Users advised to upgrade immediately
Users advised to upgrade immediately
R E L A T E D   C O N T E N T
ADVERTISEMENT

ITunes exploit code hits the web

Proof-of-concept code contains no virus or Trojan payload

Iain Thomson, vnunet.com 17 Jan 2005
ADVERTISEMENT

Code that allows hackers to exploit a vulnerability in Apple's iTunes software has appeared over the weekend.

The code was posted on the Bugtraq mailing list by someone known only as 'Nemo', and acknowledges the help of three friends 'andrewg', 'mercy' and 'core'. The code is designed purely as a proof of concept and contains no virus or Trojan payload.

"Here is some code to exploit the vulnerability. It will generate a *.pls file which, when opened with iTunes 4.7, will bind a shell on port 4444," said 'Nemo' in the message.

Early versions of iTunes are vulnerable to hackers who can build malicious playlist files which crash the application. Code can then be inserted, either to spread a virus or allow the attacker to take control of the host PC.

The latest version, iTunes 4.7.1, is not affected by the vulnerability and can be downloaded from Apple's website here.

See also:

Apple modifies iTunes software to fix security holeUsers no longer able to bypass copy protection  22 Mar 2005
Exploit code should be used to test computer securityTime to learn the tricks of the trade, says security expert  21 Feb 2005
Firms updating products against image risk  26 Jan 2005
Playlist flaw lets hackers inSubscribers urged to upgrade software immediately  14 Jan 2005

All Bugs & Fixes

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
C# Web Developer, Finance, London Financial Services Required: C#, ASP.NET, AJAX Fantastic opportunity not to be missed!! This is a great opportunity to work on a unique objectives that no other company is doing working ... more >
| JAM Recruitment
Senior Hardware Engineer Scotland/Edinburgh Communication Systems Permanent Position 40-45K+Benefits A leading organisation involved with the design and development of data acquisition systems and synthesis boards for a range of radar, signal intelligence and software radio ... more >
| JAM Recruitment
FPGA Engineer Defence/Safety Critical Buckinghamshire Permanent Position 45K+Benefits A leading UK defence organisation requires an experienced digital design engineer to strengthen its existing development team due to a number of long-term projects that have recently ... more >
| JAM Recruitment
DSP Engineer 3 Months Contract Hertfordshire £Excellent Rates£ This position requires you to have experience of measurement algorithms development for the generation and analysis of digital wireless communication standards including GSM, EDGE, UMTS, WLAN and ... more >
More job opportunities