January 04, 2007

Researcher: QuickTime still at risk from MySpace bug

Bug could still be exploited in combination with other malicious software to run unauthorized software on a patched computer, expert says

The QuickTime vulnerability that led to a widespread worm outbreak on MySpace.com last month could be exploited again, according to security researcher Aviv Raff , who has published software that illustrates his point.

Apple Computer Inc. issued a temporary patch for the problem last month, but on Wednesday Raff published proof-of-concept code showing how this bug could still be exploited in combination with other malicious software to run unauthorized software on a patched computer.

Apple created its patch after a worm spread through the MySpace community in early December, stealing MySpace log-in credentials and promoting adware Web sites. But rather than addressing the underlying problem, Apple's fix appears to simply block the MySpace worm code, Raff said. "Apple’s patch has no effect on this vulnerability," he said via instant message.

Users were infected by the MySpace worm when they played maliciously encoded .mov multimedia files.

The attack demonstrated by Raff is called a cross-zone scripting attack. It circumvents the "zone" security model that is used by Internet Explorer to limit the types of things Web-based software can do on a PC. "It potentially allows an attacker to execute arbitrary code on the user's machine," Raff said of the vulnerability.

Raff's proof-of-concept code shows how this cross-zone scripting attack could be used to run code on a Windows 2000 system running the Internet Explorer 6 browser. It was published as part of a monthlong effort to draw attention to security issues in Apple's products, called the Month of Apple Bugs.

Running malware on a victim's PC is a two-step process, however, and attackers would also need to exploit a second vulnerability in order to trick the browser into running their code.

Raff's code exploits a known bug in Microsoft's Management Console software, which was patched last August. But the attack could also be paired with code that takes advantage of an unpatched Windows vulnerability, making it a far more serious exploit, said Alyssa Myers, a virus research engineer with McAfee Inc. "It seems likely that this sort of thing could be used for a MySpace worm," she said. "Whether that actually ends up happening is anybody's guess."

When Apple created its QuickTime fix last month, it did not deliver the software directly to QuickTime users but instead took the unusual step of having MySpace link to the code.

Apple may have decided not to distribute this patch directly because it did not address the underlying problem, said Tim Erlin, risk assessment technology manager with nCircle Network Security Inc. "They didn't patch the whole thing," he said. "They reacted to the emergence of a worm on MySpace."

It will be hard for Apple to fix the underlying problem, researchers said, because the HREF Track QuickTime feature that is exploited in these attacks is used by a number of legitimate applications. These would be broken if Apple simply disabled the feature, Erlin said. "They can't simply pull it out," he said.

Apple is working on a "broader solution" to the QuickTime problem, a company spokesman said Thursday. He could not immediately comment on Raff's proof-of-concept code.



 

Close

On Twitter now

Security

Powered by Twitter

On Twitter now

White Paper

D2D Virtual Tape Library Replication Primer

This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.

Download now »

White Paper

An Alternative to Virtualization for Datacenter Cost Savings

Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.

Download now »

White Paper

Why Your Firewall, VPN, and IEEE 802.11i Aren't Enough to Protect Your Network

The emergence of WLANs has created a new breed of security threats to enterprise networks.

Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation

Download now »

White Paper

Bringing the Edge to the Data Center

Effectively address data protection challenges, implementing solutions that help store and protect business–critical data while cutting costs and improving efficiency and reliability.

Download now »

Sign up to receive Security Resource Alerts

Subscribe to the Security Central Newsletter

Stay informed of the latest security threats and fixes.

White paper

Log Management: How to Develop the Right Strategy for Business and Compliance

This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.

Download now! »

White paper

The Essential Series: Security Information Management

Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.

Download now! »

White paper

Aberdeen: Choosing and Consuming Managed Security Services

Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.

Download now! »
©1994-2009 Infoworld, Inc.