</link>
		<dc:creator>Cityboi</dc:creator>
		<pubDate>Wed, 25 Apr 2007 13:34:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-quicktime-movies#comment-16717</guid>
		<description>How can you get around websense to get to myspace</description>
		<content:encoded><![CDATA[<p>How can you get around websense to get to myspace</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: PandaLabs Blog : Insecure features : should AV companies detect them?</title>
		<link>/blog/backdooring-quicktime-movies/#comment-8356</link>
		<dc:creator>PandaLabs Blog : Insecure features : should AV companies detect them?</dc:creator>
		<pubDate>Tue, 20 Mar 2007 15:46:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-quicktime-movies#comment-8356</guid>
		<description>[...] Insecure features : should AV companies detect them? These days we have been analyzing one of the latest MySpace threats, JS/MySpace.A, which uses an interesting QuickTime feature : HREF Tracks. A deep analysis of this malware is avaliable at Didier StevenÂ´s blog.  Abusing HREF Tracks was firstly documented by pdp at GNUCITIZEN blog, later the MoAB project showed how to exploit them in conjunction with other vulnerabilities that allowed hackers to gain remote code execution.  The end of the story is as follows: Apple has finally removed javascript support in QuickTime from version 7.1.5. But thatÂ´s not the end of it,&#160;I still remember a very similar case in which a feature became a vulnerability and we ended up adding generic detections for a legal and documented use of WMF file format, though&#160;I don't think anybody was really using it. So I wonder and I ask you: Should we add generic detections&#160;to file formats that support insecure features? If we do so, we&#160;may stop malware, but what can we say to a hypothetical customer using them properly?  Published Tuesday, March 20, 2007 1:39 PM by mballano        _uacct = "UA-969620-1"; urchinTracker();     _uacct = "UA-1443584-1"; urchinTracker(); [...]</description>
		<content:encoded><![CDATA[<p>[...] Insecure features : should AV companies detect them? These days we have been analyzing one of the latest MySpace threats, JS/MySpace.A, which uses an interesting QuickTime feature : HREF Tracks. A deep analysis of this malware is avaliable at Didier StevenÂ´s blog.  Abusing HREF Tracks was firstly documented by pdp at GNUCITIZEN blog, later the MoAB project showed how to exploit them in conjunction with other vulnerabilities that allowed hackers to gain remote code execution.  The end of the story is as follows: Apple has finally removed javascript support in QuickTime from version 7.1.5. But thatÂ´s not the end of it,&nbsp;I still remember a very similar case in which a feature became a vulnerability and we ended up adding generic detections for a legal and documented use of WMF file format, though&nbsp;I don&#8217;t think anybody was really using it. So I wonder and I ask you: Should we add generic detections&nbsp;to file formats that support insecure features? If we do so, we&nbsp;may stop malware, but what can we say to a hypothetical customer using them properly?  Published Tuesday, March 20, 2007 1:39 PM by mballano        _uacct = &#8220;UA-969620-1&#8243;; urchinTracker();     _uacct = &#8220;UA-1443584-1&#8243;; urchinTracker(); [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris Mosby at myITforum.com : McAfee Avert Labs Blog - MySpace Woes: Trojan Targets French Rock Band Fans - Friday March 16, 2007</title>
		<link>/blog/backdooring-quicktime-movies/#comment-8059</link>
		<dc:creator>Chris Mosby at myITforum.com : McAfee Avert Labs Blog - MySpace Woes: Trojan Targets French Rock Band Fans - Friday March 16, 2007</dc:creator>
		<pubDate>Mon, 19 Mar 2007 16:13:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-quicktime-movies#comment-8059</guid>
		<description>[...] And the latest target is unsuspecting fans of the French rock band MAMASAID who upon visiting a MySpace account promoting the music group get a trojan JS/SpaceStalk installed on their computers via a known insecure feature in QuickTime called HREF Tracks. The technique used here does not rely on vulnerability but rather on a feature present in the QuickTime player that allows for links to be opened automatically when the movie is run. This link&#160;could be misused to point to malicious websites hosting exploit code. [...]</description>
		<content:encoded><![CDATA[<p>[...] And the latest target is unsuspecting fans of the French rock band MAMASAID who upon visiting a MySpace account promoting the music group get a trojan JS/SpaceStalk installed on their computers via a known insecure feature in QuickTime called HREF Tracks. The technique used here does not rely on vulnerability but rather on a feature present in the QuickTime player that allows for links to be opened automatically when the movie is run. This link&nbsp;could be misused to point to malicious websites hosting exploit code. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: lastjedi</title>
		<link>/blog/backdooring-quicktime-movies/#comment-7850</link>
		<dc:creator>lastjedi</dc:creator>
		<pubDate>Mon, 19 Mar 2007 02:54:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-quicktime-movies#comment-7850</guid>
		<description>i have quicktime pro and vlc media player none work on limewire.when i download a video to watch i get the same thing a girl dancing for about 10 seconds nothing else.ive downloaded hundreds of videos and i get the same thing the girl dancing.why wont it show the video i downloaded.nothing works please help!</description>
		<content:encoded><![CDATA[<p>i have quicktime pro and vlc media player none work on limewire.when i download a video to watch i get the same thing a girl dancing for about 10 seconds nothing else.ive downloaded hundreds of videos and i get the same thing the girl dancing.why wont it show the video i downloaded.nothing works please help!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Windows Vista</title>
		<link>/blog/backdooring-quicktime-movies/#comment-7190</link>
		<dc:creator>Windows Vista</dc:creator>
		<pubDate>Sat, 17 Mar 2007 03:02:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-quicktime-movies#comment-7190</guid>
		<description>neat</description>
		<content:encoded><![CDATA[<p>neat</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Computer Security Research - McAfee Avert Labs Blog</title>
		<link>/blog/backdooring-quicktime-movies/#comment-7048</link>
		<dc:creator>Computer Security Research - McAfee Avert Labs Blog</dc:creator>
		<pubDate>Fri, 16 Mar 2007 17:24:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-quicktime-movies#comment-7048</guid>
		<description>[...] And the latest target is unsuspecting fans of the French rock band MAMASAID who upon visiting a MySpace account promoting the music group get a trojan JS/SpaceStalk installed on their computers via a known insecure feature in QuickTime called HREF Tracks. The technique used here does not rely on vulnerability but rather on a feature present in the QuickTime player that allows for links to be opened automatically when the movie is run. This linkÂ could be misused to point to malicious websites hosting exploit code. [...]</description>
		<content:encoded><![CDATA[<p>[...] And the latest target is unsuspecting fans of the French rock band MAMASAID who upon visiting a MySpace account promoting the music group get a trojan JS/SpaceStalk installed on their computers via a known insecure feature in QuickTime called HREF Tracks. The technique used here does not rely on vulnerability but rather on a feature present in the QuickTime player that allows for links to be opened automatically when the movie is run. This linkÂ could be misused to point to malicious websites hosting exploit code. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: average admins &#187; Blog Archive &#187; P0wned by a QT movie</title>
		<link>/blog/backdooring-quicktime-movies/#comment-6697</link>
		<dc:creator>average admins &#187; Blog Archive &#187; P0wned by a QT movie</dc:creator>
		<pubDate>Mon, 12 Mar 2007 21:07:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-quicktime-movies#comment-6697</guid>
		<description>[...] Embedding JavaScript inside a Quicktime movie is nothing new as GNUCitizen discussed back in September but it&#8217;s good to actually see that in the wild. [...]</description>
		<content:encoded><![CDATA[<p>[...] Embedding JavaScript inside a Quicktime movie is nothing new as GNUCitizen discussed back in September but it&#8217;s good to actually see that in the wild. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>/blog/backdooring-quicktime-movies/#comment-2796</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Thu, 25 Jan 2007 22:11:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-quicktime-movies#comment-2796</guid>
		<description>I am not quite sure how to do that but I know that it is possible since I did it before. Try to mess with the target field

&lt;pre&gt;&lt;code&gt;A&#60;javascript:alert("hello from backdoor")&#62; T&#60;target&#62;&lt;/code&gt;&lt;/pre&gt;</description>
		<content:encoded><![CDATA[<p>I am not quite sure how to do that but I know that it is possible since I did it before. Try to mess with the target field</p>
<pre><code>A&lt;javascript:alert("hello from backdoor")&gt; T&lt;target&gt;</code></pre>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nick</title>
		<link>/blog/backdooring-quicktime-movies/#comment-2793</link>
		<dc:creator>Nick</dc:creator>
		<pubDate>Thu, 25 Jan 2007 20:45:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-quicktime-movies#comment-2793</guid>
		<description>How do you pop the browser directly from quicktime standalone player? I can make it work from within the browser, but I want it to pop directly from the stand alone player.</description>
		<content:encoded><![CDATA[<p>How do you pop the browser directly from quicktime standalone player? I can make it work from within the browser, but I want it to pop directly from the stand alone player.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
