|
|
| Welcome to the Mac Forums forums. Please read the FAQ if you have questions. Register to participate. |
|
|||||||
| TouchArcade.com - iPhone Game Reviews and News |
![]() |
|
|
Thread Tools | Search this Thread |
|
|
|
|
#1 | |
|
macrumors bot
Join Date: Apr 2001
|
Apple Hardens Quicktime Security
![]() With Quicktime increasingly becoming a target for malicious hackers, eWeek reports that Apple has made several steps to make Quicktime more secure in the latest version (7.4.5) released just last week. Besides patching 11 security vulnerabilities, the new version of Quicktime adds a few new features such as ASLR (address space layout randomization), stack buffer safety checking and function call hardening, all of which make it much more difficult to hack Quicktime. Security researchers have applauded the efforts: Quote:
|
|
|
|
|
|
|
#2 | |
|
macrumors newbie
Join Date: Jul 2005
|
Quote:
|
|
|
|
|
|
|
#3 | |
|
macrumors 6502
Join Date: Feb 2007
|
Quote:
|
|
|
|
|
| eastcoastsurfer |
| View Public Profile |
| Find More Posts by eastcoastsurfer |
|
|
#4 | |
|
macrumors regular
Join Date: Jan 2006
|
Quote:
|
|
|
|
|
|
|
#5 |
|
macrumors Demi-God
|
security is an on-going process, and i'm glad that Apple are trying to be pro-active about it rather than reactionary, for the most part.
|
|
|
|
| PlaceofDis |
| View Public Profile |
| Find More Posts by PlaceofDis |
|
|
#6 | |
|
macrumors 601
Join Date: Aug 2006
|
Quote:
Too bad safari still doesn't offer this.Anyway, there is always noscripts for firefox.. PS. my impression is that XSS isn't all bad, somebody clarify this? PS2. I noticed two updates (iTunes 7.6.2and QT 7.4.5) again are ~90MB in size.. will apple ever be able to make some partial update packages and save me some download time? or people with slow internet speed don't deserve same level of security? |
|
|
|
|
|
|
#7 | |
|
Contributor
Join Date: Nov 2005
Location: Oxford, UK
|
Quote:
Well its not, the website I noticed this on was using it legitimately. However they could have done it another way and to be honest it doesn't really have too many legitimate uses. |
|
|
|
|
| Eraserhead |
| View Public Profile |
| Find More Posts by Eraserhead |
|
|
#8 | |
|
macrumors 6502
Join Date: Sep 2006
Location: Upstate NY
|
Quote:
But Phishing is actually more subtile. Let say i go to XYZBank.com but I typed in XYZBenk.com or XYZ-Bank.com... Something I wouldn't quickly catch. And the site looks just like my bank. I enter my password and username. It give an error that that back site is under maintentance.... But by that time I am already dead.
__________________
17" Core 2 Duo MacBook Pro 3GB of RAM, 100GB 7200 RPM, Glossy |
|
|
|
|
| jellomizer |
| View Public Profile |
| Find More Posts by jellomizer |
|
|
#9 | |
|
macrumors member
Join Date: Feb 2007
Location: Melbourne, Australia
|
Quote:
LOL - or for those of us who have a download quota on their broadband plan and need to be frugal about what they download..... or suffer getting 'shaped" back to 64kb till the next bill cycle date!!
|
|
|
|
|
|
|
#10 | |
|
macrumors 6502a
Join Date: May 2002
Location: Bay Area, CA
|
Quote:
If you have a slow internet connection or a bandwidth quota, just go to your nearest Apple retail store and ask them to burn a CD of updates for you.
__________________
Get Memory Usage Getter, the only Mac OS X utility that graphically displays the memory and CPU usage of every open process! 800 MHz 17" G4 iMac | 1 GB RAM | SuperDrive | OS X 10.3.2 | iPod Join the MacRumors SETI team, and help kick Symantec off the Top 200 list! |
|
|
|
|
|
|
#11 | |
|
macrumors regular
Join Date: Jan 2006
|
Quote:
forever.b0rked explains what I tried to rhetorically ask Eraserhead |
|
|
|
|
|
|
#12 | |
|
Contributor
Join Date: Nov 2005
Location: Oxford, UK
|
Quote:
Unsafe Javascript attempt to access http://www.somewebsite.com from frame with URL http://blahblah.somewebsite.com domains, protocols and ports must match |
|
|
|
|
| Eraserhead |
| View Public Profile |
| Find More Posts by Eraserhead |
|
|
#13 | |
|
macrumors 6502
Join Date: Nov 2004
|
Quote:
when I clicked 'somewebsite'-I got that; when I clicked 'blahblah' I get to the Open DNS page (using Safari) I guess a good question would be: we live in the 21st century-why is SAFARI still allowed to be phished...? Last edited by seashellz : Apr 8, 2008 at 03:31 PM. |
|
|
|
|
|
|
#14 |
|
Contributor
Join Date: Nov 2005
Location: Oxford, UK
|
Good to know that they've improved it. I notice that the latest Safari has also blocked cross site scripting, unlike Internet Explorer and Firefox.
|
|
|
|
| Eraserhead |
| View Public Profile |
| Find More Posts by Eraserhead |
|
|
#15 |
|
macrumors 6502
|
Great job Apple
![]() ![]() !Now who is rating this negative why would this be negative? For hackers? MS fanboys?
Last edited by TheSpecialist : Apr 8, 2008 at 09:23 AM. |
|
|
|
| TheSpecialist |
| View Public Profile |
| Find More Posts by TheSpecialist |
|
|
#16 |
|
macrumors 68020
|
I guess you don't want to make an announcement that you've tightened things up, only to have everyone look for that one error in coding and then say you really haven't done the job... best to just secretly update it. Point release FTW!
|
|
|
|
|
|
#17 |
|
macrumors regular
Join Date: Jul 2006
Location: Boston, MA
|
This is pretty cool. I honestly was getting a bit concerned about how many exploits were targeting Quicktime specifically, and this seems like a logical reaction.
|
|
|
|
|
|
#18 |
|
macrumors 68020
Join Date: Nov 2003
|
Quicktime is great – it was the first proper multimedia software for home computers.
The problem is a lot of the code is very old now and mistakes were probably made that would not be made today – benefit of hindsight etc. That said it is good Apple are making positive steps towards locking down some of the vulnerabilities. Security is a continuous process though.
__________________
Snow Leopard is animated |
|
|
|
|
|
#19 | |
|
macrumors 68040
Join Date: Mar 2003
Location: California
|
Quote:
Is it? You'd think that they'd rewrite it from the ground up for todays world...
__________________
The Un-Funny Truth About Scientology (Warning: Graphic images) MacBook Pro 15.4"/2.5 GHz/250GB/4GB RAM iMac G4 17"/800 Mhz/80GB/512GB RAM |
|
|
|
|
| Stridder44 |
| View Public Profile |
| Find More Posts by Stridder44 |
|
|
#20 | |
|
macrumors 6502
Join Date: Sep 2006
Location: Upstate NY
|
Quote:
Still today actually using a bufferoverflow is a hard hack. But it was possible. Just with memory randomization it helps fix the dependability of such hack.
__________________
17" Core 2 Duo MacBook Pro 3GB of RAM, 100GB 7200 RPM, Glossy |
|
|
|
|
| jellomizer |
| View Public Profile |
| Find More Posts by jellomizer |
|
|
#21 |
|
macrumors 6502a
Join Date: Aug 2003
|
|
|
|
|
|
|
#22 | |
|
macrumors 6502
Join Date: Mar 2007
|
Quote:
Then again for all we know, Apple has been working on this and testing for a year... That said, I did not give it a negative, but I also abstained from a positive.
__________________
MacBookPro-MacBook-MacMini-iPhone-AppleTV-AEBS-iPodMini |
|
|
|
|
|
|
#23 | |
|
Banned
|
Quote:
|
|
|
|
|
|
|
#24 | |
|
macrumors member
Join Date: Nov 2005
|
Quote:
PS: I rated it positive, mind you Last edited by jz1492 : Apr 8, 2008 at 01:34 PM. Reason: Disclaimer |
|
|
|
|
|
|
#25 |
|
macrumors 65816
Join Date: Aug 2007
Location: Apple Store Buchanan
|
I really think this is good to hear this. Apple at the moment should take a step back for five minutes from this relentless pace they are going at at the moment and iron out all the bugs and secure everything up so they can carry on with a good basis to be working from. If they keep going at this rate the platform as a whole will suffer as it gets greatly complicated to keep all the devices under control.
|
|
|
|
| Santa Rosa |
| View Public Profile |
| Find More Posts by Santa Rosa |
![]() |
| Thread Tools | Search this Thread |
| Display Modes | |
|
|