Flash 0-day exploit
lists.immunityinc.com
lists.immunityinc.com
[1] http://support.google.com/chrome/bin/answer.py?hl=en-GB&...
Immunity makes the framework all these exploit packs plug into and acts as the primary sales channel for them. They do a pretty good job of keeping the undesirables out, but like any other desirable software product copies do have a tendency to grow legs and follow employees home.
It seems hard to believe that private 0-days are legitimate pentesting apparatus - what are you testing in this case, whether your enterprise runs software that someone might find a bug in in the future?
As far as I understand it canvas/Immunity is firmly in the offensive security market anyway, aren't they actively part of the scene that derides "killing bugs" aka reporting security bugs to software vendors (for any price)?
I'm sure this bug hasn't been reported to Adobe, all they'd be doing is closing their marketing window.
Did Adobe just ignore them?
How does the 11.2 beta fair against the exploit?
http://labs.adobe.com/technologies/flashplatformruntimes/fla...
I had a surprising number of random players installed too. e.g. Silverlight - requiring a critical update; amongst other plugins that I never even use any more.
I'm not sure it'll make a difference, but maybe it could.
http://lcamtuf.blogspot.com/2011/03/warning-object-and-embed...