Flash flaw puts most sites, users at risk, say researchers
'Frighteningly bad thing,' said Foreground Security, of flaw allowing hackers to hijack sites, attack users
By Gregg Keizer
November 12, 2009 04:17 PM ET
Computerworld - Hackers can exploit a flaw in Adobe's Flash to compromise nearly every Web site that allows users to upload content, including Google's Gmail, then launch silent attacks on visitors to those sites, security researchers said today.
Adobe did not dispute the researchers' claims, but said that Web designers and administrators have a responsibility to craft their applications and sites to prevent such attacks.
"The magnitude of this is huge," said Mike Murray, the chief information security officer at Orlando, Fla.-based Foreground Security. "Any site that allows user-uploadable content is vulnerable, and most are not configured to prevent this."
The problem lies in the Flash ActionScript same-origin policy, which is designed to limit a Flash object's access to other content only from the domain it originated from, added Mike Bailey, a senior security researcher at Foreground. Unfortunately, said Bailey, if an attacker can deposit a malicious Flash object on a Web site -- through its user-generated content capabilities, which typically allow people to upload files to the site or service -- they can execute malicious scripts in the context of that domain.
"This is a frighteningly bad thing," Bailey said. "How many Web sites allow users to upload files of some sort? How many of those sites serve files back to users from the same domain as the rest of the application? Nearly every one of them is vulnerable."
More at: Flash flaw puts most sites, users at risk, say researchers
My Computers
-
At a glance
W7 Ultimate x64/W10 Pro x64/W11 Pro Triple Bo...AMD Phenom II X4 975 Deneb 3.6ghz - 965 2nd r...Kingston Hyper X DDR3 1600 1.5v 16gb - Hyper ...MSI HD Radeon 5750 1gb - MSI HD Radeon 6450 o...- Computer type
- PC/Desktop
- Computer Manufacturer/Model Number
- Custom builds = 2
- OS
- W7 Ultimate x64/W10 Pro x64/W11 Pro Triple Boot - Main PC W7 Remote PC Micro ATX W7 Pro x64/W11 Pro
- CPU
- AMD Phenom II X4 975 Deneb 3.6ghz - 965 2nd remote pc
- Motherboard
- Gigabyte GA-790XTA-UD4-Gigabyte GA-880GM-D2H remote pc
- Memory
- Kingston Hyper X DDR3 1600 1.5v 16gb - Hyper X Fury 8gb 2nd
- Graphics Card(s)
- MSI HD Radeon 5750 1gb - MSI HD Radeon 6450 on mini tower
- Sound Card
- Creative Labs X-Fi Xtreme Audio P - Realtek onooard 2nd case
- Monitor(s) Displays
- ASUS VW199T-P 19" HP 2082a Main-HP 2082a 20" remote pc
- Screen Resolution
- Asus 1440x900 - HP 1600x900
- Hard Drives
- WD Black 1TB HD per OS W7, W10, and pending W11 presently on 500gb OS Drive - Pending Triple 1TB HDs for Spanned Storage/backup volume
Single 2TB external USB enclosure, single 1TB System 7 Host/Boot drive, Pending 8TB external HD for system image b
- PSU
- Corsair 750TX - primary / Corsair CX600 - second
- Case
- Antec 900-2 - SSD compatible / NZXT Vulcan mini tower
- Cooling
- Zalman CNPS9900A
- Keyboard
- AZIO L70 Backlit Letters Gaming - ONN Cordless/USB
- Mouse
- MSI DS200 Programmable, Logitech Cordless
- Internet Speed
- 30mbps upgrade - primary hard wired - mini tower usb WiFi
- Antivirus
- GFI VIPRE Internet Security 2014 on W7 2016 beta on W10,
- Browser
- Cyberfox, WaterFox 64bit FF variants, FireFox x64, Pale Moon
- Other Info
- Accomdata fan cooled usb 2.0 PIDE/Sata II, III external enclosure.
Sambient usb/eSata PATA/Sata II, III external enclosure.
-
At a glance
W7 Pro x64/W11 ProAMD Deneb 3.6ghz - 965Kingston Hyper X Fury 8gbMSI HD Radeon 6450 DVI Output- Computer type
- PC/Desktop
- System Manufacturer/Model Number
- CUSTOM ASSEMBLY
- OS
- W7 Pro x64/W11 Pro
- CPU
- AMD Deneb 3.6ghz - 965
- Motherboard
- Gigabyte GA-880GM-D2H remote pc
- Memory
- Kingston Hyper X Fury 8gb
- Graphics Card(s)
- MSI HD Radeon 6450 DVI Output
- Sound Card
- Realtek onooard Creative or Other separate PENDING
- Monitor(s) Displays
- VIZIO 32" LCD TV Separate LCD Pending
- Screen Resolution
- 1600x1080
- Hard Drives
- WD 500GB OS Host/Boot WD Green 1TB Storage/Backup
- PSU
- Corsair 600W - THERMALTAKE 600W spare case
- Case
- NZXT Vulcan mini tower
- Cooling
- Twin 120mm Top Fans - 240mm Side Cover
- Keyboard
- ONN Cordless/USB Logitech Cordless
- Mouse
- ONN USB/Cordless - Logitech Cordless
- Internet Speed
- DSL 5G
- Browser
- MS Edge, FireFox, WaterFox x64, FireFox Nightly
- Other Info
- OS Testing-Remote Access to Main TeamViewer