Zero-day Flash exploit on all platforms, fix two weeks out
adobe.com
adobe.com
YouTube HTML5 support is good, and for any other video you can directly download. Browser runs a lot faster, web pages load faster, and I don't miss flash ads at all.
I also disabled flash on my parents' computer, and my brothers, and enabled YouTube HTML5 for them. They haven't noticed it yet. It is only a matter of time before more corporate networks uninstall/block all flash, especially with the bad reputation it has with security.
Flash is already dead to me, I can't wait until it is dead for everybody else as well
Firefox: https://addons.mozilla.org/en-US/firefox/addon/433/
Chrome: https://chrome.google.com/extensions/detail/cdngiadmnkhgemki...
Killing everything is much better.
https://chrome.google.com/extensions/detail/gofhjkjmkpinhpoi...
Is that good enough proof that the SWF is not put into memory?
Also, the FlashBlockBlock page here does not load when I have the extension enabled: https://woofle.net/flashblockblock/
http://www.theregister.co.uk/2010/09/13/adobe_flash_0day_vul...
It is easy to turn off Flash in the Firefox plugins, and running the Better Privacy extension which kills the Flash hidden cookies normal cookie management doesn't touch. (One stalks you keeping track of every site you've visited with Flash) Better Privacy isn't yet compatible with the Firefox 4 beta but is fine with 3.x
NoScript is still a good idea for many reasons.
The malware is worse this year than last... http://www.gdatasoftware.co.uk/about-g-data/press-centre/new...
ClickToFlash for native Webkit views on OS X actually blocks Flash for real — it's a native Webkit plugin that registers for Flash's primary mimetype and preempts it. When you selectively enable a flash embed, it replaces itself with Adobe's NPAPI plugin.
[EDIT: Note: I don't know how safe the link in this article is.] http://seclists.org/fulldisclosure/2008/Jul/444
The payload is harmless but silly.
Now instead of disabling individual plugins, now in Chrome I do not allow any site to use plugins, then go back and whitelist sites as needed.
I jest, but flash is the perfect target if you want to hit multiple OS's. Doesn't mean the malware authors will actually develop exploits/malcode for multiple OS's though.
As an aside, the alpha releases for Flash on Linux are surprisingly stable. The "gray rectangle" problem appears to be solved, which was the worst part of Flash on Linux in years past. Video streaming works well, but animations flicker and tear, so most online games are still unplayable.
I'm surprised to be reading so much talk about Flash not working very well on Linux. I'm using Fedora 13 (previously Ubuntu) on an extremely low-performance machine, and I haven't seen any problems in a very long time (at least a year). Video's, games, etc... all seem to work fine, and I generally pay a lot of attention to the Flash player because I'm a flex developer. The only time I struggle is when I watch HD video, but that's to be expected on my machine even if I'm watching a DVD.
One thing that seems to reliably fail is full-screen video, though.
Let's not all gang up on Adobe just because they're, well, just as bad as everyone else.
As for the two weeks, it sounds like you are saying that the appropriate response to being told that you have to stand in line a day to buy bread is to shrug your shoulders since you're already standing in line a day to buy milk.
I think there are too many developers out there in large and small companies that don't understand they power they wield or the responsibility they have.
I'm not a big fan of Flash. It had it's day. It wants to be everywhere, but it doesn't have the track record to be safe everywhere. I recently switched to Mac and have 3 (and only 3) crashes... all in Safari and all due to Flash.
I'm all for a company making a great product and making it prolific. I just want that company to have the integrity and follow through to make it right. After all, when an exploit takes over my machine who's out the time and money?
Yeah, some Youtube videos don't work... but you can get those videos elsewhere.
(FWIW, I did do a project for a client once which involved extracting data via the Analytics API. It was very easy to do, and all the metrics were there, so it seems possible to make your own chart without requiring Flash. Hell, there is even an in-browser Javascript Analytics API and many in-browser Javascript charting libraries... so you could probably even do this in the form of a bookmarklet or user script!)
Thanks for the info. I knew of their API but haven't used it yet.
Cannot cite IE (too obvious), or Reader (also Adobe).
Google: http://seclists.org/webappsec/2006/q1/66 (6+ months)
I'm sure you can find more of them by searching for them (as I just did).
http://www.math.northwestern.edu/~hoyois/safariextensions/cl...
That and someone notified them it exists.
Were it only a vulnerability they could deny knowing, they would keep silent about it.
I beleive we can soon expect Reader exploits too.
Synergy!
YouTube: http://userscripts.org/scripts/show/62634 Vimeo: http://userscripts.org/scripts/show/56677
Neither of these scripts requires a third-party site.
http://www.google.com/support/forum/p/Chrome/thread?tid=1095...
Just thinking about it makes my blood pressure rise.
(Yes, I know I can go back and uninstall the download manager, but now there are 2 of them - one specifically for IE/ActiveX and the one for Firefox that they recently created).
The only thing closed are codecs (many of which are licensed from other companies and can't be open sourced), DRM stuff and platform level code that glues everything together. On the other hand, there are open source versions of swf players that Adobe actively promote.
Unfortunately, community involvement (developers and early testers) in all these projects have been low. My understanding is that people within Adobe (and there are many who like Open Source) have no evidence that open sourcing more stuff is any better for the player, since the community hardly gets involved.
Adobe did launch a 64-bit Linux flash player on Labs. Most 64 bit users never used it, sticking with the nspluginwrapper method instead.
I'm sure more community involvement with existing open source projects at Adobe would pave the way for opening up of more stuff.
Or, alternatively, is there some cross-domain element that makes this a threat even if I'm just seeing Flash-based ads on CNN.com?
BTW, anyone else think serving flash-based banner ads from untrusted third parties given its track record is well, the height of irresponsability?
Flashblock is a simple and effective way to manage Flash.
> A "zero day" attack occurs on or before the first or "zeroth" day of developer awareness
Oh no! What if it gets my iPhone! Oh, wait...