On CHOW: Groundbreaking hangover cure
BNET Business Network:
BNET
TechRepublic
ZDNet

March 11th, 2009

Rigged podcasts can leak your iTunes username/password

Posted by Ryan Naraine @ 10:13 pm

Categories: Apple, Arbitrary Code Execution, Browsers, Data theft, Denial of Service (DoS), Exploit code, Passwords, Patch Watch, Phishing, Spam and Phishing, Viruses and Worms, Vulnerability research

Tags: Apple Inc., Apple iTunes, Authentication, Podcasts, Digital Music, Digital Media, Internet, Personal Technology, Consumer Electronics, Ryan Naraine

Hackers can create malicious podcasts to hijack usernames and passwords from Apple’s iTunes software.

According to a warning from Apple, a “design issue” in the iTunes podcast feature can be abused via rigged audio files to cause an authentication dialog to be presented to the user.  From that dialog, a hacker can hijack iTunes credentials and upload it to the podcast server.


[ SEE: Apple plugs gaping iTunes hole, doesn't tell everyone ]

From Apple’s advisory:

  • A design issue exists in the iTunes podcast feature. A subscription to a malicious podcast may cause an authentication dialog to be presented to the user. This dialog may entice the user to send iTunes credentials to the podcast server.

Apple has shipped a patch in iTunes 8.1 to clarify the origin of the authentication request in the dialog box.

The iTunes update also corrects a denial-of-service flaw that can be caused via maliciously crafted DAAP messages.

  • An infinite loop exists in the handling of iTunes Digital Audio Access Protocol (DAAP) messages. Sending a message containing a maliciously crafted Content-Length parameter in the DAAP header may lead to a denial of service. This update addresses the issue by performing additional validation of DAAP messages.

The denial -of-service bug does not affect Mac OS X systems.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 26 Talkback(s)
YAY FACETIOUS!
(Read the rest)
Posted by: nix_hed Posted on: 03/17/09 You are currently: a Guest | | Terms of Use
Then I guess...  vikingnyc@... | 03/12/09
what about iTunes on the iPhone?  davidf01 | 03/12/09
actually, it's fixed  Narr vi | 03/12/09
QFT  bishofthedump | 03/16/09
For telling us what was fixed? Apple sure didn't. Who's dishonest here?NT  invmgr@... | 03/16/09
Pardon me, yes Apple did. NT  invmgr@... | 03/16/09
RE: Rigged podcasts can leak your iTunes username/password  Daedalu | 03/13/09
RE: Rigged podcasts can leak your iTunes username/password  bblaho | 03/13/09
Hmm...  tikigawd | 03/16/09
amazing?  pillbox1234567 | 03/16/09
I think he was being sarcastic (NT)  Yax_to_the_Max | 03/16/09
But Pillbox wasn't... NT  invmgr@... | 03/16/09
YAY FACETIOUS!  nix_hed | 03/17/09
Im still running an older version. thanks for the update.  pcguy777 | 03/16/09
Impossible! Apple products are bulletproof and utterly secure!  HypnoToad | 03/14/09
extreme sarcasm more like  pillbox1234567 | 03/16/09
So was the Titanic.  phatkat | 03/16/09
Terminology  Mewshew | 03/15/09
RE: terminology  onedavester@... | 03/16/09
Pure FUD  comp_indiana | 03/16/09
RE:Pure FUD  richdave | 03/16/09
re to fuds  malcomhfc1875@... | 03/16/09
Er...having a Mac wouldn't fix it  scorchgeek | 03/16/09
DAAP DOS was only in the Windows version...  nix_hed | 03/17/09
RE: Rigged podcasts can leak your iTunes username/password  yakko007@... | 03/16/09
RE: Rigged podcasts can leak your iTunes username/password  robertleeking@... | 03/17/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

  • Smart Tech Expert advice on innovations in healthcare and the green technologies that make it happen. Find out more
  • Smart Business Discussion and advice on management issues that revolve around making your world smarter and more useful. More Smart Advice
  • Smart People The best and worst moves in the management and strategy trenches. Learn More