YOUR IT - Technology for you

No. 1 Story

Cloud alliance sides with Optus on copyright

OzHub, the Macquarie Telecom-led cloud computing alliance, has come down firmly on the side of Optus over the copyright controversy surrounding Optus TV Now, warning that any moves to change the law "risk branding Australia a global luddite state."

read more

Third 'Apple Bug' seems familiar

Your IT - Home IT

The third instalment of the Month of Apple Bugs is less impressive than the first two, since it is apparently just a new way of exploiting a known vulnerability in QuickTime (as previously used by the MySpace XSS QuickTime worm).

The disclosure page does not indicate whether the Mac OS X version of QuickTime is affected as well as the one for Windows, and the proof of concept appears to rely on other Windows vulnerabilities. Furthermore, the exploit is described as a "cross-zone scripting attack," which is a Windows concept.

That shouldn't be taken as a claim that the QuickTime for Mac is 'safe' in this respect, but since the motivation for MoAB is said to be that "We like to play with OS X," we would have expected a Mac-based proof of concept.

Given that the QuickTime's ability to execute JavaScript contained within a movie's HREFTrack is an explicit feature (eg, to open a browser window with particular dimensions at a certain point in the movie), it isn't obvious how this issue could be best addressed within QuickTime.

Loading comments ...

- sponsored feature -

The Death of Traditional BI: What’s Next?

How to Make Business Discovery Work for Your Business IP PABX BUYING GUIDE

Business Discovery takes its cues from consumer apps. Like Google, it encourages us- ers to hunt for and explore data without worrying about or even noticing the underly- ing technology. Their entire experience is working within an intuitive interface to get real-time, self-service results with only minimal training. ...more