YNOT
  • Home
  • Industry News
    • Adult Business News
    • Adult Novelty News
    • YNOT Magazine
    • EU News
    • Opinions
    • Picture Galleries
  • PR Wire
    • Adult Company News
    • Adult Retail News
    • Adult Talent News
    • Adult Videos News
  • Podcasts
  • Industry Guides
    • Adult Affiliate Guide
    • Affiliate Marketing for Beginners
    • Top Adult Traffic Networks
    • Top Adult PR Agents
    • Funding an Adult Business
  • Business Directory
    • View Categories
    • View Listings
    • Submit Listing
  • Newsletters
  • Industry Events
    • Events Calendar
    • YNOT Cam Awards | Hollywood
    • YNOT Awards | Prague
    • YNOT Cammunity
    • YNOT Summit
    • YNOT Reunion
  • Login with YNOT ID

“Month of Apple Bugs” Begins With Report of Critical, Easily-Exploited QuickTime Flaw

Posted On 02 Jan 2007
By : admin

CYBERSPACE — Security researcher Kevin Finisterre and his anonymous partner “LMH” kicked off their MOAB (“Month of Apple Bugs”) project yesterday by detailing a stack overflow error in Apple’s commonly-used QuickTime media player.“A vulnerability exists in the handling of the rtsp:// URL handler,” LMH stated in a post to his “Apple Fun” blog. “By supplying a specially crafted string… an attacker could overflow a stack-based buffer, using either HTML, Javascript or a QTL file as attack vector, leading to an exploitable remote arbitrary code execution condition.”

“Exploitation of this issue is trivial,” LMH added in his summary of the flaw.

The French Security Incident Response Team (FrSIRT) has rated the flaw “Critical,” and suggests that QuickTime users disable Real Time Streaming Protocol (RTSP) support until an official patch for the bug has been supplied.

Dutch security firm Secunia concurred with FrSIRT’s assessment, terming the flaw “highly critical.” Secunia recommended that QuickTime users not open “untrusted QTL files” pending the release of an official patch.

Apple has not yet commented on the bug.

This is not LMH’s first “month of bugs” project; in November, the anonymous researcher/hacker conducted the “Month of Kernel Bugs.” Both appear to have been inspired by the “Month of Browser Bugs” conducted by MetaSploit.com last July.

The MOAB project was recently derided in a Mac Observer editorial as a “Month of Continuous Foolishness.” In the piece, Mac Observer’s John Martellaro takes umbrage with LMH’s bug reporting approach, which does not include prior notification to Apple’s security teams.

Martellaro opines that the MOAB project is “some kind of desire for notoriety,” and notes that “there are appropriate channels to handle these discoveries that are professional and protect everyone.”

On a FAQ published on the MOAB website, LMH states that his project does “rarely” notify vendors first, adding that “sometimes we may decide to pass an issue through the appropriate people.”

“The problem with so-called ‘responsible disclosure’ is that for some people, it means keeping others on hold for insane amounts of time, even when the fix should be trivial,” the FAQ answer continues. “And the reward (automated responses and euphemism-heavy advisories) doesn’t pay off in the end.”

In his editorial criticizing the MOAB project, Martellaro asserts “the supposition that there are some people who take the security of Mac OS X more seriously than the BSD professionals and Apple engineers is stupendously arrogant and self-serving.”

For more information, check out the following:

Secunia’s security advisory: http://secunia.com/advisories/23540/
LMH’s “Apple Fun” blog: http://applefun.blogspot.com/
The MOAB website: http://projects.info-pull.com/moab/

  • google-share
Previous Story

Panda Software Releases Annual List of Worst Viruses, Worms, and Malware

Next Story

“X”-mas Indeed; Xbox Game Gift Turns Out to Be Porn Disc

Leave a Reply Cancel reply

You must be logged in to post a comment.

Sponsor

YNOT Shoot Me

YNOTShootMe.com has exclusive pics from adult industry business events. Check it out!

YNOT Directory

  • Honest Porn Reviews
    Marketing & Traffic Services
  • Vicetemple
    Hosting & Technical Services
  • Lovers Choice
    Novelty & Lingerie Distributors
  • Premiere Listing

    Live Studio

    More Details

RECENT

POPULAR

COMMENTS

Kasey Kei Sinks Her Teeth Into Spooky New Gender X Films Scene

Posted On 05 Sep 2025

ASN Awards Announces 2025 Winners

Posted On 05 Sep 2025
Elegant Angel Releases “Shared: A Hotwife Origin Story”

Elegant Angel Releases “Shared: A Hotwife Origin Story”

Posted On 05 Sep 2025

Vanessa, Meet Vivid

Posted On 29 Sep 2014
Laila Mickelwaite and Exodus Cry

Laila Mickelwaite, Exodus Cry and their Crusade Against Porn

Posted On 03 May 2021

Someone puts Gal Gadot in one of your vids? Take it down!

Posted On 13 Dec 2017

Hoping viewers can also enjoy a spooky...

Posted On 24 Oct 2023

now a days these type of games will get...

Posted On 17 Jul 2023

good move from adent. these type of...

Posted On 06 Jul 2023

Sponsor

Sitemap
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.OkPrivacy Policy