Results 1 to 2 of 2

Thread: Serious Flash vulns menace at least 10,000 websites

  1. #1
    Broken's Avatar Obama Supporter
    Join Date
    Sep 2003
    Location
    Washington, DC
    Posts
    1,904
    Serious Flash vulns menace at least 10,000 websites

    Researchers from Google and a well-known security firm have documented serious vulnerabilities in Adobe Flash content which leave tens of thousands of websites susceptible to attacks that steal the personal details of visitors.

    The security bugs reside in Flash applets, the ubiquitous building blocks for movies and graphics that animate sites across the web. Also known as SWF files, they are vulnerable to attacks in which malicious strings are injected into the legitimate code through a technique known as cross-site scripting, or XSS. Currently there are no patches for the vulnerabilities, which are found in sites operated by financial institutions, government agencies and other organizations

    A security update Adobe released this week for its Flash player doesn't fix the vulnerabilities, Stamos said.

    Attack scenarios work something like this: A bank website hosts marketing graphics in the form of a vulnerable Flash applet. Attackers who trick a customer into clicking on a malicious link are able to execute the SWF file but inject malicious code variables that cause the customer's authentication cookies or login credentials to be sent to the attacker.

    "There are definitely lots of people who are vulnerable," Stamos said. "Tens of thousands is very conservative. Realistically, it's probably in the hundreds (of thousands)."

    read more...

    Source: http://www.theregister.co.uk/

  2. News (Archive)   -   #2
    mbucari1's Avatar Poster BT Rep: +35BT Rep +35BT Rep +35BT Rep +35BT Rep +35BT Rep +35BT Rep +35
    Join Date
    Jan 2007
    Age
    37
    Posts
    2,477
    *goes and deletes cookies

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •