Newsletters

Select newsletters below and click the button to sign up!

Boston News NY News
DC News Internet Daily
SiliconValley News
InternetNews Business Report




Become a Marketplace Partner



Partner With Us















Internetnews Bloggers

Recent Entries

Archives

October 2009
Sun Mon Tue Wed Thu Fri Sat
        1 2 3
4 5 6 7 8 9 10
11 12 13 14 15 16 17
18 19 20 21 22 23 24
25 26 27 28 29 30 31

Monthly Archives

Search The Blog

Netstat -vat by Sean Michael Kerner (bio)

A command line view of IT



Black Hat : Blinded by Flash security

blackhat.jpg
From the 'flash isn't always secure' files:

WASHINGTON DC -- Adobe's Flash format is everywhere on the web, but be warned : Flash files could potentially be carriers of security exploits.

At least that's the allegation of HP security researcher  Prajakta Jagdale who today talked about Flash security in a session at Black Hat DC. There are a number of different types of vulnerabilites that could affect Flash including information disclosure and cross site scripting issues.  Though ultimately Jagdale argued that it comes down to proper coding and validation to secure Flash.

On the low hanging fruit side, Jagdale noted that some Flash developers hardcode username and password information into files.  A simple Google search with the search query  "Filetype:swf inurl:login  " was used by Jagdale to show how easy it is to identify vulnerable flash sites.

Additionally she noted that Flash allows for text boxes that could have HTML values - as such HTML injection could lead to exploit.
"You always need to validate inputs," Jagdale said.
Again she did a basic Google search to try and find potentially vulnerable Flash sites for HTML injection. She used the query "filetype:swf inurl:clickTag". When she did the search she claimed that she got at least 200 results of which in her analysis  120 were found to be vulnerable to XSS.

Jagdale advised that in addition to input validation developers should use SSL and should avoid storing sensitive information in the Flash application.

| Comments (0) | TrackBacks (0) | Share

0 TrackBacks

Listed below are links to blogs that reference this entry: Black Hat : Blinded by Flash security.

TrackBack URL for this entry: https://swarm.jupitermedia.com/mt-tb.cgi/7466

Leave a comment