<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; flash security</title>
	<atom:link href="http://www.darknet.org.uk/tag/flash-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>At Last &#8211; Adobe Launches Sandboxed Flash Player For Firefox</title>
		<link>http://www.darknet.org.uk/2012/02/at-last-adobe-launches-sandboxed-flash-player-for-firefox/</link>
		<comments>http://www.darknet.org.uk/2012/02/at-last-adobe-launches-sandboxed-flash-player-for-firefox/#comments</comments>
		<pubDate>Tue, 07 Feb 2012 18:34:16 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[Security Software]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[adobe flash]]></category>
		<category><![CDATA[adobe flash player]]></category>
		<category><![CDATA[adobe flash security]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[firefox-security]]></category>
		<category><![CDATA[flash]]></category>
		<category><![CDATA[flash exploit]]></category>
		<category><![CDATA[flash exploits]]></category>
		<category><![CDATA[flash player security]]></category>
		<category><![CDATA[flash sandbox]]></category>
		<category><![CDATA[flash security]]></category>
		<category><![CDATA[flash vulnerabilities]]></category>
		<category><![CDATA[hacking-firefox]]></category>
		<category><![CDATA[hacking-flash]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3254</guid>
		<description><![CDATA[Finally a proactive measure from Adobe to try and remedy the horrible security flaws they have introduced to Firefox with their Flash Player. There have been some massive hacks recently due to Flash - - Hackers Exploiting Latest Adobe Flash Bug On Large Scale - Adobe Patches Latest Flash Zero Day Vulnerability - Adobe Promises [...]]]></description>
			<content:encoded><![CDATA[<p>Finally a proactive measure from <a href="http://www.darknet.org.uk/tag/adobe/">Adobe</a> to try and remedy the horrible security flaws they have introduced to Firefox with their Flash Player.</p>
<p>There have been some massive hacks recently due to Flash -</p>
<p>- <a href="http://www.darknet.org.uk/2011/06/hackers-exploiting-latest-adobe-flash-bug-on-large-scale/">Hackers Exploiting Latest Adobe Flash Bug On Large Scale</a><br />
- <a href="http://www.darknet.org.uk/2011/04/adobe-patches-latest-flash-zero-day-vulnerability/">Adobe Patches Latest Flash Zero Day Vulnerability</a><br />
- <a href="http://www.darknet.org.uk/2011/03/adobe-promises-patch-for-flash-0-day-being-used-in-targeted-attacks/">Adobe Promises Patch For Flash 0-day Being Used In Targeted Attacks</a></p>
<p>Those 3 were all in 2011!</p>
<blockquote><p>Adobe has released a beta version of Flash Player for Firefox, which has better protection against vulnerability exploits because of a new sandboxed architecture.</p>
<p>&#8220;The design of this sandbox is similar to what Adobe delivered with Adobe Reader X Protected Mode and follows the same Practical Windows Sandboxing approach,&#8221; said Peleus Uhley, platform security strategist at Adobe, in a blog post on Monday. &#8220;Like the Adobe Reader X sandbox, Flash Player will establish a low integrity, highly restricted process that must communicate through a broker to limit its privileged activities.&#8221;</p>
<p>In secure software development, sandboxing refers to the practice of isolating a process from the operating system in order to minimize the fallout of a potential exploit. This type of technology has gained popularity in recent years, primarily because of its use in Google Chrome, a browser that has never experienced a successful remote code execution attack so far.</p>
<p>Adobe decided to implement sandboxing in Adobe Reader back in 2010 in order to counter the large number of exploits that targeted the product and its users. The technology was built into Adobe Reader X (10.0) and is based on the same sandboxing principles that Google used when developing Chrome.</p>
<p>Later that same year Adobe also launched a sandboxed version of Flash Player for Chrome and promised to explore the possibility of doing the same for other browsers. The new sandboxed Flash Player for Firefox, which works with Windows Vista and Windows 7, is the result of those efforts. </p></blockquote>
<p>They have been talking about sandboxing for a long time and did mention they wanted to sandbox <a href="http://www.darknet.org.uk/2010/10/adobe-pdf-reader-rewrite-to-include-sandbox-feature/">Adobe PDF Reader</a> too, <a href="http://www.darknet.org.uk/tag/chrome/">Chrome</a> has had great success with it&#8217;s sandbox model and I&#8217;m sure many more software vendors will follow suit.</p>
<p>It&#8217;s good to see this approach with the web becoming an extremely dangerous place and more and more commerce is moving online, this gives us a deadly mix of poor security and lots of money floating around.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<blockquote><p>Critical Flash Player vulnerabilities have regularly been exploited to infect computers with malware during the past several years. Along with Java and Adobe Reader, Flash Player is one of the most attacked software applications, because its vulnerabilities can usually be exploited by simply visiting a malicious website.</p>
<p>&#8220;Since its launch in November 2010, we have not seen a single successful exploit in the wild against Adobe Reader X,&#8221; Uhley said. &#8220;We hope to see similar results with the Flash Player sandbox for Firefox once the final version is released later this year.&#8221;</p>
<p>However, the success of this version at deterring cybercriminals from writing Flash Player exploits in the future will largely depend on how quickly it gets adopted. In order to speed up the process, Adobe is working on a new update mechanism, the company&#8217;s senior manager for corporate communications, Wiebke Lips, said.</p>
<p>Having a sandboxed version of Flash Player for every major browser, not just Chrome and Firefox, is also important, if Adobe wants cybercriminals to lose interest in its product. &#8220;We are currently in the process of researching the best path to provide Flash Player sandbox protection for Internet Explorer,&#8221; Lips said.</p>
<p>However, because Internet Explorer has a completely different plug-in architecture than Chrome and Firefox, namely ActiveX, developing a sandboxed Flash Player version for it requires a different approach, Lips said. Nevertheless, the current version of Flash Player supports Protected Mode in Internet Explorer 7 or later on Windows Vista and Windows 7. </p></blockquote>
<p>I&#8217;d like to see them implement a much better and more user-friendly update system for Flash player, so when the update comes out more users get it ASAP.</p>
<p>Also, this is only for <a href="http://www.darknet.org.uk/tag/firefox/">Firefox</a> and the largest target for malware peddlers is Internet <del datetime="2012-02-07T18:31:59+00:00">Exploder</del> Explorer &#8211; so they better get that version sorted out soon too.</p>
<p>Source: <a href="http://www.networkworld.com/news/2012/020612-adobe-launches-sandboxed-flash-player-255783.html?source=nww_rss">Network World</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=At+Last+%E2%80%93+Adobe+Launches+Sandboxed+Flash+Player+For+Firefox+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3254+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2012/02/at-last-adobe-launches-sandboxed-flash-player-for-firefox/&amp;t=At+Last+%E2%80%93+Adobe+Launches+Sandboxed+Flash+Player+For+Firefox" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2012/02/at-last-adobe-launches-sandboxed-flash-player-for-firefox/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2012/02/at-last-adobe-launches-sandboxed-flash-player-for-firefox/&amp;title=At+Last+%E2%80%93+Adobe+Launches+Sandboxed+Flash+Player+For+Firefox" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2012/02/at-last-adobe-launches-sandboxed-flash-player-for-firefox/&amp;title=At+Last+%E2%80%93+Adobe+Launches+Sandboxed+Flash+Player+For+Firefox" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2012/02/at-last-adobe-launches-sandboxed-flash-player-for-firefox/&amp;title=At+Last+%E2%80%93+Adobe+Launches+Sandboxed+Flash+Player+For+Firefox" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2012/02/at-last-adobe-launches-sandboxed-flash-player-for-firefox/&amp;title=At+Last+%E2%80%93+Adobe+Launches+Sandboxed+Flash+Player+For+Firefox" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2012%2F02%2Fat-last-adobe-launches-sandboxed-flash-player-for-firefox%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2012/02/at-last-adobe-launches-sandboxed-flash-player-for-firefox/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Hackers Exploiting Latest Adobe Flash Bug On Large Scale</title>
		<link>http://www.darknet.org.uk/2011/06/hackers-exploiting-latest-adobe-flash-bug-on-large-scale/</link>
		<comments>http://www.darknet.org.uk/2011/06/hackers-exploiting-latest-adobe-flash-bug-on-large-scale/#comments</comments>
		<pubDate>Tue, 21 Jun 2011 09:41:57 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[adobe flash]]></category>
		<category><![CDATA[adobe flash security]]></category>
		<category><![CDATA[adobe flash vulnerability]]></category>
		<category><![CDATA[flash]]></category>
		<category><![CDATA[flash exploit]]></category>
		<category><![CDATA[flash patch]]></category>
		<category><![CDATA[flash security]]></category>
		<category><![CDATA[flash vulnerability]]></category>
		<category><![CDATA[hacking adobe flash]]></category>
		<category><![CDATA[hacking-flash]]></category>
		<category><![CDATA[out of band patch]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3137</guid>
		<description><![CDATA[It&#8217;s very out of character for Adobe &#8211; but they&#8217;ve actually released two out of band patches in the last week or so. They&#8217;ve had to patch 4 times in the past 2 months &#8211; that&#8217;s a total of 6 times in 2011 so far &#8211; with 5 out of those 6 being for critical [...]]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s very out of character for <a href="http://www.darknet.org.uk/tag/adobe/">Adobe</a> &#8211; but they&#8217;ve actually released two <a href="http://www.darknet.org.uk/tag/out-of-band/">out of band</a> patches in the last week or so.</p>
<p>They&#8217;ve had to patch 4 times in the past 2 months &#8211; that&#8217;s a total of 6 times in 2011 so far &#8211; with 5 out of those 6 being for critical bugs.</p>
<p>It seems like <a href="http://www.darknet.org.uk/tag/flash/">Flash</a> has become a major target for hackers in the past 6 months or so, despite the fact that Adobe has worked with Google to sandbox Flash in the <a href="http://www.darknet.org.uk/tag/chrome/">Chrome</a> browser.</p>
<blockquote><p>Hackers are aggressively exploiting a just-patched Flash vulnerability, serving attack code &#8220;on a fairly large scale&#8221; from compromised sites as well as from their own malicious domains, a security researcher said Friday. The attacks exploit the critical Flash Player bug that Adobe patched June 14 with its second &#8220;out-of-band,&#8221; or emergency update, in nine days.</p>
<p>&#8220;CVE-2011-2110 is being exploited in the wild on a fairly large scale,&#8221; said Steven Adair, a researcher with the Shadowserver Foundation, a volunteer-run group that tracks vulnerabilities and botnets. &#8220;In particular this exploit is showing up as a drive-by in several legitimate websites, including those belonging to various NGOs [non-government organizations], aerospace companies, a Korean news site, an Indian government Web site, and a Taiwanese university.&#8221;</p>
<p>CVE-2011-2110 is the identifier for the Flash vulnerability assigned by the Common Vulnerabilities and Exposures database. Attackers are also using the exploit in &#8220;spear phishing&#8221; attacks aimed at specific individuals, said Adair on the Shadowserver site. Adair called the attacks &#8220;nasty&#8221; because the exploit &#8220;happens seamlessly in the background,&#8221; giving victims no clue that their systems have been compromised. </p></blockquote>
<p>The CVE ID for this vulnerability is &#8211; <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2110">CVE-2011-2110</a> with the <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-2110">NVD listing</a> stating:</p>
<p><code>Adobe Flash Player before 10.3.181.26 on Windows, Mac OS X, Linux, and Solaris, and 10.3.185.23 and earlier on Android, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as exploited in the wild in June 2011.</code></p>
<p>Sounds pretty nasty, at least the patch is out for it &#8211; but as usual, how many people will apply it in a timely fashion?</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<blockquote><p>When Adobe patched the vulnerability last week, it conceded that exploits were already in use.</p>
<p>Adair also said there&#8217;s been an increase in Flash-based attacks. &#8220;There has been an ongoing assault against Flash Player for several years now, but especially so in the last three months,&#8221; Adair said.</p>
<p>Adobe has patched Flash Player four times in the last two months, and six times so far this year. Of the six updates, five addressed &#8220;zero-day&#8221; bugs that attackers were already exploiting at the time the patches were issued.</p>
<p>Brad Arkin, Adobe&#8217;s director of product security and privacy, acknowledged the problems in keeping ahead of attackers, but blamed the popularity of Flash Player for the attention.</p>
<p>&#8220;The installed base [of Flash Player] is a real big part of it,&#8221; said Arkin. &#8220;It&#8217;s such a widely distributed technology that attackers find it worthwhile to invest the time to carry out some kind of malicious activity. They&#8217;re making an investment for the biggest return possible.&#8221;</p>
<p>Arkin also argued that attackers get more bang for their buck by rooting out Flash vulnerabilities than they do looking for bugs in individual browsers because virtually every personal computer has the Flash plug-in installed. &#8220;Flash is the code [used in the browser] that has the highest market penetration,&#8221; he said.</p>
<p>According to Adair, the exploit of CVE-2011-2110 has been in use since June 9, five days before Adobe issued its latest security update. Arkin corroborated that timeline.</p></blockquote>
<p>Adobe does claim to be more pro-active about patching than Microsoft &#8211; which honestly isn&#8217;t really hard is it? Brad Arkin the head of security said:</p>
<p>&#8220;<em>I think we&#8217;re more aggressive than Microsoft, basically, if we have information about attacks in the wild, or if the information is out there on a mailing list &#8212; which means attacks are imminent &#8212; that tends to be a trigger for us to think about an out-of-band.</em>&#8221; </p>
<p>Do note they said &#8216;think&#8217; about a patch though and not &#8216;issue&#8217; one.</p>
<p>Source: <a href="http://www.networkworld.com/news/2011/062011-attackers-exploit-latest-flash-bug.html?source=nww_rss">Network World</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Hackers+Exploiting+Latest+Adobe+Flash+Bug+On+Large+Scale+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3137+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/06/hackers-exploiting-latest-adobe-flash-bug-on-large-scale/&amp;t=Hackers+Exploiting+Latest+Adobe+Flash+Bug+On+Large+Scale" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/06/hackers-exploiting-latest-adobe-flash-bug-on-large-scale/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/06/hackers-exploiting-latest-adobe-flash-bug-on-large-scale/&amp;title=Hackers+Exploiting+Latest+Adobe+Flash+Bug+On+Large+Scale" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/06/hackers-exploiting-latest-adobe-flash-bug-on-large-scale/&amp;title=Hackers+Exploiting+Latest+Adobe+Flash+Bug+On+Large+Scale" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/06/hackers-exploiting-latest-adobe-flash-bug-on-large-scale/&amp;title=Hackers+Exploiting+Latest+Adobe+Flash+Bug+On+Large+Scale" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/06/hackers-exploiting-latest-adobe-flash-bug-on-large-scale/&amp;title=Hackers+Exploiting+Latest+Adobe+Flash+Bug+On+Large+Scale" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F06%2Fhackers-exploiting-latest-adobe-flash-bug-on-large-scale%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/06/hackers-exploiting-latest-adobe-flash-bug-on-large-scale/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Adobe Promises Patch For Flash 0-day Being Used In Targeted Attacks</title>
		<link>http://www.darknet.org.uk/2011/03/adobe-promises-patch-for-flash-0-day-being-used-in-targeted-attacks/</link>
		<comments>http://www.darknet.org.uk/2011/03/adobe-promises-patch-for-flash-0-day-being-used-in-targeted-attacks/#comments</comments>
		<pubDate>Tue, 15 Mar 2011 10:30:57 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[General News]]></category>
		<category><![CDATA[0-day]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[adobe flash]]></category>
		<category><![CDATA[adobe flash security]]></category>
		<category><![CDATA[adobe security]]></category>
		<category><![CDATA[flash 0-day]]></category>
		<category><![CDATA[flash exploit]]></category>
		<category><![CDATA[flash security]]></category>
		<category><![CDATA[flash vulnerability]]></category>
		<category><![CDATA[flash zero day]]></category>
		<category><![CDATA[hacking-flash]]></category>
		<category><![CDATA[out of band patch]]></category>
		<category><![CDATA[zero-day]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3066</guid>
		<description><![CDATA[With all the new vulnerabilities with working exploits pouring out of Pwn2Own, I can&#8217;t say I expected to see another 0-day in Adobe Flash outside of the contest. It wasn&#8217;t that long ago (back in October 2010) when there was another Critical 0-day Vulnerability In Adobe Flash Player, Reader &#038; Acrobat and Adobe were scrambling [...]]]></description>
			<content:encoded><![CDATA[<p>With all the new vulnerabilities with working exploits pouring out of <a href="http://www.darknet.org.uk/tag/pwn2own/">Pwn2Own</a>, I can&#8217;t say I expected to see another 0-day in <a href="http://www.darknet.org.uk/tag/adobe-flash/">Adobe Flash</a> outside of the contest.</p>
<p>It wasn&#8217;t that long ago (back in October 2010) when there was another <a href="http://www.darknet.org.uk/2010/10/critical-0-day-vulnerability-in-adobe-flash-player-reader-acrobat/">Critical 0-day Vulnerability In Adobe Flash Player, Reader &#038; Acrobat</a> and <a href="http://www.darknet.org.uk/tag/adobe/">Adobe</a> were scrambling to fix it.</p>
<p>They are promising an out of band patch for this vulnerability as it&#8217;s marked as critical and has apparently been seen in the wild, but only in a few targeted attacks according to this blog post by Adobe:</p>
<p><a href="http://blogs.adobe.com/asset/2011/03/background-on-apsa11-01-patch-schedule.html">Background on APSA11-01 Patch Schedule</a></p>
<blockquote><p>Adobe Systems plans to release emergency patches for its Flash and Reader applications after learning a critical vulnerability is being exploited to install malware on vulnerable machines.</p>
<p>The out-of-cycle patches for Adobe Flash Player 10 and Acrobat and Reader versions 9, 10, and X will arrive during the week March 21, the company said on Monday. The updates will cover all versions of those programs except for Reader X for Windows, which ships with a security sandbox that blocks the exploits Adobe has observed so far.</p>
<p>The announcement comes after members of Adobe&#8217;s security team received reports of targeted attacks aimed “at a very small number of organizations and limited in scope” that “install persistent malware on the victim&#8217;s machine,” the company said in an advisory. The exploits wield a booby-trapped Flash file hidden inside a Microsoft Excel file attached to an email.</p>
<p>The attacks exploit an unspecified flaw in Flash Player for the Windows, Mac, Linux, Solaris and Android operating systems. Adobe security members are unaware of other types of attacks, such as those that plant the malicious Flash file in documents using the the PDF, or portable document format, specification.</p></blockquote>
<p>It&#8217;s a pretty tricky attack with multiple layers, it seems like the Flash exploit itself is embedded in an Excel file attached to e-mails. It looks like corporate users of Reader X will be out of luck as there is no patch for that version. But then <a href="http://www.darknet.org.uk/tag/adobe/">Adobe</a> states as Reader X comes with a sandbox the exploit won&#8217;t actually function anyway.</p>
<p>The patch is slated to come out next week sometime, there are no specifics as of yet &#8211; I guess it depends how long it takes them to fix the problem reliably. They are looking to rush the patch out though rather than waiting for the next cycle.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<blockquote><p>“However, attackers have leveraged these type [sic] of Flash Player vulnerabilities in the past via .pdf files to attack the embedded authplay.dll component shipping with Adobe Reader and Acrobat v9,” Brad Arkin, Adobe&#8217;s senior director of product security and privacy, wrote. “Out of a preponderance of caution we took the decision to ship out-of-cycle updates for Adobe Reader and Acrobat v9, and Acrobat X to mitigate the risk of attackers shifting the attack from an .xls container to a .pdf container.”</p>
<p>The unscheduled patch won&#8217;t cover Reader X for Windows, because that recently released version of the program contains a Sandbox that isolates remotely supplied payloads from the OS&#8217;s core functions. As a result, the exploits Adobe has seen to date aren&#8217;t able to successfully execute on machines that run it. Many Reader users, particularly those in corporate settings, still run versions 10 or 9 of Reader, meaning they will remain vulnerable until the emergency patch is installed.</p>
<p>Excluding Reader X for Windows from the out-of-cycle release will allow Adobe engineers to publish it more quickly than it otherwise could. The fix for that version will be released on June 14, during Adobe&#8217;s next scheduled quarterly update.</p></blockquote>
<p>The Security Bulletin from Adobe is here:</p>
<p><a href="http://www.adobe.com/support/security/advisories/apsa11-01.html">Security Advisory for Adobe Flash Player, Adobe Reader and Acrobat</a></p>
<p>It has been assigned the CVE Number: CVE-2011-0609</p>
<p>Source: <a href="http://www.theregister.co.uk/2011/03/14/adobe_flash_reader_emergency_patch/">The Register</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Adobe+Promises+Patch+For+Flash+0-day+Being+Used+In+Targeted+Attacks+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3066+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/03/adobe-promises-patch-for-flash-0-day-being-used-in-targeted-attacks/&amp;t=Adobe+Promises+Patch+For+Flash+0-day+Being+Used+In+Targeted+Attacks" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/03/adobe-promises-patch-for-flash-0-day-being-used-in-targeted-attacks/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/03/adobe-promises-patch-for-flash-0-day-being-used-in-targeted-attacks/&amp;title=Adobe+Promises+Patch+For+Flash+0-day+Being+Used+In+Targeted+Attacks" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/03/adobe-promises-patch-for-flash-0-day-being-used-in-targeted-attacks/&amp;title=Adobe+Promises+Patch+For+Flash+0-day+Being+Used+In+Targeted+Attacks" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/03/adobe-promises-patch-for-flash-0-day-being-used-in-targeted-attacks/&amp;title=Adobe+Promises+Patch+For+Flash+0-day+Being+Used+In+Targeted+Attacks" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/03/adobe-promises-patch-for-flash-0-day-being-used-in-targeted-attacks/&amp;title=Adobe+Promises+Patch+For+Flash+0-day+Being+Used+In+Targeted+Attacks" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F03%2Fadobe-promises-patch-for-flash-0-day-being-used-in-targeted-attacks%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/03/adobe-promises-patch-for-flash-0-day-being-used-in-targeted-attacks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Critical Zero Day Abobe Flash Flaw Puts Android Phones At Risk</title>
		<link>http://www.darknet.org.uk/2010/09/critical-zero-day-abobe-flash-flaw-puts-android-phones-at-risk/</link>
		<comments>http://www.darknet.org.uk/2010/09/critical-zero-day-abobe-flash-flaw-puts-android-phones-at-risk/#comments</comments>
		<pubDate>Wed, 15 Sep 2010 06:34:50 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[General News]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[adobe flash]]></category>
		<category><![CDATA[adobe flash security]]></category>
		<category><![CDATA[android]]></category>
		<category><![CDATA[android exploit]]></category>
		<category><![CDATA[android vulnerability]]></category>
		<category><![CDATA[flash]]></category>
		<category><![CDATA[flash 0-day]]></category>
		<category><![CDATA[flash exploit]]></category>
		<category><![CDATA[flash security]]></category>
		<category><![CDATA[flash vulnerability]]></category>
		<category><![CDATA[flash zero day]]></category>
		<category><![CDATA[smart-phone security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2950</guid>
		<description><![CDATA[Adobe hasn&#8217;t been having the best of luck recently with a string of serious PDF exploits in their Reader software and now in less than a week two critical flaws in Flash. This is a pretty serious flaw and sadly proves Steve Jobs right for not supporting Flash on the iPhone and Ipad. A new [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.darknet.org.uk/tag/adobe/">Adobe</a> hasn&#8217;t been having the best of luck recently with a string of <a href="http://www.darknet.org.uk/2010/08/adobe-scrambling-to-fix-another-serious-pdf-flaw/">serious PDF exploits</a> in their Reader software and now in less than a week two critical flaws in <a href="http://www.darknet.org.uk/tag/flash/">Flash</a>.</p>
<p>This is a pretty serious flaw and sadly proves Steve Jobs right for not supporting Flash on the <a href="http://www.darknet.org.uk/tag/iphone/">iPhone</a> and Ipad. A new twist is that this vulnerability extends to mobile platforms such as Android due to the full support for flash. It also effects desktop systems across the board (Windows, Mac, Linux &#038; Solaris).</p>
<blockquote><p>Adobe revealed a critical zero day flaw  in Adobe Flash&#8211;the second in less than a week. The vulnerability extends even to Adobe Flash on the Android mobile OS, supporting at least one of the reasons laid out by Steve Jobs for not allowing Flash on the iPhone and iPad.</p>
<p>An Adobe spokesperson contacted me and shared that, &#8220;A critical vulnerability exists in Adobe Flash Player 10.1.82.76 and earlier versions for Windows, Macintosh, Linux, Solaris and Android operating systems. This vulnerability also affects Adobe Reader 9.3.4 for Windows, Macintosh and UNIX, and Adobe Acrobat 9.3.4 and earlier versions for Windows and Macintosh.&#8221;</p>
<p>In a nutshell, the critical flaw could be exploited to crash the affected system, or may even allow an attacker to gain access and control it to execute additional malicious software. There are reports that this vulnerability is being actively exploited in the wild against Adobe Flash Player, but Adobe is not aware of any attacks exploiting it against Adobe Reader or Acrobat thus far.</p>
<p>The Adobe spokesperson explained, &#8220;Adobe is actively sharing information about this vulnerability (and vulnerabilities in general) with partners in the security community to enable them to quickly develop detection and quarantine methods to protect users until a patch is available. As always, Adobe recommends that users follow security best practices by keeping their anti-malware software and definitions up to date.&#8221; </p></blockquote>
<p>There are reports of this vulnerability being exploited in the wild, but I haven&#8217;t really seen any details of it so far. It&#8217;s an interesting point regarding smart-phones and I wonder how Android developers might look at addressing this kind of issue and safeguarding the phones in the future.</p>
<p>A sandbox method might be a good idea, and from what I know of Android you don&#8217;t have root privileges by default anyway. We&#8217;ll have to see if Android makes any announcements regarding this or comes out with any kind of plan for future safeguards.</p>
<blockquote><p>Those best practices are long established among the traditional desktop computing platforms, but users running Adobe Flash on Android smartphones  may be left wondering exactly which &#8220;best practices&#8221; will protect them. Smartphones have grown into palm-based portable computers&#8211;with processing power and storage space significant enough to be a worthy target&#8211;but smartphone security is not as evolved as its desktop and notebook counterparts.</p>
<p>As Microsoft has improved its software development processes and implemented new security controls in the Windows operating system and other applications, attackers have looked elsewhere to find the chinks in the armor. Adobe has emerged as the virtually ubiquitous low-hanging fruit&#8211;with security practices that are not as mature as Microsoft&#8217;s, and software with potentially exploitable weaknesses available on pretty much every platform out there.</p>
<p>The iPhone and iPad stand uniquely apart from other smartphone and tablet platforms thanks to Apple&#8217;s very public rejection of Adobe Flash for iOS. While the real reasons probably have more to do with iAd and wanting to exert tighter control over the developer community, security is also a concern that has been cited. Zero day flaws like this one, which potentially impact Android smartphones running Adobe Flash, seem to illustrate the wisdom of that choice. </p></blockquote>
<p>You can read the security advisory from Adobe here &#8211; <a href="http://www.adobe.com/support/security/advisories/apsa10-03.html">Security Advisory for Flash Player</a>, the fix has not been issued as yet but they do state they are working on it so expect a flash update soon.</p>
<p>It&#8217;ll be interesting to see what comes of this and how fast Adobe can push a patch out.</p>
<p>Source: <a href="http://www.networkworld.com/news/2010/091410-adobe-flash-zero-day-puts.html?source=nww_rss">Network World</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Critical+Zero+Day+Abobe+Flash+Flaw+Puts+Android+Phones+At+Risk+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2950+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/09/critical-zero-day-abobe-flash-flaw-puts-android-phones-at-risk/&amp;t=Critical+Zero+Day+Abobe+Flash+Flaw+Puts+Android+Phones+At+Risk" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/09/critical-zero-day-abobe-flash-flaw-puts-android-phones-at-risk/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/09/critical-zero-day-abobe-flash-flaw-puts-android-phones-at-risk/&amp;title=Critical+Zero+Day+Abobe+Flash+Flaw+Puts+Android+Phones+At+Risk" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/09/critical-zero-day-abobe-flash-flaw-puts-android-phones-at-risk/&amp;title=Critical+Zero+Day+Abobe+Flash+Flaw+Puts+Android+Phones+At+Risk" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/09/critical-zero-day-abobe-flash-flaw-puts-android-phones-at-risk/&amp;title=Critical+Zero+Day+Abobe+Flash+Flaw+Puts+Android+Phones+At+Risk" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/09/critical-zero-day-abobe-flash-flaw-puts-android-phones-at-risk/&amp;title=Critical+Zero+Day+Abobe+Flash+Flaw+Puts+Android+Phones+At+Risk" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F09%2Fcritical-zero-day-abobe-flash-flaw-puts-android-phones-at-risk%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/09/critical-zero-day-abobe-flash-flaw-puts-android-phones-at-risk/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>SWFScan &#8211; Free Flash Application Security Scanner</title>
		<link>http://www.darknet.org.uk/2009/09/swfscan-free-flash-application-security-scanner/</link>
		<comments>http://www.darknet.org.uk/2009/09/swfscan-free-flash-application-security-scanner/#comments</comments>
		<pubDate>Tue, 08 Sep 2009 05:34:39 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[flash application security]]></category>
		<category><![CDATA[flash decompiler]]></category>
		<category><![CDATA[flash security]]></category>
		<category><![CDATA[flash-hacking]]></category>
		<category><![CDATA[hacking-flash]]></category>
		<category><![CDATA[hacking-websites]]></category>
		<category><![CDATA[swfscan]]></category>
		<category><![CDATA[web-application-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2054</guid>
		<description><![CDATA[HP SWFScan is a free tool developed by HP Web Security Research Group, which will automatically find security vulnerabilities in applications built on the Flash platform. HP is offering SWFScan because: Their research shows that developers and increasingly implementing applications built on the Adobe Flash platform without the required security expertise. As a result, they [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>HP SWFScan is a free tool developed by HP Web Security Research Group, which will automatically find security vulnerabilities in applications built on the Flash platform.</p>
<p>HP is offering SWFScan because:</p>
<ul>
<li>Their research shows that developers and increasingly implementing applications built on the Adobe Flash platform without the required security expertise.</li>
<li>As a result, they are seeing a proliferation of insecure applications being deployed on the web.</li>
<li>A vulnerable application built on the Flash platform widens your website’s attack surface creating more opportunity for malicious hackers.</li>
</ul>
<p>How SWFScan works and what vulnerabilities it finds:</p>
<ul>
<li>Decompiles applications built on the Adobe Flash platform to extract the ActionScript code and statically analyzes it to identify security issues such as information disclosure.</li>
<li>Identifies and reports insecure programming and deployment practices and suggests solutions.</li>
<li>Enables you to audit third party applications without requiring access to the source code.</li>
</ul>
<p>You can download SWFScan here:</p>
<p><a href="https://h30406.www3.hp.com/campaigns/2009/wwcampaign/1-5TUVE/images/SwfScan.msi">SwfScan.msi</a></p>
<p></p>
<p>Or read more <a href="https://h30406.www3.hp.com/campaigns/2009/wwcampaign/1-5TUVE/index.php?key=swf">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=SWFScan+%E2%80%93+Free+Flash+Application+Security+Scanner+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2054+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/09/swfscan-free-flash-application-security-scanner/&amp;t=SWFScan+%E2%80%93+Free+Flash+Application+Security+Scanner" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/09/swfscan-free-flash-application-security-scanner/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/09/swfscan-free-flash-application-security-scanner/&amp;title=SWFScan+%E2%80%93+Free+Flash+Application+Security+Scanner" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/09/swfscan-free-flash-application-security-scanner/&amp;title=SWFScan+%E2%80%93+Free+Flash+Application+Security+Scanner" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/09/swfscan-free-flash-application-security-scanner/&amp;title=SWFScan+%E2%80%93+Free+Flash+Application+Security+Scanner" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/09/swfscan-free-flash-application-security-scanner/&amp;title=SWFScan+%E2%80%93+Free+Flash+Application+Security+Scanner" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F09%2Fswfscan-free-flash-application-security-scanner%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/09/swfscan-free-flash-application-security-scanner/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>SWFIntruder &#8211; Analysis and Security Testing of Flash Applications</title>
		<link>http://www.darknet.org.uk/2008/02/swfintruder-analysis-and-security-testing-of-flash-applications/</link>
		<comments>http://www.darknet.org.uk/2008/02/swfintruder-analysis-and-security-testing-of-flash-applications/#comments</comments>
		<pubDate>Fri, 22 Feb 2008 08:58:27 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[flash]]></category>
		<category><![CDATA[flash applications]]></category>
		<category><![CDATA[flash security]]></category>
		<category><![CDATA[hacking-flash]]></category>
		<category><![CDATA[swfintruder]]></category>
		<category><![CDATA[testing flash security]]></category>
		<category><![CDATA[web-application-security]]></category>
		<category><![CDATA[web-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2008/02/swfintruder-analysis-and-security-testing-of-flash-applications/</guid>
		<description><![CDATA[With a recent spate of attacks from banner ads (many of which are using flash) this might be a useful tool if you are using flash or more accurately flash applications on your website or portal. I did mention a Flash decompiler a while back, now we have SWFIntruder (pronounced Swiff Intruder), which is apparently [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>With a recent spate of attacks from banner ads (many of which are using flash) this might be a useful tool if you are using flash or more accurately flash applications on your website or portal.</p>
<p>I did mention a <a href="http://www.darknet.org.uk/2007/09/flare-flash-decompiler-to-extract-actionscript/">Flash decompiler</a> a while back, now we have SWFIntruder (pronounced Swiff Intruder), which is apparently the first tool specifically developed for analyzing and testing security of Flash applications at runtime.</p>
<p>It helps to find flaws in Flash applications using the methodology originally described in <a href="http://www.owasp.org/images/8/8c/OWASPAppSec2007Milan_TestingFlashApplications.ppt">Testing Flash Applications</a> and in <a href="http://www.owasp.org/images/d/d8/OWASP-WASCAppSec2007SanJose_FindingVulnsinFlashApps.ppt">Finding Vulnerabilities in Flash Applications</a>.</p>
<p><strong>Features</strong></p>
<ul>
<li>Basic predefined attack patterns.</li>
<li>Highly customizable attacks.</li>
<li>Highly customizable undefined variables.</li>
<li>Semi automated XSS check.</li>
<li>User configurable internal parameters.</li>
<li>Log Window for debugging and tracking.</li>
<li>History of latest 5 tested SWF files.</li>
<li>ActionScript Objects runtime explorer in tree view.</li>
<li>Persistent Configuration and Layout. </li>
</ul>
<p>SWFIntruder was developed using ActionScript, Html and JavaScript resulting in a tool taking advantage of the best features of those technologies in order to get the best capabilities for analysis and interaction with the testing Flash movies.</p>
<p>SWFIntruder was developed by using only open source software. Thanks to its generality, SWFIntruder is OS independant.</p>
<p>You can download SWFIntruder here:</p>
<p><a href="http://swfintruder.googlecode.com/files/swfintruder-0.9.1.tgz">swfintruder-0.9.1.tgz</a></p>
<p></p>
<p>Or read more <a href="https://www.owasp.org/index.php/Category:SWFIntruder">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=SWFIntruder+%E2%80%93+Analysis+and+Security+Testing+of+Flash+Applications+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D759+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2008/02/swfintruder-analysis-and-security-testing-of-flash-applications/&amp;t=SWFIntruder+%E2%80%93+Analysis+and+Security+Testing+of+Flash+Applications" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2008/02/swfintruder-analysis-and-security-testing-of-flash-applications/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2008/02/swfintruder-analysis-and-security-testing-of-flash-applications/&amp;title=SWFIntruder+%E2%80%93+Analysis+and+Security+Testing+of+Flash+Applications" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2008/02/swfintruder-analysis-and-security-testing-of-flash-applications/&amp;title=SWFIntruder+%E2%80%93+Analysis+and+Security+Testing+of+Flash+Applications" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2008/02/swfintruder-analysis-and-security-testing-of-flash-applications/&amp;title=SWFIntruder+%E2%80%93+Analysis+and+Security+Testing+of+Flash+Applications" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2008/02/swfintruder-analysis-and-security-testing-of-flash-applications/&amp;title=SWFIntruder+%E2%80%93+Analysis+and+Security+Testing+of+Flash+Applications" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2008%2F02%2Fswfintruder-analysis-and-security-testing-of-flash-applications%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2008/02/swfintruder-analysis-and-security-testing-of-flash-applications/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

