|
|
| Welcome to the Mac Forums forums. Please read the FAQ if you have questions. Register to participate. |
|
|||||||
| TouchArcade.com - iPhone Game Reviews and News |
![]() |
|
|
Thread Tools | Search this Thread | Display Modes |
|
|
#1 | ||
|
macrumors bot
Join Date: Apr 2001
|
MySpace Demands Apple Change Quicktime To Fix MySpace Worm
![]() According to News.com, MySpace.com is demanding that Apple change its Quicktime player software to address an issue that occurred recently when the popular social networking website was attacked by a phishing/worm attack that used embedded Quicktime movies to propagate. Quote:
Quote:
|
||
|
|
|
|
|
#2 |
|
Demi-God (Editor)
|
+1 for Apple's security reputation (which it could use after last month)
-5 for MySpace's security reputation |
|
|
|
|
|
#3 |
|
macrumors 603
|
well i think it's good that Apple is doing something about it, but myspace shouldn't demand them too though
|
|
|
|
|
|
#4 |
|
macrumors 6502a
|
Myspace really is a crock. My band's account got compromised the other day, which was irritating.
And why on earth do people put that ridiculous transparency effect on their pages? Crashes Safari every time.
__________________
Wii Code - 0279-2698-2658-0111 - Dunepilot |
|
|
|
|
|
#5 |
|
macrumors 68000
|
Because the people that use them don't know what a good webpage looks like?
__________________
|
|
|
|
| benthewraith |
| View Public Profile |
| Find More Posts by benthewraith |
|
|
#6 |
|
macrumors 68030
Join Date: Dec 2002
Location: Alameda, CA
|
This is potentially much more harmful to Apple from a PR standpoint than last week's Nike+iPod "stalking" story. Let's see what the press does with this one.
|
|
|
|
|
|
#7 |
|
Demi-God (Moderator)
Join Date: Jan 2004
Location: Grand Rapids, MI, USA
|
Well, bitching about MySpace aside, there is a vulnerability in Quicktime. Which is bad. But Apple is fixing it, which is good. I can live with that, I guess.
__________________
Mohan |
|
|
|
|
|
#8 |
|
macrumors 6502a
Join Date: Dec 2004
|
Isn't Myspace run by a (former) notorious spammer? That says something about their credibility.
__________________
Home: PM G5 2.3 GHz 4.5 GB RAM, 20" ACD, 1G 512 MB and 2G 1GB Shuffle, 4 GB nano RED, 80 GB iPod, iPhone 3G S⃣ 32 GB Black. Work: MacBook C2D 2.0 GHz 4GB RAM |
|
|
|
|
|
#9 |
|
macrumors 65816
Join Date: Sep 2006
Location: New York City
|
Is it wrong of me to get a good chuckle from this story?
|
|
|
|
|
|
#10 |
|
macrumors 65816
|
No actually...
__________________
"I wonder if you can refuse to inherit the world." -Calvin, The Essential Calvin and Hobbes |
|
|
|
|
|
#11 |
|
macrumors 68020
Join Date: Dec 2003
Location: West Coast
|
|
|
|
|
|
|
#12 |
|
macrumors 68020
Join Date: May 2002
Location: 2 Much Infinite Loops
|
"Recently we learned about an issue that exploits a feature in QuickTime used to target MySpace users. We have devised a way to disable this QuickTime feature for those who use Internet Explorer. We are working on a broader solution for all other users as well," Fox said in the e-mail.
maybe it is just me, does it only happen with IE users? if so, why is this solely Apple's problem?
__________________
"Real men FTP/SSH their files around anyway." -- generik |
|
|
|
|
|
#13 | |
|
macrumors 68040
Join Date: Oct 2003
Location: The soggy part of the Pacific NW
|
Quote:
There's no real detail in that report, though. It just says "there's a flaw, it involves Quicktime's Javascript support, we're working on it".
__________________
The fevered rantings found in this post are generated randomly. Any resemblance to coherent thought is completely coincidental. |
|
|
|
|
|
|
#14 |
|
macrumors member
|
So is this a problem that has always been around and was just now brought to attention because of myspace's popularity or is this a totally new issue?
|
|
|
|
|
|
#15 | |
|
macrumors 65816
Join Date: Mar 2004
Location: The Great White North
|
Quote:
__________________
MB Alu 2GHz, iMac i7, iPhone 3G, iPhone 3GS |
|
|
|
|
|
|
#16 |
|
macrumors Demi-God
Join Date: Mar 2005
Location: London, UK
|
Wow, a security vulnerability does some good for once!
__________________
"No, I'm from Iowa, I only work in outer space." |
|
|
|
| Spanky Deluxe |
| View Public Profile |
| Find More Posts by Spanky Deluxe |
|
|
#17 |
|
macrumors 65816
Join Date: Apr 2006
|
My freind sent me this
CLICK AT YOUR OWN RISK! http://vids.myspace.com/quicktime/upgrade.cfm is that the patch? or a hoax to try and install the worm?
__________________
Black MacBook | Core Duo 2 GHz | 2 GB Ram | 320 GB HDD | OS X Snow Leopard 10.6 - iPod Touch | 16 GB
Camino OpenSolaris Last edited by Doctor Q : Dec 6, 2006 at 12:14 PM. |
|
|
|
|
|
#18 |
|
macrumors regular
|
Myspace is so *****ty it's not even funny. It's the slowest running web site on the internet, and it's always down.
They should resolve some of their own issues before they go and tell Apple what to do... |
|
|
|
|
|
#19 | |
|
Demi-God (Moderator)
Join Date: Jan 2004
Location: Grand Rapids, MI, USA
|
Quote:
However, it's important to note I think that QT is the VECTOR. That is, it delivers the exploit, but the exploit itself seems to be a Windows exploit... as far as I know there isn't any evidence of MacOS spyware related to this... just Windows? Nonetheless, if this impacts OS X as a vector, it's a missing link, because there's never really been an exploited vulnerability in OS X that allowed software to be installed without user intervention before.
__________________
Mohan |
|
|
|
|
|
|
#20 |
|
macrumors 6502a
Join Date: Jul 2003
|
Fixing vuneralbilities is a good thing. Shame it came to light because of myspace. Yuck
|
|
|
|
|
|
#21 | |
|
macrumors 65816
Join Date: Jun 2004
|
Quote:
Basically an interactivity feature of QuickTime (exists for various good reasons) is being leveraged to bring up a spoofed login page attempting to trick a myspace user to provide their login information. If they do that then javascript in the spoofed webpage then walks their myspace site attempting to inject links to a fishing site and add the QuickTime movie to the users site. So I really don't see the vulnerability existing in QuickTime... any number of other methods could be used to attempt similar trickery (flash can do similar things). All I can see Apple doing is providing a way for a hosting site to disable this feature for all movies downloaded from its site (likely strip the track). ...welcome to wonderful world of cross-site scripting attacks.
__________________
Steve Balmers the CEO of Microsoft... Dance Monkey, Developers!, The remix, The ad Last edited by shawnce : Dec 6, 2006 at 12:33 PM. |
|
|
|
|
|
|
#22 |
|
macrumors god
Join Date: Sep 2002
Location: at the table with countless relatives
|
I'd like to know if it's technically a feature of QuickTime, a vulnerability of QuickTime, or a bug in QuickTime. The choice might involve semantics, but it's also a technical distinction.
Is a feature being removed?
__________________
"You've just been abducted, of course you need crepes!" -- Walter Bishop |
|
|
|
|
|
#23 |
|
Demi-God (Moderator)
Join Date: Jan 2004
Location: Grand Rapids, MI, USA
|
That's a good question...although, I would tend to think that if whatever is involved here was being used frequently, this exploit would have been identified already. But then you never know.
__________________
Mohan |
|
|
|
|
|
#24 |
|
macrumors regular
Join Date: Apr 2006
Location: NEK
|
Well, maybe if the worm actual only effected the MySpace users seen on DateLine's "To Catch a Predator", it would be a good thing.
Actually...aren't most....nahhy, I won't go there. Kudos for Apple to step up even if is is a combination of issues with QT and MySpace and IE. |
|
|
|
|
|
#25 |
|
macrumors 6502
Join Date: Dec 2004
Location: of my hand will get me slapped.
|
I demand MySpace do more to make sure pedophiles stay out.
__________________
SE30 | Bondi Blu iMac | iBook G3 700 - 384 Megs 40gig |5th gen iPod 30gig Video | 17" 2.0 CD2 iMac |20" 2.16 CD2 iMac |5gb 1st Gen iPhone |
|
|
|
![]() |
| Thread Tools | Search this Thread |
| Display Modes | |
|
|