If you write a simple Flash program that opens a socket to a remote server, you can embed that on a site and use it to identify certain people running through Tor or any other SOCKS/HTTP proxy. It will only catch people who have configured their proxy very poorly. This has been known for well over a decade and it just catches the low-hanging fruit; it's really not an innovative tactic, you can find it on all sorts of sites. If you use the Tor Browser Bundle, it will route Flash through Tor so you're immune.
However, during Operation Torpedo, the FBI deployed an "implant" on Freedom Hosting's servers which was an exploit for CVE-2013-1690, a vulnerability in Firefox. Wasn't a 0-day, but a lot of people using TBB had not patched yet. This was just some Javascript which executed a small bit of Windows shellcode, sending each victim's IP address, MAC address, and a serial number to an FBI-controlled server. The only way to be safe from this was with an updated Firefox version, and/or running NoScript.