• On CHOW: Can girls use the guys' bathroom?
advertisement
December 4, 2006 12:05 PM PST

QuickTime HREF tracks functionality can potentiate phishing (MySpace vulnerability): Avoiding

by CNET staff

News outlets are buzzing about a newly exploited -- but long extant -- phishing vulnerability that in part rests on the ability of QuickTime movies to automatically and involuntarily open URLs.

The exploit is carried out through the "HREF tracks" functionality in QuickTime. Essentially, HREF tracks allows the movie author to specify JavaScript functions or Web pages that load a specific browser frame or window when a QuickTime movie is played. This tactic is used by some movie trailers, for instance, to automatically lead users back to the associated promotional Web site.

The current manifestation of this flaw involves MySpace user profiles. When user A is logged into MySpace and plays a malicious QuickTime movie stored in user B's profile, JavaScript code is executed that makes changes to User A's profile -- embedding links that lead to phishing sites and placing a copy of the malicious QuickTime file on user A's profile page. The placed links can lead to spoofed (fake) MySpace login pages that cull username/password data.

In theory, this flaw is platform-agnostic, but we haven't been able to find a test version of the exploit to evaluate on Mac OS X systems running Safari/Firefox.

We're watching for more details on this issue as they emerge, but for the time being, users should be wary of playing embedded QuickTime media on MySpace profiles, and avoid clicking on links in non-default profile navigation bars.

Also, open System Preferences and click on the "QuickTime" pane. Click on the "Browser" tab an un-check the option to "Play movies automatically."

Feedback? Late-breakers@macfixit.com.

Resources

  • MySpace user profiles
  • Late-breakers@macfixit.com
  • More from Late-Breakers
  • Recent posts from MacFixIt
    The OS X 10.7 buzz starts--something big in the next release?
    MacFixIt Answers
    Safari still crashing after update?
    Safari 5.0.1 update fixes black Mail backgrounds, autofill, and more
    Making the switch to Apple? Get the perfect setup
    Apple releases OS X 10.6.4 update for iMacs; trackpad driver
    CNET Apple Byte: iPhone to T-Mobile?
    iTunes not connecting to the iTunes store after updating
    Add a Comment (Log in or register)
    by proachaz_1 December 4, 2006 2:21 PM PST
    I have also had this issue on a downloaded movie, where when you open the movie it launches a website.

    I have "play movie automatically" unchecked, but there needs to be a "Don't launch URL's or Execute Java" button.

    I throw away movies that do this, I have found no way to stop them from auto launching and figured it could definally be used as a great phishing feature. The idea that the movie would phone home when ever it is run.
    Reply to this comment
    advertisement

    About MacFixIt

    MacFixIt is CNET's troubleshooting resource for all things Mac. The information here helps you navigate the ins-and-outs of Mac ownership with how-tos, troubleshooting information, news, reviews, and more.

    Add this feed to your online news reader