Original URL: http://www.reghardware.co.uk/2007/11/26/quicktime_exploit/
Hackers have created a proof-of-concept exploit for an Apple QuickTime player streaming media vulnerability.
Release of the exploit on Sunday follows hot on the heels of the public disclosure of the as-yet-unpatched buffer overflow bug (http://secunia.com/advisories/27755), which involves the QuickTime RTSP (Real Time Streaming Protocol) Response Header, on 23 November by Polish security researcher Krystian Kloskowski.
Symantec reports that the exploit might be applied to attack users of the latest version of stand-alone QuickTime players (version 7.3), tricked into opening malicious content on hacker-controlled websites. The same attack only crashes the browser of users of QuickTime browser plugins. Email-based attacks featuring attachments with hostile XML code that open a connection to malicious servers are also possible. This attack requires users to double-click on the malicious QuickTime multimedia attachment to run.
Both attacks rely on initiating a RTSP connection on port 554 leading to the transmission of hostile code. Symantec reports that both IE 6 and 7 (as well as Safari 3 block the attack. However, relying on this as a defence may be unwise. "Attackers may attempt to refine the exploit in the coming days in order to overcome this initial hiccup and work to create a reliable exploit that works on Internet Explorer," Symantec notes.
For the meantime, Firefox users are more exposed to the problem, especially if they've selected QuickTime as the default player for multimedia formats.
Pending a patch from Microsoft, users are advised to restrict outbound connections on port TCP 554 using their firewalls, advice that's probably easier to apply in corporate environments. Home users are warned to avoid any temptation to follow links to untrusted websites.
Symantec's write-up of the flaw, featuring screenshots showing the exploit code at work, can be found here (http://www.symantec.com/enterprise/security_response/weblog/2007/11/0day_exploit_for_apple_quickti.html). ®
Apple okay with Safari 'carpet bombing' vuln for now (15 May 2008)
http://www.theregister.co.uk/2008/05/15/apple_safari_carpet_bombing_vuln/
Apple unleashes monster patch batch on Mac faithful (19 March 2008)
http://www.reghardware.co.uk/2008/03/19/monster_apple_patch_batch/
Judge accuses hacks of hacking cannibal ruling (26 February 2008)
http://www.theregister.co.uk/2008/02/26/judge_blames_media_hackers/
Media player users beware: more vulns ahead (10 December 2007)
http://www.theregister.co.uk/2007/12/10/3ivx_mp4_vuln/
Latest QuickTime Exploit targets both Macs and PCs (29 November 2007)
http://www.theregister.co.uk/2007/11/29/new_quicktime_exploit/
Hacker defaces temples to OS X (27 November 2007)
http://www.theregister.co.uk/2007/11/27/mac_site_defacer/
QuickTime update fixes code-execution holes (6 November 2007)
http://www.theregister.co.uk/2007/11/06/new_quicktime_update/
Apple patches Windows QuickTime bug (4 October 2007)
http://www.theregister.co.uk/2007/10/04/windows_quicktime_update/
Security maven: QuickTime flaw threatens PCs, Macs (12 September 2007)
http://www.theregister.co.uk/2007/09/12/quicktime_vulnerability_attacks_firefox/
Security flaw marketplace lays out its wares (6 July 2007)
http://www.theregister.co.uk/2007/07/06/security_flaw_marketplace/
Apple plugs holes in new Safari beta (14 June 2007)
http://www.reghardware.co.uk/2007/06/14/safari_holes_plugged/
Apple plugs two QuickTime holes (30 May 2007)
http://www.reghardware.co.uk/2007/05/30/latest_quicktime_security_patch/
The rise of zero-day patches (2 March 2007)
http://www.theregister.co.uk/2007/03/02/zero-day_patches_interviews/