No. 1 Story

HP job cuts loom for Australian employees

A number of Australian employees of Hewlett-Packard are facing the loss of their jobs as the global computer giant looks to slash its worldwide workforce by up to 30,000.

read more

Related Articles

Adoption of cloud computing has reached a tipping point  - but don’t expect legacy...
In yet another blow to the Facebook IPO this week, following the withdrawal of...
Recruitment technology and social media have played a significant role in growing business in...
Fancy a 4G Windows Phone? Your wait may be over next Tuesday when Telstra...
Microsoft and its partners such as Nokia and HTC are trumpeting the virtues of...

Symantec: Second PoC for QuickTime vulnerability

Your IT - Home IT

A second proof-of-concept exploit for the QuickTime RTSP vulnerability has been identified by Symantec's security response team.

The unfortunately named Quimkids Trojan relies on a specially modified RTSP server. It works by using JavaScript to send shell code to the target system while the RTSP server sends a stream that overwrites the QuickTime stack and triggers the stored shell code.

Since the attack relies on Internet Explorer, it is specific to Windows XP and Vista.

This approach makes it easier to deliver whatever shell code the attacker chooses, but it will not work on an unmodified RTSP server. Symantec has assigned Quimkids its lowest risk level as it has been found on a very small number of sites and is easily contained and removed.

Symantec currently recommends sites block RTSP completely unless is it specifically required, disable the QuickTime ActiveX controls in Internet Explorer and the plug-in for Firefox, disable JavaScript (this is a tall order given that even Symantec's web site uses JavaScript), and (as always) users should avoid untrusted QuickTime files.