<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Matasano Chargen - Latest Comments in URGENT: Unconfirmed Reports QuickTime Exploit Capture Is Circulating</title><link>http://matasanochargen.disqus.com/</link><description></description><language>en</language><lastBuildDate>Tue, 01 May 2007 17:09:18 -0000</lastBuildDate><item><title>Re: URGENT: Unconfirmed Reports QuickTime Exploit Capture Is Circulating</title><link>http://www.matasano.com/log/840/urgent-turn-off-java-in-your-browser/#comment-2322459</link><description>Update - QuickTime 7.1.6 has been released today, and apparently fixes the problem.  Kudos to Apple.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David Schor</dc:creator><pubDate>Tue, 01 May 2007 17:09:18 -0000</pubDate></item><item><title>Re: URGENT: Unconfirmed Reports QuickTime Exploit Capture Is Circulating</title><link>http://www.matasano.com/log/840/urgent-turn-off-java-in-your-browser/#comment-2322436</link><description>Cue Lalo Shiffrin soundtrack.... you may want to consider moving to a virtual env altogether, and ask yourself where your hardware came from, for starters. &lt;br&gt;&lt;br&gt;Summer should be a fun time. &lt;br&gt;&lt;br&gt;H</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">HAL</dc:creator><pubDate>Fri, 27 Apr 2007 12:35:11 -0000</pubDate></item><item><title>Re: URGENT: Unconfirmed Reports QuickTime Exploit Capture Is Circulating</title><link>http://www.matasano.com/log/840/urgent-turn-off-java-in-your-browser/#comment-2322458</link><description>Possibly because it's a Quicktime vuln, and not a Java vuln? If it's a shellcode-based exploit, maybe you can use Java to cross-platform shove code at it, but that doesn't necessarily mean it's going to execute.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Ryan Russell</dc:creator><pubDate>Thu, 26 Apr 2007 00:48:45 -0000</pubDate></item><item><title>Re: URGENT: Unconfirmed Reports QuickTime Exploit Capture Is Circulating</title><link>http://www.matasano.com/log/840/urgent-turn-off-java-in-your-browser/#comment-2322457</link><description>If it's a Java bug, I don't see why it wouldn't.&lt;br&gt;Remember, Java's selling point was write once run anywhere.  ;-)</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Hash</dc:creator><pubDate>Wed, 25 Apr 2007 21:06:45 -0000</pubDate></item><item><title>Re: URGENT: Unconfirmed Reports QuickTime Exploit Capture Is Circulating</title><link>http://www.matasano.com/log/840/urgent-turn-off-java-in-your-browser/#comment-2322435</link><description>Any news on whether this exploit works on PPC machines?</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David Schor</dc:creator><pubDate>Wed, 25 Apr 2007 20:08:50 -0000</pubDate></item><item><title>Re: URGENT: Unconfirmed Reports QuickTime Exploit Capture Is Circulating</title><link>http://www.matasano.com/log/840/urgent-turn-off-java-in-your-browser/#comment-2322456</link><description>The latest versions of NoScript can block Java (as well as JavaScript, Flash, other Plugins, and some XSS. You have the option to allow these for "trusted" sites.  See the screen shot under mitigation that I posted: &lt;a href="http://www.nist.org/news.php?extend.226" rel="nofollow"&gt;http://www.nist.org/news.php?extend.226&lt;/a&gt;  &lt;br&gt;&lt;br&gt;If the browser never processes the Java code it can't pass it on to Quicktime. You may want check the box to not allow any plugins on untrusted sites just in case.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">John Herron</dc:creator><pubDate>Wed, 25 Apr 2007 18:38:07 -0000</pubDate></item><item><title>Re: URGENT: Unconfirmed Reports QuickTime Exploit Capture Is Circulating</title><link>http://www.matasano.com/log/840/urgent-turn-off-java-in-your-browser/#comment-2322455</link><description>I don't like it either, but them's the breaks. Matasano isn't directly involved in this exercise; we're just reporting what we hear.&lt;br&gt;&lt;br&gt;The problem is that we've confirmed that disabling Java (or QuickTime) mitigates the vulnerability, but haven't firmed deleting specific Java components will. I totally believe your solution could work, but I can't confirm it.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Ptacek</dc:creator><pubDate>Wed, 25 Apr 2007 17:06:15 -0000</pubDate></item><item><title>Re: URGENT: Unconfirmed Reports QuickTime Exploit Capture Is Circulating</title><link>http://www.matasano.com/log/840/urgent-turn-off-java-in-your-browser/#comment-2322454</link><description>Could you simply rename the "QTJava.zip" file and continue to use Java as you normally would?  I don't like that you're advising to disable one vendor's software in order to protect against a vulnerability in another vendor's product.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Don jackson</dc:creator><pubDate>Wed, 25 Apr 2007 15:33:56 -0000</pubDate></item><item><title>Re: URGENT: Unconfirmed Reports QuickTime Exploit Capture Is Circulating</title><link>http://www.matasano.com/log/840/urgent-turn-off-java-in-your-browser/#comment-2322453</link><description>It seems like the the advanced no plugins, no java, and no flash options in noscript would be preventative enough.  Whether it's an embedded quicktime object or embedded java applet, both are blocked by a recent noscript with those options on.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Jordan Wiens</dc:creator><pubDate>Wed, 25 Apr 2007 15:17:26 -0000</pubDate></item><item><title>Re: URGENT: Unconfirmed Reports QuickTime Exploit Capture Is Circulating</title><link>http://www.matasano.com/log/840/urgent-turn-off-java-in-your-browser/#comment-2322452</link><description>Ok so quicktime is required, I am saved via lack of functionality and support :D  thanks</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Chris Rohlf</dc:creator><pubDate>Wed, 25 Apr 2007 15:03:16 -0000</pubDate></item><item><title>Re: URGENT: Unconfirmed Reports QuickTime Exploit Capture Is Circulating</title><link>http://www.matasano.com/log/840/urgent-turn-off-java-in-your-browser/#comment-2322451</link><description>Firefox is vulnerable, with or without NoScript.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">carl</dc:creator><pubDate>Wed, 25 Apr 2007 15:00:31 -0000</pubDate></item><item><title>Re: URGENT: Unconfirmed Reports QuickTime Exploit Capture Is Circulating</title><link>http://www.matasano.com/log/840/urgent-turn-off-java-in-your-browser/#comment-2322450</link><description>No confirmation of Linux. What's the disposition of QuickTime on Linux?&lt;br&gt;&lt;br&gt;Again, as regards vulnerability details: it requires Java and QuickTime, and has been confirmed on FF/X, FireFox, Safari, IE6, and IE7 XP.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Ptacek</dc:creator><pubDate>Wed, 25 Apr 2007 15:00:25 -0000</pubDate></item><item><title>Re: URGENT: Unconfirmed Reports QuickTime Exploit Capture Is Circulating</title><link>http://www.matasano.com/log/840/urgent-turn-off-java-in-your-browser/#comment-2322449</link><description>Ok too many people are saying too many things and I have been out of the loop this week, busy with other things. Firefox on Linux, vulnerable? Not vulnerable? Thanks</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Chris Rohlf</dc:creator><pubDate>Wed, 25 Apr 2007 14:59:03 -0000</pubDate></item><item><title>Re: URGENT: Unconfirmed Reports QuickTime Exploit Capture Is Circulating</title><link>http://www.matasano.com/log/840/urgent-turn-off-java-in-your-browser/#comment-2322448</link><description>No. Definitely stop living dangerously. I feel dumb for being cavalier about this finding.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Ptacek</dc:creator><pubDate>Wed, 25 Apr 2007 14:47:40 -0000</pubDate></item><item><title>Re: URGENT: Unconfirmed Reports QuickTime Exploit Capture Is Circulating</title><link>http://www.matasano.com/log/840/urgent-turn-off-java-in-your-browser/#comment-2322447</link><description>It's very, very possible that someone is "auditing" a reverse engineer of various libraries based on the crash log snippets posted earlier. While they won't help much, they may help just enough. I even thought about using them to find what's what. But then I figured it'd take too much time to reproduce the exact config in order to make it easier for me. Laziness wins again.&lt;br&gt;&lt;br&gt;Also, people could just be searching the various codepoints like crazy trying to find anything that could resemble this bug.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Rosyna</dc:creator><pubDate>Wed, 25 Apr 2007 14:47:26 -0000</pubDate></item><item><title>Re: URGENT: Unconfirmed Reports QuickTime Exploit Capture Is Circulating</title><link>http://www.matasano.com/log/840/urgent-turn-off-java-in-your-browser/#comment-2322446</link><description>Thomas, so we can continue to live dangerously? Throw caution to the wind? Have our cake and eat it too?&lt;br&gt;&lt;br&gt;Also, how about we just call it Java and ECMAScript from now on? The latter is probably more accurate as well.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Rosyna</dc:creator><pubDate>Wed, 25 Apr 2007 14:42:40 -0000</pubDate></item><item><title>Re: URGENT: Unconfirmed Reports QuickTime Exploit Capture Is Circulating</title><link>http://www.matasano.com/log/840/urgent-turn-off-java-in-your-browser/#comment-2322445</link><description>Someone may have reverse-engineered the vulnerability but they didn't pull it off the network there. The network was very simple:&lt;br&gt;a WAP that was connected to a hub and to the router to provide Internet access. The Macs sat on the hub and the only other systems on there were the ones we used to monitor the network to ensure rules were followed and then K2's when he ran the exploit. The WAP was routing traffic from the hub to the Internet, not sending it out over the wireless network.&lt;br&gt;We were sniffing the traffic on the wireless network and would have noticed if it had been getting traffic from the wired side.&lt;br&gt;Y'all know routing &amp;amp; switching protocols well enough to know that traffic destined for the Internet wouldn't end up on the pocket wireless network. The AP doesn't have enough smarts to mess up routing that way unless someone owned it (which is admittedly possible).&lt;br&gt;The point is, no one sitting on the wireless network would have been able to sniff the traffic from the wired network to the Internet.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">toby</dc:creator><pubDate>Wed, 25 Apr 2007 14:29:30 -0000</pubDate></item><item><title>Re: URGENT: Unconfirmed Reports QuickTime Exploit Capture Is Circulating</title><link>http://www.matasano.com/log/840/urgent-turn-off-java-in-your-browser/#comment-2322444</link><description>JavaScript and Java have absolutely nothing in common except a poorly-chosen name. Disabling JavaScript (directly or via NoScript) has no effect on Java code.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Drew Thaler</dc:creator><pubDate>Wed, 25 Apr 2007 14:04:16 -0000</pubDate></item><item><title>Re: URGENT: Unconfirmed Reports QuickTime Exploit Capture Is Circulating</title><link>http://www.matasano.com/log/840/urgent-turn-off-java-in-your-browser/#comment-2322443</link><description>"The NoScript Firefox extension provides extra protection for Firefox, Flock, Seamonkey and others mozilla-based browsers: this free, open source add-on allows JavaScript and Java execution only for trusted domains."&lt;br&gt;&lt;br&gt;It includes Java.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Jon Bowie</dc:creator><pubDate>Wed, 25 Apr 2007 14:04:04 -0000</pubDate></item><item><title>Re: URGENT: Unconfirmed Reports QuickTime Exploit Capture Is Circulating</title><link>http://www.matasano.com/log/840/urgent-turn-off-java-in-your-browser/#comment-2322442</link><description>You don't need to disable Javascript. Javascript and Java are unrelated.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Ptacek</dc:creator><pubDate>Wed, 25 Apr 2007 13:58:20 -0000</pubDate></item><item><title>Re: URGENT: Unconfirmed Reports QuickTime Exploit Capture Is Circulating</title><link>http://www.matasano.com/log/840/urgent-turn-off-java-in-your-browser/#comment-2322441</link><description>I've used the NoScript Firefox plugin for awhile now:&lt;br&gt;&lt;br&gt;&lt;a href="http://noscript.net/" rel="nofollow"&gt;http://noscript.net/&lt;/a&gt;&lt;br&gt;&lt;br&gt;By default it completely disables javascript, allowing for user-based manual exclusion of sites you trust.&lt;br&gt;&lt;br&gt;I haven't audited it, so caveat emptor.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Jon Bowie</dc:creator><pubDate>Wed, 25 Apr 2007 13:56:55 -0000</pubDate></item><item><title>Re: URGENT: Unconfirmed Reports QuickTime Exploit Capture Is Circulating</title><link>http://www.matasano.com/log/840/urgent-turn-off-java-in-your-browser/#comment-2322440</link><description>You can remove QuickTime as well, and that will also solve the problem. It's harder to do that than to click the Java checkbox in the browser, which is why we're recommending it.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Ptacek</dc:creator><pubDate>Wed, 25 Apr 2007 13:56:54 -0000</pubDate></item><item><title>Re: URGENT: Unconfirmed Reports QuickTime Exploit Capture Is Circulating</title><link>http://www.matasano.com/log/840/urgent-turn-off-java-in-your-browser/#comment-2322439</link><description>Why Should I disable Java? The flaw is in Apple QuickTime and so I disable QuickTime</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">carl</dc:creator><pubDate>Wed, 25 Apr 2007 13:52:18 -0000</pubDate></item><item><title>Re: URGENT: Unconfirmed Reports QuickTime Exploit Capture Is Circulating</title><link>http://www.matasano.com/log/840/urgent-turn-off-java-in-your-browser/#comment-2322438</link><description>You don't know that, yet.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Ptacek</dc:creator><pubDate>Wed, 25 Apr 2007 13:26:48 -0000</pubDate></item><item><title>Re: URGENT: Unconfirmed Reports QuickTime Exploit Capture Is Circulating</title><link>http://www.matasano.com/log/840/urgent-turn-off-java-in-your-browser/#comment-2322437</link><description>I'm using IE7 in Windows Vista and so I'm not affected</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">luc</dc:creator><pubDate>Wed, 25 Apr 2007 13:25:12 -0000</pubDate></item></channel></rss>