A new version of Apple's Update utility lets you choose which components to install and which to ignore.
Apple Stops QuickTime Nagging About Safari
Apple made my pet-peeves list recently with its decision to push Safari out to Windows customers via its QuickTime Update software, and I certainly wasn't the only one. The good news is that Apple seems to have finally relented.
A new version of QuickTime Update, available beginning today, uses a two-pane interface to separate legitimate updates to your currently-installed components from any new applications that Apple would like you to install. Shockingly, that even includes iTunes, for those of us who use our PCs mainly for business. And, though the option isn't easy to find, the new version even lets you opt out of Safari and iTunes downloads completely.
To get it, first run your existing QuickTime Update software. You can find it by opening the QuickTime control panel from your Start menu, selecting the Update tab, then pressing the button marked "Update..." You should see an application called "QuickTime Update 2.1" -- leave the box next to that checked, but uncheck all the others.
Inexplicably, installing the new QuickTime Update requires you to restart your computer. Once you're back up and running, launch QuickTime Update again (the same way you just did) to see the new interface.
By default, all the current updates are checked (including Safari and iTunes), but you might notice that you can now download the latest version of the standalone QuickTime software, without iTunes. Hooray for that.
Here's the kicker, though. With the new division of software, it's relatively painless to opt out of Apple's iTunes and Safari nagging for good. Make sure that you've installed the QuickTime updates that you need, then launch QuickTime Update again. You should now see only the updates that you don't want. Now go to the Tools menu and choose "Ignore Selected Updates." (You can always reset your ignored updates later if you change your mind.)
Voila! You should now have a functioning Apple Software Update that does what it was intended to do -- update your software, not push multi-megabyte applications that you don't really want.
Friday, April 18, 2008
Apple Stops Pushing Safari to PCs
Sunday, January 13, 2008
QuickTime Flaw Found
Another flaw in Apple's QuickTime player found, putting users at risk
New QuickTime Flaw Found
The United States Computer Emergency Readiness Team (US-CERT) has found a new buffer overflow vulnerability with Apple's QuickTime media software.
The flaw affects both Windows and Mac operating systems. And since QuickTime is a part of iTunes, Apple's popular jukebox software, iTunes is also affected, said the researchers.
The vulnerability is found in the way QuickTime handles RTSP response messages. When attempting to display a specially crafted Reason-Phrase, QuickTime Player crashes at a memory location that can be controlled by an attacker, according to US-CERT.
The organization also said that they are aware of publicly available proof-of-concept code for this vulnerability.
US-CERT offers several solutions to the problem including uninstalling QuickTime, Blocking the RTSP protocol and disabling the QuickTime plug-ins in your Web browser.
Attackers targeted QuickTime in December in a separate RTSP vulnerability that Apple later fixed with a software update.
Posted by
Ran Werkheiser
at
06:29
0
comments
Friday, December 14, 2007
QuickTime Bug Squashed
Apple releases a patch to update a critical flaw, making it the eight update this year for QuickTime.
Apple Fixes QuickTime Bug
A new security patch for QuickTime has been released by Apple, making it the eight update for this year for the media player software. The update addresses three critical security flaws in Quicktime that also includes a vulnerability that has been used by online criminals.
The most critical of the flaws patched is the implementation of QuickTime of the Real Time Streaming Protocol, or RTSP, which is used to play video and audio over the internet. Attackers began exploiting the flaw early December after it was made public last November. The online attack includes tricking victims into visiting a malicious website that exploited the flaw, and hackers were able to install malicious software on the victims' PCs.
These attacks have targeted Windows-based systems, but experts says that Mac OS X users are also at risk. Apple issued patches for both Windows and Mac OS X users last Thursday.
Security researchers are looking at the way QuickTime works with QuickTime Media Link (QTL) fire format used by the media player. The second critical vulnerability, which had apparently not been publicly disclosed, has to do with this file format.
Apple also patched a handful of similar bugs in the way that QuickTime handles Adobe's Flash media format. The most serious of these flaws could let attackers run unauthorized software on the computer, much as the RTSP bug does, Apple said.
With security researchers paying special attention to media format bugs, Apple has had to patch QuickTime frequently this year. Some of these updates have come just weeks apart. Apple last patched QuickTime on Nov. 5.
Wednesday, December 5, 2007
PC + Mac QuickTime Flaw
Symantec warns that both Windows and Mac systems may be vulnerable to exploits of an unpatched Quicktime flaws
Windows and Mac Shares QuickTime Flaw
Last Sunday, Symantec warned in a DeepSight Threat Management System alert that attackers are trying to exploit an unpatched vulnerability in Apple's QuickTime software that could let them run code on a victim's computer.
Attackers appear to be aimed at Windows users, but Mac OS users could be open to the risk as well, as QuickTime vulnerability in question affects both operating systems. The vulnerability, called the Apple QuickTime RTSP Response Header Stack-Based Buffer Overflow Vulnerability, was first revealed on November 23, and still remains unpatched by Apple.
Windows XP and Windows Vista running Internet Explorer, Firefox, Opera, and Safari are affected by this vulnerability, as well as Apple's own MacOS X 10.4 and 10.5.
Symantec said that there are two types of attacks underway. One involves redireting the victim's computer from an adult web site, Ourvoyeur.net, to another web site that infects the computer with an application called loader.exe. It can be saved to the victim's computer as metasploit.exe, asasa.exe, or syst.exe. Once installed on a computer, this application downloads another binary file, which Symantec identified as Hacktool.Rootkit, a set of tools that can be used to break into a system. It's possible that Ourvoyer.net was compromised as part of the attack.
The second method of attack also involves redirection, however, Symantec is currently investigating the attack to determine what, if any, malicious code is involved.
To protect systems from attack, Symantec recommended blocking access to affected sites. "Filter outgoing access to 85.255.117.212, 85.255.117.213, 216.255.183.59, 69.50.190.135, 58.65.238.116, and 208.113.154.34. Additionally 2005-search.com, 1800-search.com, search-biz.org, and ourvoyeur.net should be filtered," it said, adding IT managers can also block outgoing TCP access to port 554.
Alternatively, IT managers could take more drastic steps. "As a last measure, QuickTime should be uninstalled until patches are available," the alert said.
Posted by
Ran Werkheiser
at
18:47
0
comments
Labels: apple, bug, flaw, mac, patch, quicktime, symantec, windows xp