<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: QuickTime 0day for Vista and XP</title>
	<atom:link href="http://www.gnucitizen.org/blog/quicktime-0day-for-vista-and-xp/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/blog/quicktime-0day-for-vista-and-xp/</link>
	<description>Information Security Think Tank</description>
	<lastBuildDate>Sat, 02 Feb 2013 17:50:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.1</generator>
	<item>
		<title>By: Details of the QuickTime Vulnerability &#124; GNUCITIZEN</title>
		<link>http://www.gnucitizen.org/blog/quicktime-0day-for-vista-and-xp/comment-page-1/#comment-123630</link>
		<dc:creator>Details of the QuickTime Vulnerability &#124; GNUCITIZEN</dc:creator>
		<pubDate>Tue, 09 Sep 2008 14:24:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/quicktime-0day-for-vista-and-xp/#comment-123630</guid>
		<description>[...] I intend to give a brief overview of the QuickTime vulnerability which I partially-disclosed over here. I should have made these details public long time ago but better late then never. The [...]</description>
		<content:encoded><![CDATA[<p>[...] I intend to give a brief overview of the QuickTime vulnerability which I partially-disclosed over here. I should have made these details public long time ago but better late then never. The [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: My BH Las Vegas Slides &#124; GNUCITIZEN</title>
		<link>http://www.gnucitizen.org/blog/quicktime-0day-for-vista-and-xp/comment-page-1/#comment-123626</link>
		<dc:creator>My BH Las Vegas Slides &#124; GNUCITIZEN</dc:creator>
		<pubDate>Tue, 09 Sep 2008 10:30:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/quicktime-0day-for-vista-and-xp/#comment-123626</guid>
		<description>[...] Yes, it is time for a coffee. Unfortunately, it does not look as good as the one from the picture above. The slides can be found here. The next post is all about the QuickTime vulnerability which I partially-disclosed over here. [...]</description>
		<content:encoded><![CDATA[<p>[...] Yes, it is time for a coffee. Unfortunately, it does not look as good as the one from the picture above. The slides can be found here. The next post is all about the QuickTime vulnerability which I partially-disclosed over here. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Zero-Day Vulnerability Reported in Apple&#8217;s QuickTime for Windows XP and Vista</title>
		<link>http://www.gnucitizen.org/blog/quicktime-0day-for-vista-and-xp/comment-page-1/#comment-123299</link>
		<dc:creator>Zero-Day Vulnerability Reported in Apple&#8217;s QuickTime for Windows XP and Vista</dc:creator>
		<pubDate>Sun, 24 Aug 2008 14:19:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/quicktime-0day-for-vista-and-xp/#comment-123299</guid>
		<description>[...] a computer security consultancy, on Friday warned of a zero-day vulnerability in Apple&#8217;s QuickTime media player for Windows XP and Windows Vista. &#8220;A remote [...]</description>
		<content:encoded><![CDATA[<p>[...] a computer security consultancy, on Friday warned of a zero-day vulnerability in Apple&#8217;s QuickTime media player for Windows XP and Windows Vista. &#8220;A remote [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giuseppe Cascone &#187; Blog Archive &#187; QuickTime 0day for Vista and XP</title>
		<link>http://www.gnucitizen.org/blog/quicktime-0day-for-vista-and-xp/comment-page-1/#comment-122901</link>
		<dc:creator>Giuseppe Cascone &#187; Blog Archive &#187; QuickTime 0day for Vista and XP</dc:creator>
		<pubDate>Wed, 09 Jul 2008 12:37:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/quicktime-0day-for-vista-and-xp/#comment-122901</guid>
		<description>[...] see video click) Because we are an information security think tank and because we encounter some very interesting [...]</description>
		<content:encoded><![CDATA[<p>[...] see video click) Because we are an information security think tank and because we encounter some very interesting [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Antonio Trigiani iBlog - Informatica Virale &#187; Blog Archive &#187; Video: VulnerabilitÃ  QuickTime 0day su Windows Vista e XP</title>
		<link>http://www.gnucitizen.org/blog/quicktime-0day-for-vista-and-xp/comment-page-1/#comment-121397</link>
		<dc:creator>Antonio Trigiani iBlog - Informatica Virale &#187; Blog Archive &#187; Video: VulnerabilitÃ  QuickTime 0day su Windows Vista e XP</dc:creator>
		<pubDate>Sat, 10 May 2008 17:52:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/quicktime-0day-for-vista-and-xp/#comment-121397</guid>
		<description>[...] sicurezza, Video &#124;     Il team di Gnucitizen mostra in questo video come sfruttare la vulnerabilitÃ  0day di QuickTime su Windows Vista e Windows [...]</description>
		<content:encoded><![CDATA[<p>[...] sicurezza, Video |     Il team di Gnucitizen mostra in questo video come sfruttare la vulnerabilitÃ  0day di QuickTime su Windows Vista e Windows [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Quicktime Flaw Makes Windows Vulnerable to Attack &#124; Networking for Networkers</title>
		<link>http://www.gnucitizen.org/blog/quicktime-0day-for-vista-and-xp/comment-page-1/#comment-120835</link>
		<dc:creator>Quicktime Flaw Makes Windows Vulnerable to Attack &#124; Networking for Networkers</dc:creator>
		<pubDate>Mon, 05 May 2008 16:58:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/quicktime-0day-for-vista-and-xp/#comment-120835</guid>
		<description>[...] PCs running Windows Vista SP1 and XP SP2. Although details are a bit thin at the moment, the GNUCitizen blog has published a movie purporting to show the attack in [...]</description>
		<content:encoded><![CDATA[<p>[...] PCs running Windows Vista SP1 and XP SP2. Although details are a bit thin at the moment, the GNUCitizen blog has published a movie purporting to show the attack in [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ix</title>
		<link>http://www.gnucitizen.org/blog/quicktime-0day-for-vista-and-xp/comment-page-1/#comment-120563</link>
		<dc:creator>Ix</dc:creator>
		<pubDate>Fri, 02 May 2008 13:38:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/quicktime-0day-for-vista-and-xp/#comment-120563</guid>
		<description>Seconding Jim&#039;s question. Knowing it exists is important, knowing what&#039;s being done about it is even more important.</description>
		<content:encoded><![CDATA[<p>Seconding Jim&#8217;s question. Knowing it exists is important, knowing what&#8217;s being done about it is even more important.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jim Manico</title>
		<link>http://www.gnucitizen.org/blog/quicktime-0day-for-vista-and-xp/comment-page-1/#comment-120414</link>
		<dc:creator>Jim Manico</dc:creator>
		<pubDate>Thu, 01 May 2008 04:13:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/quicktime-0day-for-vista-and-xp/#comment-120414</guid>
		<description>Inquiring minds want to know. Can you at least let us know how Apple is reacting to this exploit?</description>
		<content:encoded><![CDATA[<p>Inquiring minds want to know. Can you at least let us know how Apple is reacting to this exploit?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: flashdrive</title>
		<link>http://www.gnucitizen.org/blog/quicktime-0day-for-vista-and-xp/comment-page-1/#comment-120409</link>
		<dc:creator>flashdrive</dc:creator>
		<pubDate>Thu, 01 May 2008 00:03:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/quicktime-0day-for-vista-and-xp/#comment-120409</guid>
		<description>when can we expect to see how this is done?</description>
		<content:encoded><![CDATA[<p>when can we expect to see how this is done?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GNUCitizen: QuickTime for Windows Vista and XP Leakage Leads to Inevitable Badness &#124; Infosecurity.US</title>
		<link>http://www.gnucitizen.org/blog/quicktime-0day-for-vista-and-xp/comment-page-1/#comment-120408</link>
		<dc:creator>GNUCitizen: QuickTime for Windows Vista and XP Leakage Leads to Inevitable Badness &#124; Infosecurity.US</dc:creator>
		<pubDate>Wed, 30 Apr 2008 23:57:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/quicktime-0day-for-vista-and-xp/#comment-120408</guid>
		<description>[...] Quicktime on Microsoft WIndows Vista and XP only. See the full announcement on the GNUCitizen site here. Current Workarounds include&#8230;.Not opening up attachments from unknown sources.  Sphere: [...]</description>
		<content:encoded><![CDATA[<p>[...] Quicktime on Microsoft WIndows Vista and XP only. See the full announcement on the GNUCitizen site here. Current Workarounds include&#8230;.Not opening up attachments from unknown sources.  Sphere: [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: works on mac?</title>
		<link>http://www.gnucitizen.org/blog/quicktime-0day-for-vista-and-xp/comment-page-1/#comment-120400</link>
		<dc:creator>works on mac?</dc:creator>
		<pubDate>Wed, 30 Apr 2008 15:59:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/quicktime-0day-for-vista-and-xp/#comment-120400</guid>
		<description>so you are doing some HREF track ninja? http://www.apple.com/quicktime/tutorials/hreftracks.html You test this stuff on a mac PDP?</description>
		<content:encoded><![CDATA[<p>so you are doing some HREF track ninja? <a href="http://www.apple.com/quicktime/tutorials/hreftracks.html" rel="nofollow">http://www.apple.com/quicktime.....racks.html</a> You test this stuff on a mac PDP?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hardware e Software &#187; Blog Archive &#187; QuickTime, individuata falla pericolosa</title>
		<link>http://www.gnucitizen.org/blog/quicktime-0day-for-vista-and-xp/comment-page-1/#comment-120324</link>
		<dc:creator>Hardware e Software &#187; Blog Archive &#187; QuickTime, individuata falla pericolosa</dc:creator>
		<pubDate>Tue, 29 Apr 2008 21:21:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/quicktime-0day-for-vista-and-xp/#comment-120324</guid>
		<description>[...] chi volesse approfondire lâ€™argomento vi consiglio il seguente link contenente il messaggio ufficiale rilasciato dal Petkov ed un video che mostra la vulnerabilitÃ  in [...]</description>
		<content:encoded><![CDATA[<p>[...] chi volesse approfondire lâ€™argomento vi consiglio il seguente link contenente il messaggio ufficiale rilasciato dal Petkov ed un video che mostra la vulnerabilitÃ  in [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: hilikus</title>
		<link>http://www.gnucitizen.org/blog/quicktime-0day-for-vista-and-xp/comment-page-1/#comment-120305</link>
		<dc:creator>hilikus</dc:creator>
		<pubDate>Tue, 29 Apr 2008 17:44:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/quicktime-0day-for-vista-and-xp/#comment-120305</guid>
		<description>Very good findings and research pdp, keep up the good work, and props for the responsible disclosure. Don&#039;t let any of these trolls take away from your execlent findings. And good luck working with Apple, I just keep thinking about the wireless dirver vulnerability and how they treated HDMoore :\ 

@alino: I doubt he is going to say, read the other comments and his responses.</description>
		<content:encoded><![CDATA[<p>Very good findings and research pdp, keep up the good work, and props for the responsible disclosure. Don&#8217;t let any of these trolls take away from your execlent findings. And good luck working with Apple, I just keep thinking about the wireless dirver vulnerability and how they treated HDMoore :\ </p>
<p>@alino: I doubt he is going to say, read the other comments and his responses.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Windows Ãœzerinde Yeni Bir QuickTime AÃ§Ä±ÄŸÄ± &#124; MacOSXPC.Com</title>
		<link>http://www.gnucitizen.org/blog/quicktime-0day-for-vista-and-xp/comment-page-1/#comment-120300</link>
		<dc:creator>Windows Ãœzerinde Yeni Bir QuickTime AÃ§Ä±ÄŸÄ± &#124; MacOSXPC.Com</dc:creator>
		<pubDate>Tue, 29 Apr 2008 17:20:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/quicktime-0day-for-vista-and-xp/#comment-120300</guid>
		<description>[...] olan ve bilgisayar korsanlarÄ± arasÄ±nda &#8220;pdp&#8221; olarak bilinen Petko D. Petkov&#8217;un aÃ§Ä±klamasÄ±na gÃ¶re Apple&#8216;Ä±n medya oynatÄ±cÄ± yazÄ±lÄ±mÄ± olan QuickTime, Microsoft&#8216;un Windows [...]</description>
		<content:encoded><![CDATA[<p>[...] olan ve bilgisayar korsanlarÄ± arasÄ±nda &#8220;pdp&#8221; olarak bilinen Petko D. Petkov&#8217;un aÃ§Ä±klamasÄ±na gÃ¶re Apple&#8216;Ä±n medya oynatÄ±cÄ± yazÄ±lÄ±mÄ± olan QuickTime, Microsoft&#8216;un Windows [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pesquisador encontra nova falha no QuickTime p/ Windows</title>
		<link>http://www.gnucitizen.org/blog/quicktime-0day-for-vista-and-xp/comment-page-1/#comment-120282</link>
		<dc:creator>Pesquisador encontra nova falha no QuickTime p/ Windows</dc:creator>
		<pubDate>Tue, 29 Apr 2008 14:43:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/quicktime-0day-for-vista-and-xp/#comment-120282</guid>
		<description>[...] acordo com os detalhes publicados no blog GNUCitizen, o exploit envolve um arquivo malicioso especialmente criado. Quando o usuÃ¡rio abre este arquivo, [...]</description>
		<content:encoded><![CDATA[<p>[...] acordo com os detalhes publicados no blog GNUCitizen, o exploit envolve um arquivo malicioso especialmente criado. Quando o usuÃ¡rio abre este arquivo, [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: alino</title>
		<link>http://www.gnucitizen.org/blog/quicktime-0day-for-vista-and-xp/comment-page-1/#comment-120269</link>
		<dc:creator>alino</dc:creator>
		<pubDate>Tue, 29 Apr 2008 12:09:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/quicktime-0day-for-vista-and-xp/#comment-120269</guid>
		<description>@PDP: Which Class of Vulnerability ( stack/heap based buffer overflow or other.. ) was used for this vulnerability? btw: good work pdp :)</description>
		<content:encoded><![CDATA[<p>@PDP: Which Class of Vulnerability ( stack/heap based buffer overflow or other.. ) was used for this vulnerability? btw: good work pdp :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David Kierznowski</title>
		<link>http://www.gnucitizen.org/blog/quicktime-0day-for-vista-and-xp/comment-page-1/#comment-120260</link>
		<dc:creator>David Kierznowski</dc:creator>
		<pubDate>Tue, 29 Apr 2008 09:57:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/quicktime-0day-for-vista-and-xp/#comment-120260</guid>
		<description>&lt;blockquote&gt;
Regarding hype:
&lt;/blockquote&gt;

I think we sometimes forget our roots as security researchers. The only reason we have an industry today was because of full-disclosure and hype. If you can&#039;t create a noise to motivate change, then you don&#039;t affect the commercial market, which in turn means we are all out of jobs ;)</description>
		<content:encoded><![CDATA[<blockquote><p>
Regarding hype:
</p></blockquote>
<p>I think we sometimes forget our roots as security researchers. The only reason we have an industry today was because of full-disclosure and hype. If you can&#8217;t create a noise to motivate change, then you don&#8217;t affect the commercial market, which in turn means we are all out of jobs ;)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: cryoohki</title>
		<link>http://www.gnucitizen.org/blog/quicktime-0day-for-vista-and-xp/comment-page-1/#comment-120259</link>
		<dc:creator>cryoohki</dc:creator>
		<pubDate>Tue, 29 Apr 2008 09:50:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/quicktime-0day-for-vista-and-xp/#comment-120259</guid>
		<description>@jim: rtfa next time. Or at least the comments on /.

For the &quot;imaginary vulnerabilities&quot; Apple&#039;s policy stinks, that&#039;s all I can say...</description>
		<content:encoded><![CDATA[<p>@jim: rtfa next time. Or at least the comments on /.</p>
<p>For the &#8220;imaginary vulnerabilities&#8221; Apple&#8217;s policy stinks, that&#8217;s all I can say&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Agujero de seguridad en Quicktime compromete a usuarios de Vista y XP &#124; Win-Vista.es</title>
		<link>http://www.gnucitizen.org/blog/quicktime-0day-for-vista-and-xp/comment-page-1/#comment-120209</link>
		<dc:creator>Agujero de seguridad en Quicktime compromete a usuarios de Vista y XP &#124; Win-Vista.es</dc:creator>
		<pubDate>Mon, 28 Apr 2008 22:29:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/quicktime-0day-for-vista-and-xp/#comment-120209</guid>
		<description>[...] VÃ­a &#124; GNUCitizen [...]</description>
		<content:encoded><![CDATA[<p>[...] VÃ­a | GNUCitizen [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Security News - Tools - Tutorials and more &#8230; &#187; Blog Archive &#187; Department of Homeland Security website hacked!</title>
		<link>http://www.gnucitizen.org/blog/quicktime-0day-for-vista-and-xp/comment-page-1/#comment-120198</link>
		<dc:creator>Security News - Tools - Tutorials and more &#8230; &#187; Blog Archive &#187; Department of Homeland Security website hacked!</dc:creator>
		<pubDate>Mon, 28 Apr 2008 19:36:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/quicktime-0day-for-vista-and-xp/#comment-120198</guid>
		<description>[...] the demand. But should the attackers get their hands on a newer exploit - say, one targeting a zero-day vulnerability in QuickTime - it would be relatively easy for them to swap out the [...]</description>
		<content:encoded><![CDATA[<p>[...] the demand. But should the attackers get their hands on a newer exploit &#8211; say, one targeting a zero-day vulnerability in QuickTime &#8211; it would be relatively easy for them to swap out the [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
