Quicktime Javascript exploit (the MySpace worm)

Discussion started by Mr. Uh Clem, Dec 5, 2006.

  Mr. Uh Clem

    Mr. Uh Clem Guest

    After reading the limited coverage of the MySpace worm such as
    I'm left with some questions.

    1.) Does this affect both Windows & OS X?

    2.) Does this affect all browsers that use the Quicktime plugin?
    Are some more secure than others?

    3.) Is there a way to turn off the bloody javascript in the
    Quicktime plugin?

    4.) Does this vulnerability itself pose a threat to the exploited

    I don't personally use MySpace, but the word does need to get
    out and I'm curious about the vulnerability itself. My gut says
    this worm is completely cross-platform, but I haven't seen much
    on the details of what is vulnerable in terms of browsers &
    operating systems.
    Dec 5, 2006
  Mr. Uh Clem

    Mr. Uh Clem Guest

    But the next paragraph says: "The same happens when viewing an
    infected page with Firefox, according to a CNET News.com reader who
    had his MySpace profile compromised." (I hadn't caught that before -
    so it IS cross browser.) I've seen nothing to rule out OS X...
    Dec 5, 2006
  Mr. Uh Clem

    ZnU

    The exploit is using a designed feature of the QuickTime plug-in. An
    unintentional behavior might only exist on one platform, due to an
    error, but an intentional behavior is presumably going to exist across
    all platforms.

    Browsers implicitly trust scripts loaded from a domain to manipulate
    pages hosted on that domain, on the basis that if something is hosted on
    a domain, it must legitimately belong there. This assumption clearly
    breaks down with sites like MySpace that let untrusted users upload
    arbitrary content.
    No. It's basically just using JavaScript to manipulate some data on a
    web page.
    ZnU, Dec 5, 2006
  Mr. Uh Clem

    bogdan

    Mr. Uh Clem wrote:

    bogdan, Dec 6, 2006
