search technology reviews, news, features, group tests
Popular Searches:   video , dell , dvd
 |  Register
 |  Newsletters  | 
Sitemap  |  RSS
RSS
Monday November 23, 2009 4:30 AM AEST
Skip Navigation LinksPC Authority > News > Hacking contest yields QuickTime exploit
NEWS

Hacking contest yields QuickTime exploit

by Shaun Nichols  on Apr 27, 2007
Tags: Hack | QuickTime
Researcher wins US$10,000 bounty with JavaScript attack.
A security researcher has claimed a $12,000 bounty by crafting a security exploit that targets Apple's QuickTime software.

The exploit was demonstrated on a fully-patched Mac OS 10.4.9 system running Apple's Safari browser.

Both the Mac and PC versions of Firefox have been confirmed as susceptible to the attack, but early tests suggest that Microsoft's Internet Explorer could not be used as an avenue for attack.

Independent researcher Dino Dai Zovi crafted the attack, which uses JavaScript code embedded in a web page. When executed, the exploit provides the attacker with access to the machine under the user's account privileges.

"You can steal cookies, you can steal browser cache, you can install malware. It is definitely serious," said independent security researcher Tom Ferris

Users can defend against the vulnerability by disabling Java within the browser or by removing the QTJava.jar extension.

Dai Zovi wrote the exploit for a contest at the CanSecWest conference in which researchers were challenged to break into a pair of fully-patched MacBook Pro laptops. 

A successful exploit wins the researcher the target machine and a US$10,000 reward from Tipping Point's Zero Day Initiative.

The process of finding the vulnerability and writing the attack took Dai Zovi just nine hours.

"I began looking for a browser-based vulnerability around 10pm on Thursday night, had found one by around 3am, and had written a reliably working exploit by 7am," he said in an email interview.

As part of the contract for collecting the reward, Dai Zovi agreed to hand over the handling and development rights to the vulnerability to Tipping Point.

The company then immediately contacted Apple to report the flaw and added a fix to its own security software.

Apple did not return a request for comment. The company has a policy of not confirming or discussing vulnerabilities until after a fix has been issued.

Copyright © 2009 v3.co.uk
Email a Friend Email this
Print Page Print this
Tweet This Tweet this
Feedback Send us your tips


Ads by Google

Comments

Be the first to comment on this article.
Thoughts on this article? Add a comment below.
Login or register to submit a comment.
 

Top Stories

Box battle: Telstra takes on TiVo and Foxtel with T-Box trial in Melbourne
It's not quite Foxtel IQ and it's isn't TiVo either. The T-Box lets Telstra users watch movies and TV from the Bigpond site, as well as record and watch digital TV
 
5 More Free Linux Apps You Can't Do Without
More digital Swiss Army knife software, including Linux utilities and tools that are so useful you won't know how you ever did without them
 
Microsoft delivers Office 2010 public beta
Vendor details editions for Office 2010 along with application virtualisation for testing.
 


 
Intel
 
 
LogMeIn
 
 
Amazing Dell Coupons now available
 
Discover Apple