Apple Adds Anti-Hacker Features to QuickTime

Apple Adds Anti-Hacker Features to QuickTime

Written By
Ryan Naraine
Ryan Naraine
Apr 7, 2008
2 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Apple is quietly adding several key anti-hacker security features into its flagship QuickTime media player as part of a deliberate plan to reduce the effectiveness of malicious exploits.
The XPMs (exploit prevention mechanisms) have been fitted into the WIndows and Mac OS X versions of QuickTime 7.4.5, a new update that also patches 11 high-risk security vulnerabilities.

Click Here to Watch the Latest eWEEK Newsbreak Video.

According to a source familiar with Apple’s moves, QuickTime for Windows Vista now features ASLR (address space layout randomization), a security technology that randomly arranges the positions of key data areas to prevent malware authors from predicting target addresses.
ASLR, which has been used by Apple to add code scrambling diversity to Mac OS X Leopard, is used in tandem with additional security features to reduce the effectiveness of exploit attempts.
Several open-source security systems – OpenBSD, PaX and Exec Shield – already implement ASLR in some form. Microsoft has also fitted ASLR into default configurations of Windows Vista.
In addition to ASLR, QuickTime for Windows will also do stack buffer safety checking (Visual Studio 2005’s /GS option) and support for hardware NX on Windows Vista.
The security hardening has also extended to QuickTime for Mac OS X, which gets:

1. Stack buffer safety checking (-fstack-protector to gcc)

2. Function call hardening, which should prevent some buffer overflows

Security researchers reacted to Apple’s move with applause. “That’s a pretty big change for a point release,” said Dino Dai Zovi, a hacker who has written multiple exploits for QuickTime. “They [Apple] have way more guts than many other software companies to do something like that. Either that, or they are afraid of the backlash if malware starts targeting QuickTime and iTunes in a more serious way.”
Dai Zovi, who used a QuickTime exploit to hack into a MacBook Pro machine at the 2007 CanSecWest security conference, said the decision to enable the use of ASLR and NX on Vista will hamper exploits.

“QuickTime looks like it may have just gotten more difficult. That is definitely a good thing,” Zovi said.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.