View Single Post
Old 04-09-2004, 04:06 AM   #2 (permalink)
Silvy
paranoid
 
Silvy's Avatar
 
Location: The Netherlands
I have some difficulty understanding this:

Quote:
Originally posted by Nomad

The Trojan horse's code is encapsulated in the ID3 tag of an MP3 (digital music) file. This code is in reality a hidden application that can run on any Macintosh computer running Mac OS X. Mac OS X displays the icon of the MP3 file, with an .mp3 extension, rather than showing the file as an application, leading users to believe that they can double-click the file to listen to it. But double clicking the file launches the hidden code, which can damage or delete files on computers running Mac OS X, then [launches] iTunes to play the music contained in the file, to make users think that it is really an MP3 file.
So the trojan is in the ID3 tag. That means it must be in the MP3 file.
Then it's logically displayed as an MP3 file, which in the above text is thought as deceiving.
Double clicking on it launches the code.... So you mean it's an application? So it's not actually an MP3 file? Then MacOS just assumes it is?
Then the trojan launches iTunes? So it is an MP3 file?
Ok, you got me: what is it?

My conclusion: The exploit is in the way MP3 files are handled (in iTunes?). It is an MP3 file, but some info in there exploits the security hole (in iTunes?). And think I'm correct in assuming that iTunes is launched, the MP3 is played, and then the malicious code is executed.

It's all the same difference, the file is Bad, and the security leak should be patched. But I hardly see it as an Mac OS X problem, as it most certainly lies within the iTunes application.

Note: I've never used Mac OS X
__________________
"Do not kill. Do not rape. Do not steal. These are principles which every man of every faith can embrace. "
- Murphy MacManus (Boondock Saints)
Silvy is offline  
 

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73