Microsoft Windows Vista Community Forums - Vistaheads
Driver Scanner 2009 - Free Scan Now



Welcome to the Microsoft Windows Vista Community Forums - Vistaheads, YOUR Largest Resource for Windows Vista related information.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so , join our community today!

If you have any problems with the registration process or your account login, please contact us.

Registry Mechanic - Free Scan Now

QuickSpace: MySpace Tracker Launch by QuickTime

Security News



Click On Your Flag for Translation
Simplified Chinese French Spanish Italian Portugeuse Japanese German Dutch
Reply
  #1 (permalink)  
Old 03-23-2007
Paul's Avatar
Paul Paul is offline
Moderator
 

Join Date: Feb 2007
Location: wicklow mts
Posts: 9,491
Paul is on a distinguished road
Thanks: 0
Thanked 0 Times in 0 Posts
QuickSpace: MySpace Tracker Launch by QuickTime
We've seen another attack using an insecure feature of QuickTime called HREF Tracks. This is a feature that can specify movies from other links to automatically open simultaneously when the movie is run. With the QuickTime sample that we received, it will try to download and execute a spying JavaScript from this website:

http://profileawareness.com/logs4/[removed].js
We detect the JavaScript as Trojan-Spy:JS/Spacestalk.A. We detect the downloader as
Trojan-Downloader:JS/Spacestalk.A.

The said script collects MySpace information from the user that includes Username, FriendID, MySpace Display Name, and other logins of the user, and sends this information back to the tracking server at http://profileawareness.com together with the current URL as well as the current referrers' page.

Updated to add:
We would like to note that Apple resolved this issue with QuickTime 7.1.5 – released on March 5th. See CVE-ID: CVE-2006-4965, CVE-2007-0059 for all the details.
From Apple's website:
QuickTime 7.1.5 for Windows may be obtained from the Apple Software Update application, or as a manual download from: http://www.apple.com/quicktime/download/win.html
So, you'll need Apple Software Update installed or else you'll have to perform a manual download. We've already posted on manually downloading QuickTime. Some of ours readers wrote to tell us that the update automation also includes "optional recommendations" to install iTunes…

This isn't particularly useful to those of us with corporate machines that want QuickTime but not iTunes. On 19/03/07 At 06:07 AM


More...
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
QuickSpace: MySpace Tracker Launch by QuickTime Paul Security News 0 03-21-2007 18:31
New QuickTime exploit hits MySpace, steals passwords BlogFeed Windows Vista Blogs Forum 0 03-21-2007 18:31
QuickSpace: MySpace Tracker Launch by QuickTime Paul Security News 0 03-19-2007 19:24
QuickSpace: MySpace Tracker launch by Quicktime Paul Security News 0 03-19-2007 07:56
MySpace-hosted malware exploits QuickTime flaw BlogFeed Windows Vista Blogs Forum 0 03-17-2007 02:39


All times are GMT +1. The time now is 07:36.


Registry Mechanic - Free Scan Now
Driver Scanner 2009 - Free Scan Now




Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.7
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.0.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119