<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>Kakkoi &#187; Apple</title>
	<atom:link href="http://42.kaizeku.com/taxonomy/apple//feed/" rel="self" type="application/rss+xml" />
	<link>http://42.kaizeku.com</link>
	<description>web development, software, windows tips and trick</description>
	<pubDate>Sat, 12 Jul 2008 15:10:01 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
	<language>en</language>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Block Apple Quicktime ActiveX &#038; RTSP Exploit</title>
		<link>http://42.kaizeku.com/apple/block-apple-quicktime-activex-rtsp-exploit/</link>
		<comments>http://42.kaizeku.com/apple/block-apple-quicktime-activex-rtsp-exploit/#comments</comments>
		<pubDate>Thu, 06 Dec 2007 17:45:50 +0000</pubDate>
		<dc:creator>Nick B</dc:creator>
		
		<category><![CDATA[Apple]]></category>

		<category><![CDATA[QuickTime]]></category>

		<category><![CDATA[mac]]></category>

		<category><![CDATA[buffer+overflow]]></category>

		<category><![CDATA[Exploit]]></category>

		<category><![CDATA[ie6]]></category>

		<category><![CDATA[ie7]]></category>

		<category><![CDATA[internet+explorer]]></category>

		<category><![CDATA[jikto]]></category>

		<category><![CDATA[microsoft]]></category>

		<category><![CDATA[Mozilla Firefox]]></category>

		<category><![CDATA[remote+exploit]]></category>

		<category><![CDATA[RSTP]]></category>

		<category><![CDATA[safari]]></category>

		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/apple/block-apple-quicktime-activex-rtsp-exploit/</guid>
		<description><![CDATA[<p><img width="128" height="128" style="float: left;" alt="Fixes Apple QuickTime" src="http://i.kakkoi.net/leopard/QuickTimePlayer.png" longdesc="http://blog.kakkoi.net/apple/block-apple-quicktime-activex-rtsp-exploit/" title="Quicktime Logo" /><strong style="font-weight:400">Apple QuickTime</strong> contains a stack <a href="http://en.wikipedia.org/wiki/Buffer_overflow" rev="wikipedia:Buffer_overflow" title="buffer overflow" rel="external nofollow">buffer overflow</a> vulnerability in the way it handles the <abbr title="Real Time Streaming Protocol ">RTSP</abbr> Content-Type header. This vulnerability may be exploited by specially crafted RTSP stream protocol</p><strong>Live Example</strong>
<ul class="xoxo nfo">
<li><a href="http://www.gnucitizen.org/blog/backdooring-quicktime-movies/">GNUcitizen- Backdooring QuickTime Movies </a></li>
<li><a href="http://quicktime.tc.columbia.edu/users/iml/movies/mtest.html">Apple QuickTime redirection to the RTSP exploit</a></li>

</ul>
Elia Florio (Symantec) wrap  a good introduction post regarding <a href="http://www.symantec.com/enterprise/security_response/weblog/2007/11/0day_exploit_for_apple_quickti.html">QuickTime 0 day Exploit</a>. 


<h2 style="border-top:1px solid #ccc; margin-top:38px;padding-top:14px">Known Vulnerabilities Proof of concept (milw0rm).</h2>
<ul class="xoxo nfo">
<li><a rel="nofollow" href="http://blog.kakkoi.net/uri/bWlsdzBybS5jb20vZXhwbG9pdHMvNDY3Mw.curie,80,302">Apple QuickTime 7.3 RTSP Response Content-Type Header Stack Buffer Overflow exploit </a> </li>
<li><a rel="nofollow" href="http://blog.kakkoi.net/uri/bWlsdzBybS5jb20vZXhwbG9pdHMvNDY2NA.curie,80,302">Apple QuickTime Remote stack rewrite exploit for Internet Explorer 6 &#38; 7</a></li>
<li><a rel="nofollow" href="http://blog.kakkoi.net/uri/bWlsdzBybS5jb20vZXhwbG9pdHMvNDY1Nw.curie,80,302">Apple QuickTime 7.2/7.3 RTSP Response Universal Exploit (IE7/FF/Opera)</a></li>
<li><a rel="nofollow" href="http://blog.kakkoi.net/uri/bWlsdzBybS5jb20vZXhwbG9pdHMvNDY1MQ.curie,80,302">Apple Quicktime (Vista/XP Sp2 RTSP RESPONSE) Code Exec Exploit</a></li>
</ul>

<h2 style="margin-top:18px;padding-top:14px">Workarounds</h2>
You may try the following workarounds [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src="http://i.kakkoi.net/leopard/QuickTimePlayer.png" style="float: left" alt="Fixes Apple QuickTime" longdesc="http://blog.kakkoi.net/apple/block-apple-quicktime-activex-rtsp-exploit/" title="Quicktime Logo" height="128" width="128" /><strong style="font-weight: 400">Apple QuickTime</strong> contains a stack <a href="http://en.wikipedia.org/wiki/Buffer_overflow" rev="wikipedia:Buffer_overflow" title="buffer overflow" rel="external nofollow">buffer overflow</a> vulnerability in the way it handles the <abbr title="Real Time Streaming Protocol ">RTSP</abbr> Content-Type header. This vulnerability may be exploited by specially crafted RTSP stream protocol</p>
<p><strong>Live Example</strong></p>
<ul class="xoxo nfo">
<li><a href="http://www.gnucitizen.org/blog/backdooring-quicktime-movies/">GNUcitizen- Backdooring QuickTime Movies </a></li>
<li><a href="http://quicktime.tc.columbia.edu/users/iml/movies/mtest.html">Apple QuickTime redirection to the RTSP exploit</a></li>
</ul>
<p>Elia Florio (Symantec) wrap a good introduction post regarding <a href="http://www.symantec.com/enterprise/security_response/weblog/2007/11/0day_exploit_for_apple_quickti.html">QuickTime 0 day Exploit</a>.<br />
<span id="more-62"></span></p>
<h2 style="border-top: 1px solid #cccccc; margin-top: 38px; padding-top: 14px">Known Vulnerabilities Proof of concept (milw0rm).</h2>
<ul class="xoxo nfo">
<li><a href="http://blog.kakkoi.net/uri/bWlsdzBybS5jb20vZXhwbG9pdHMvNDY3Mw.curie,80,302" rel="nofollow">Apple QuickTime 7.3 RTSP Response Content-Type Header Stack Buffer Overflow exploit </a></li>
<li><a href="http://blog.kakkoi.net/uri/bWlsdzBybS5jb20vZXhwbG9pdHMvNDY2NA.curie,80,302" rel="nofollow">Apple QuickTime Remote stack rewrite exploit for Internet Explorer 6 &amp; 7</a></li>
<li><a href="http://blog.kakkoi.net/uri/bWlsdzBybS5jb20vZXhwbG9pdHMvNDY1Nw.curie,80,302" rel="nofollow">Apple QuickTime 7.2/7.3 RTSP Response Universal Exploit (IE7/FF/Opera)</a></li>
<li><a href="http://blog.kakkoi.net/uri/bWlsdzBybS5jb20vZXhwbG9pdHMvNDY1MQ.curie,80,302" rel="nofollow">Apple Quicktime (Vista/XP Sp2 RTSP RESPONSE) Code Exec Exploit</a></li>
</ul>
<h2 style="margin-top: 18px; padding-top: 14px">Workarounds</h2>
<p>You may try the following workarounds, as there is no complete patch for this this vulnerability.</p>
<ul id="downloads" class="xoxo nfo">
<li> Block TCP <strong>port 554 </strong> (optionaly 7070) and UDP 6970 through 6999 in your firewall</li>
<li>Update <a href="http://www.apple.com/quicktime/download/">Quicktime</a></li>
<li> <a href="http://blog.kakkoi.net/wp-content/uploads/2007/12/disabledquicktimeactivex-kb240797.reg" title="DisabledQuicktimeActiveX-KB240797">Disabled Apple Quicktime ActiveX control running in Internet Explorer</a> (Windows registry file)</li>
<li>For Firefox - <a href="http://noscript.net/">Noscripts</a> addons</li>
</ul>
<h2 style="border-top: 1px solid #cccccc; margin-top: 38px; padding-top: 14px">Related Links</h2>
<ul class="xoxo">
<li><a href="http://info.internet.isi.edu/in-notes/rfc/files/rfc2326.txt">RTSP - rfc2326 </a> &amp; <a href="http://info.internet.isi.edu/in-notes/rfc/files/rfc1889.txt">RTP - rfc1889 </a></li>
<li><a href="http://docs.info.apple.com/article.html?artnum=307038">Apple Security Update on Safari 3 Beta Update 3.0.4</a></li>
<li><a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2002-0252">NVD Database - Buffer overflow in Apple QuickTime</a></li>
<li><a href="http://support.microsoft.com/kb/240797">Microsoft KB240797 - How to stop an ActiveX control from running in Internet Explorer</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/apple/block-apple-quicktime-activex-rtsp-exploit/feed/</wfw:commentRss>
		</item>
		<item>
		<title>How to remove Adobe Version Cue CS3</title>
		<link>http://42.kaizeku.com/adobe/adobe-photoshop-cs3-removed-bonjour/</link>
		<comments>http://42.kaizeku.com/adobe/adobe-photoshop-cs3-removed-bonjour/#comments</comments>
		<pubDate>Thu, 15 Nov 2007 15:22:35 +0000</pubDate>
		<dc:creator>Avice De'veréux</dc:creator>
		
		<category><![CDATA[Adobe]]></category>

		<category><![CDATA[Apple]]></category>

		<category><![CDATA[Bonjour]]></category>

		<category><![CDATA[cs3]]></category>

		<category><![CDATA[rivo+uninstaller]]></category>

		<category><![CDATA[version+cue]]></category>

		<category><![CDATA[winsock]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/adobe/adobe-photoshop-cs3-removed-bonjour/</guid>
		<description><![CDATA[Removed the whole Bonjour crap (both mDNSResponder.exe and mdnsNSP.dll) using the following steps]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/03/adobe-version-cue-cs3-bonjour.png' alt='adobe-version-cue-cs3-bonjour.png' width='128' height='128' class="photo thumb- fl" /><br />
<h2>What is Adobe Version Cue (Bonjour)</h2>
<blockquote class="mgt"><p class="cite">Bonjour is a file management tool that is integrated in Adobe Photoshop, Adobe InDesign, Adobe Acrobat, Adobe Illustrator and other creative applications within the Creative Suite. It is client/server based. The clients are integrated into each of the applications and they all communicate with the Version Cue Server.</p>
</blockquote>
<p><span id="more-6"></span><br />
To make setup and configuration easier, Adobe uses Apple&#8217;s Bonjour technology to enable the connectivity to Version Cue servers on a local area network. Bonjour is widely used throughout Mac OS X and Windows in applications like iTunes and popular printers to allow users to set up a network service without any configuration.</p>
<p>As adobe install this programs <em class="hilite-3">without your permission</em>, running in the background silently and there is no options to disabled it!. You should consider adobe version cue as a <span class="hilite-4">pestware</span> and should be remove immediately.</p>
<p>There is four methods to removed bonjour services aka Adobe Version Cue CS3 Component.</p>
<h2 class="cb mgb-"><big class="fl">1<span>)</span></big> &nbsp;Manual removal</h2>
<ul class="exturl pdt">
<li>Stop <strong>Bonjour service</strong> <tt class="di">RUN &gt; sc stop &#8220;bonjour service&#8221;</tt></li>
<li>Remove Bonjour services from windows startup <tt class="di">RUN&gt; sc delete &#8220;bonjour service&#8221;</tt></li>
<li>Disable the Bonjour socket driver:<br />
<tt class="di">RUN &gt; Regedit:</tt></p>
<pre class="smallbox">HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\
Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004</pre>
<p>find key:<br />
<tt class="di">Enabled=REG_DWORD:00000001</tt> change it from 1 to 0.</li>
<li>Reboot, the driver will not be loaded any more.</li>
<li>Delete the Bonjour directory (with the files <strong>mDNSResponder.exe</strong> and <strong>mdnsNSP.dll</strong>).</li>
</ul>
<h2 class="mgt"><big class="fl">2<span>)</span></big> &nbsp;Apple Bonjour Official Uninstaller</h2>
<p>Download <a href="/uri/d3d3LmFwcGxlLmNvbS9zdXBwb3J0L2Rvd25sb2Fkcy9ib25qb3VyZm9yd2luZG93cy5odG1s.curie,80,302" title="Apple Bonjour for Windows 2.1MB" class="exturl icn-r1">Apple Bonjour for Windows</a> and run the bonjour uninstaller.</p>
<h2><big class="fl">3<span>)</span></big> &nbsp;Optional Methods</h2>
<p>Third methods will disabled bonjour services from running in the background. You&#8217;ll need to removed bonjour manually.<br />
<code>RUN &gt; C:\Program Files\Bonjour\mDNSResponder.exe -remove</code></p>
<h2 class="cb mgt mgb-"><big class="fl">4<span>)</span></big> &nbsp;Third party Uninstaller</h2>
<ul class="xoxo exturl pdt">
<li>
<a href="/uri/d3d3LnNoYXJlYXBpYy5uZXQvY29udGVudC5waHA_aWQ9NDY2NjAzNg.curie,80,302"><img src="http://gmodules.com/ig/proxy?url=http://www.shareapic.net/preview2/004666036.jpg" width="130" height="103" class="fr" alt="uninstalled bonjour with rivo uninstaller" /></a>This is the prefer methods, as it wont affect others shared programs that depend on bonjour (ie: itunes, quicktime). Read on <a href="/uri/bGlmZWhhY2tlci5jb20vc29mdHdhcmUvZmVhdHVyZWQtd2luZG93cy1kb3dubG9hZC9jb21wbGV0ZWx5LXJlbW92ZS1wcm9ncmFtcy13aXRoLXJldm8tdW5pbnN0YWxsZXItMjgyMzM3LnBocA.curie,80,302" class="exturl icn-r">lifehacker</a> for more info about Revo Uninstaller. Its free.
</li>
<li>Download and Installed <a href="http://www.revouninstaller.com/revo_uninstaller_free_download.html" class="exturl icn-r1">Revo uninstaller</a>.</li>
<li>Start Revo uninstaller and wait till it finished populating the lists with all your applications and its components.</li>
<li>Find and select <strong>Adobe Version Cue CS3</strong>. Click the Uninstall Icon to proceed. Select the &#8220;Moderate&#8221; options.</li>
<li>After the first &amp; second step is done (dont click finish yet), proceed with removing all bonjour registry.</li>
</ul>
<p class="notice">You can used Revo Uninstaller to removed others &#8220;hidden&#8221; installed components package with Adobe CS3.</p>
<h3 class="cb">Related info</h3>
<h5>Software registry keys</h5>
<dl>
<dt id="Adobe-Version-Cue">Adobe Version Cue CS3 Client</dt>
<dd>MsiExec.exe /I{D0DFF92A-492E-4C40-B862-A74A173C25C5}</dd>
</dl>
<h3 class="cb mgb-">External Links</h3>
<ul class="xoxo exturl">
<li><a href="/uri/Y2V4eC5vcmcvbHNwZml4Lmh0bQ.curie,80,302" title="Repairs Winsock 2 settings, caused by buggy or improperly-removed Internet software " rel="nofollow external">Repairs Winsock 2 settings, caused by buggy or improperly-removed Internet software</a></li>
<li><a href="http://wxpnews.com/archives/wxpnews-322-20080408.htm" rev="vote-for" title="Who Owns That File Format?">WXPNews: Who Owns That File Format?</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/adobe/adobe-photoshop-cs3-removed-bonjour/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
