Files ≈ Packet Storm Packet Storm - Information Security News, Files, Tools, Exploits, Advisories and Whitepapers http://packetstormsecurity.org/ en-us Mon, 28 May 2012 08:10:51 GMT Packet Storm 144400 http://packetstormsecurity.org/ http://www.google-analytics.com/__utm.gif?utmwv=1.3&utmn=2227000990&utmcs=ISO-8859-1&utmsr=31337x31337&utmsc=32-bit&utmul=en-us&utmje=0&utmfl=-&utmcn=1&utmdt=Files%u2248%20Packet%20Storm&utmhn=packetstormsecurity.org&utmr=-&utmp=%2F1008-exploits%2Fapple_quicktime_marshaled_punk.rb.txt%2F&utmac=UA-18885198-1&utmcc=__utma%3D32867617.2227000990.1338192651.1338192651.1338192651.1%3B%2B__utmz%3D32867617.1338192651.1.1.utmccn%3D(direct)%7Cutmcsr%3D(direct)%7Cutmcmd%3D(none) Apple QuickTime 7.6.7 _Marshaled_pUnk Code Execution http://packetstormsecurity.org/files/93312/apple_quicktime_marshaled_punk.rb.txt http://packetstormsecurity.org/files/93312/apple_quicktime_marshaled_punk.rb.txt http://packetstormsecurity.org/files/93312/Apple-QuickTime-7.6.7-_Marshaled_pUnk-Code-Execution.html Mon, 30 Aug 2010 23:00:59 GMT This Metasploit module exploits a memory trust issue in Apple QuickTime 7.6.7. When processing a specially-crafted HTML page, the QuickTime ActiveX control will treat a supplied parameter as a trusted pointer. It will then use it as a COM-type pUnknown and lead to arbitrary code execution. This exploit utilizes a combination of heap spraying and the QuickTimeAuthoring.qtx module to bypass DEP and ASLR. This Metasploit module does not opt-in to ASLR. As such, this module should be reliable on all Windows versions. NOTE: The addresses may need to be adjusted for older versions of QuickTime.