This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Flash file cross-site scripting vulns

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://www.us-cert.gov/current/#flash_auth…rate_vulnerable
January 2, 2008 - "US-CERT is aware of reported vulnerabilities in Flash (SWF) files that may allow a remote, unauthenticated attacker to conduct cross-site scripting attacks on a vulnerable system. The flaws exist in the way that input is validated when passed to embedded ActionsScript and JavaScript in the SWF file. Authoring tools that automatically generate Flash files may introduce these vulnerabilities.
More information regarding these vulnerabilities can be found in:
> Vulnerability Note VU#249337 - http://www.kb.cert.org/vuls/id/249337
> Web site document "XSS Vulnerabilities in Common Shockwave Flash Files"
http://docs.google.com/View?docid=ajfxntc4dmsq_14dt57ssdw

:ph34r:
More…

- http://www.theregister.co.uk/2008/01/02/buggy_flash_fix/
"…Security pros and Flash authors may also want to use Stafano Di Paola's SWFIntruder* to check for vulnerabilities in their content… The buggy Flash files are known to be contained on tens of thousands of websites, many belonging to banks, government agencies and major corporations, according to the authors, who relied on Google searches for their estimate. The actual number of sites could be in the hundreds of thousands because vulnerable files don't always turn up in web searches…"
* https://www.owasp.org/index.php/Category:SWFIntruder

:ph34r:
FYI…

- http://www.securityfocus.com/news/11511
2008-03-28 - "Warnings about the insecurity of online Flash multimedia created with all but the most recent authoring tools have largely fallen upon deaf ears.. While software makers have taken steps to close the security holes, Web site owners continue to host older files created by older authoring programs that are vulnerable to cross-site scripting (XSS) attacks, Rich Cannings, information security engineer of search giant Google, told security professionals… Using a specially-crafted Web address, an attacker could use a vulnerable Flash file on a major Web site to gain access to the user's account on that site, once the victim logs in. A bad Flash file on a banking site, for example, could put that bank's customers at risk, allowing an attacker the ability to access the victims' funds… until Web site developers rebuild their Flash multimedia with the latest authoring tools, the older files still present on their company's Web sites could be used by fraudsters to attack the site's users… Adobe estimates that 98 percent of Web users have the Adobe Flash Player installed. Flash is widely used to create the advertisements hosted on most Web sites. Because the advertisements are generally provided by third-party services, using the affiliate networks to send out malicious Flash advertisements has become a serious vector of attack…"
* http://www.adobe.com/devnet/flashplayer/ar…ity_update.html
"Adobe is planning to release a security update for Flash Player 9 in April 2008 to strengthen the security of Adobe Flash Player for our customers and end users… This security update will make the optional socket policy file changes introduced in Flash Player 9,0,115,0 mandatory…"

:( :ph34r: