<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Serious Flaw in Popular Media Players from Microsoft and AOL</title>
	<atom:link href="http://www.darknet.org.uk/2007/12/serious-flaw-in-popular-media-players-from-microsoft-and-aol/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk/2007/12/serious-flaw-in-popular-media-players-from-microsoft-and-aol/</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<pubDate>Thu, 04 Dec 2008 16:28:48 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.5</generator>
		<item>
		<title>By: eM3rC</title>
		<link>http://www.darknet.org.uk/2007/12/serious-flaw-in-popular-media-players-from-microsoft-and-aol/#comment-94014</link>
		<dc:creator>eM3rC</dc:creator>
		<pubDate>Sun, 06 Jan 2008 22:16:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2007/12/serious-flaw-in-popular-media-players-from-microsoft-and-aol/#comment-94014</guid>
		<description>Although this is more the users fault for not updating rather than microsoft, it seems like there should be some security update or alert specifically for people who are vulnerable to this exploit.

Plus, its microsoft... Enough said...</description>
		<content:encoded><![CDATA[<p>Although this is more the users fault for not updating rather than microsoft, it seems like there should be some security update or alert specifically for people who are vulnerable to this exploit.</p>
<p>Plus, its microsoft&#8230; Enough said&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sir Henry</title>
		<link>http://www.darknet.org.uk/2007/12/serious-flaw-in-popular-media-players-from-microsoft-and-aol/#comment-83529</link>
		<dc:creator>Sir Henry</dc:creator>
		<pubDate>Fri, 14 Dec 2007 16:49:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2007/12/serious-flaw-in-popular-media-players-from-microsoft-and-aol/#comment-83529</guid>
		<description>@Pantagruel:

I, too, am within the population of busy bees you described.  Should I encounter a free moment today, I shall see what ground I can cover.  I will report back with any updates as I have them.</description>
		<content:encoded><![CDATA[<p>@Pantagruel:</p>
<p>I, too, am within the population of busy bees you described.  Should I encounter a free moment today, I shall see what ground I can cover.  I will report back with any updates as I have them.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nobody_Holme</title>
		<link>http://www.darknet.org.uk/2007/12/serious-flaw-in-popular-media-players-from-microsoft-and-aol/#comment-83507</link>
		<dc:creator>Nobody_Holme</dc:creator>
		<pubDate>Fri, 14 Dec 2007 15:11:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2007/12/serious-flaw-in-popular-media-players-from-microsoft-and-aol/#comment-83507</guid>
		<description>I do update my QT... makes life easier. hadnt spotted that latest though. Off i go to download it.</description>
		<content:encoded><![CDATA[<p>I do update my QT&#8230; makes life easier. hadnt spotted that latest though. Off i go to download it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pantagruel</title>
		<link>http://www.darknet.org.uk/2007/12/serious-flaw-in-popular-media-players-from-microsoft-and-aol/#comment-83500</link>
		<dc:creator>Pantagruel</dc:creator>
		<pubDate>Fri, 14 Dec 2007 14:59:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2007/12/serious-flaw-in-popular-media-players-from-microsoft-and-aol/#comment-83500</guid>
		<description>@ Sir Henry

I guess most of us are busy doing other stuff (I certainly am), securing machines, applying patches, etc.
But give it a whirl, get vmware (or any other virtual environment) and install a 'virgin' version of XP and try the exploits available. We'll be eager to read your first hand experience. After a look at my 'to-do'list this exploit most likely will have to wait untill somewhere next week.</description>
		<content:encoded><![CDATA[<p>@ Sir Henry</p>
<p>I guess most of us are busy doing other stuff (I certainly am), securing machines, applying patches, etc.<br />
But give it a whirl, get vmware (or any other virtual environment) and install a &#8216;virgin&#8217; version of XP and try the exploits available. We&#8217;ll be eager to read your first hand experience. After a look at my &#8216;to-do&#8217;list this exploit most likely will have to wait untill somewhere next week.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sir Henry</title>
		<link>http://www.darknet.org.uk/2007/12/serious-flaw-in-popular-media-players-from-microsoft-and-aol/#comment-83472</link>
		<dc:creator>Sir Henry</dc:creator>
		<pubDate>Fri, 14 Dec 2007 14:07:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2007/12/serious-flaw-in-popular-media-players-from-microsoft-and-aol/#comment-83472</guid>
		<description>So, has anyone here actually tried the exploit?  Given, I do not normally use those apps, but I would be intrigued to see a hands-on with these vulnerabilities.</description>
		<content:encoded><![CDATA[<p>So, has anyone here actually tried the exploit?  Given, I do not normally use those apps, but I would be intrigued to see a hands-on with these vulnerabilities.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pantagruel</title>
		<link>http://www.darknet.org.uk/2007/12/serious-flaw-in-popular-media-players-from-microsoft-and-aol/#comment-83452</link>
		<dc:creator>Pantagruel</dc:creator>
		<pubDate>Fri, 14 Dec 2007 12:55:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2007/12/serious-flaw-in-popular-media-players-from-microsoft-and-aol/#comment-83452</guid>
		<description>Apple released a patch for QT 7.3.1 yesterday removing the problems you run into when opening QTL and RTSP.
Get the patch at www.apple.com/support/downloads</description>
		<content:encoded><![CDATA[<p>Apple released a patch for QT 7.3.1 yesterday removing the problems you run into when opening QTL and RTSP.<br />
Get the patch at <a href="http://www.apple.com/support/downloads" rel="nofollow">http://www.apple.com/support/downloads</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sKreeM</title>
		<link>http://www.darknet.org.uk/2007/12/serious-flaw-in-popular-media-players-from-microsoft-and-aol/#comment-83240</link>
		<dc:creator>sKreeM</dc:creator>
		<pubDate>Thu, 13 Dec 2007 19:42:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2007/12/serious-flaw-in-popular-media-players-from-microsoft-and-aol/#comment-83240</guid>
		<description>Ohhhh... I was expecting an MP4 video broadcast of this news</description>
		<content:encoded><![CDATA[<p>Ohhhh&#8230; I was expecting an MP4 video broadcast of this news</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pantagruel</title>
		<link>http://www.darknet.org.uk/2007/12/serious-flaw-in-popular-media-players-from-microsoft-and-aol/#comment-83150</link>
		<dc:creator>Pantagruel</dc:creator>
		<pubDate>Thu, 13 Dec 2007 15:27:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2007/12/serious-flaw-in-popular-media-players-from-microsoft-and-aol/#comment-83150</guid>
		<description>@ Nobody_Holme

Even QT sufferes from bug and vuln (have a look at http://secunia.com/advisories/27755/ )

A similar vulnerability is mentioned (http://secunia.com/advisories/26034/)  also sporting a 'crafted' file 
as point of entry. Results range from memory corruption upto arbitrary code execution.

So even here the adagio: 'Patch, patch and moreover patch' applies.</description>
		<content:encoded><![CDATA[<p>@ Nobody_Holme</p>
<p>Even QT sufferes from bug and vuln (have a look at <a href="http://secunia.com/advisories/27755/" rel="nofollow">http://secunia.com/advisories/27755/</a> )</p>
<p>A similar vulnerability is mentioned (http://secunia.com/advisories/26034/)  also sporting a &#8216;crafted&#8217; file<br />
as point of entry. Results range from memory corruption upto arbitrary code execution.</p>
<p>So even here the adagio: &#8216;Patch, patch and moreover patch&#8217; applies.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nobody_Holme</title>
		<link>http://www.darknet.org.uk/2007/12/serious-flaw-in-popular-media-players-from-microsoft-and-aol/#comment-83142</link>
		<dc:creator>Nobody_Holme</dc:creator>
		<pubDate>Thu, 13 Dec 2007 14:49:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2007/12/serious-flaw-in-popular-media-players-from-microsoft-and-aol/#comment-83142</guid>
		<description>@Pantagruel
Good point. Thats why all such sites should use quicktime...
I had never thought of youtube... thank god for running a recent version of XP and having a fairly up-to-date WMP. now i'm off to update a program i dont intentionally use for the first time ever...</description>
		<content:encoded><![CDATA[<p>@Pantagruel<br />
Good point. Thats why all such sites should use quicktime&#8230;<br />
I had never thought of youtube&#8230; thank god for running a recent version of XP and having a fairly up-to-date WMP. now i&#8217;m off to update a program i dont intentionally use for the first time ever&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pantagruel</title>
		<link>http://www.darknet.org.uk/2007/12/serious-flaw-in-popular-media-players-from-microsoft-and-aol/#comment-83108</link>
		<dc:creator>Pantagruel</dc:creator>
		<pubDate>Thu, 13 Dec 2007 11:21:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2007/12/serious-flaw-in-popular-media-players-from-microsoft-and-aol/#comment-83108</guid>
		<description>@ cpj

Indeed you might expect no problems if users do not use media player (as such). The bigger problem is websites like YouTube which use the webbrowser to display video and sound through the installed codecs.
This will eventually get people into trouble and will force them to update (without ever actually using WMP) or suffer a breach/hanging Windows XP/Vista.
Eventhough my parents are basic computer and internet users, they are aware of YouTube and browse about for the sheer fun of it (wondering why someone would put such content of him/herself on the www). This is already enough to keep your codecs up to scratch.</description>
		<content:encoded><![CDATA[<p>@ cpj</p>
<p>Indeed you might expect no problems if users do not use media player (as such). The bigger problem is websites like YouTube which use the webbrowser to display video and sound through the installed codecs.<br />
This will eventually get people into trouble and will force them to update (without ever actually using WMP) or suffer a breach/hanging Windows XP/Vista.<br />
Eventhough my parents are basic computer and internet users, they are aware of YouTube and browse about for the sheer fun of it (wondering why someone would put such content of him/herself on the www). This is already enough to keep your codecs up to scratch.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
