Firefox: https://addons.mozilla.org/en-US/firefox/addon/433/
Chrome: https://chrome.google.com/extensions/detail/cdngiadmnkhgemki...
Firefox: https://addons.mozilla.org/en-US/firefox/addon/433/
Chrome: https://chrome.google.com/extensions/detail/cdngiadmnkhgemki...
Killing everything is much better.
https://chrome.google.com/extensions/detail/gofhjkjmkpinhpoi...
Is that good enough proof that the SWF is not put into memory?
Also, the FlashBlockBlock page here does not load when I have the extension enabled: https://woofle.net/flashblockblock/
ClickToFlash for native Webkit views on OS X actually blocks Flash for real — it's a native Webkit plugin that registers for Flash's primary mimetype and preempts it. When you selectively enable a flash embed, it replaces itself with Adobe's NPAPI plugin.
http://www.theregister.co.uk/2010/09/13/adobe_flash_0day_vul...
It is easy to turn off Flash in the Firefox plugins, and running the Better Privacy extension which kills the Flash hidden cookies normal cookie management doesn't touch. (One stalks you keeping track of every site you've visited with Flash) Better Privacy isn't yet compatible with the Firefox 4 beta but is fine with 3.x
NoScript is still a good idea for many reasons.
The malware is worse this year than last... http://www.gdatasoftware.co.uk/about-g-data/press-centre/new...
[EDIT: Note: I don't know how safe the link in this article is.] http://seclists.org/fulldisclosure/2008/Jul/444
The payload is harmless but silly.