Massive Facebook and MySpace Flash Vulnerability Exposes User Data
techcrunch.com
techcrunch.com
http://services.digg.com/crossdomain.xml
<allow-access-from domain="* "/>
http://api.search.live.net/crossdomain.xml
<allow-http-request-headers-from domain="* " headers="* "/>
<allow-access-from domain="* "/>
http://webservices.amazon.com/crossdomain.xml
<allow-access-from domain="* "/>
http://s.ytimg.com/crossdomain.xml
<allow-access-from domain="* "/>
http://profile.ak.facebook.com/crossdomain.xml
<allow-access-from domain="* "/>
<site-control permitted-cross-domain-policies="master-only"/>
http://www.vimeo.com/crossdomain.xml
<allow-access-from domain="* "/>
https://api.ebay.com/crossdomain.xml
<allow-access-from domain="* "/>
In case of an API, it makes perfect sense to allow crossdomain flash access. After all, this is what an API is made for, allowing access for third party services.
It is only problematic if you don't have proper authentication, e.g. when a flash app can use the cookie of the user to authenticate.
If you want to provide access to an API, put the API on a separate subdomain. That's why api.flickr.com has an open crossdomain.xml file and flickr.com doesn't.
Adobe actually have a pretty good explanation of the security issues caused by an open crossdomain.xml file:
http://www.adobe.com/devnet/flashplayer/articles/cross_domai...
That's what I was referring to. OP listed domains which are probably used exclusively to provide an API, e.g. api.ebay.com, implying that the crossdomain files on these domains pose a security risk.
I was wondering if my comment is understandable, obviously it's not :) Thanks for the clarification!
tbh I just did a google for crossdomain ext:xml and pulled out the famous domains with * in the policy.
http://www.yvoschaap.com/index.php/weblog/facebook_myspace_a...
Wouldn't you use htaccess rules (or similar) to prevent the .xml file from being accessed except from domains who were to be allowed flash crossdomain access, belt and braces as it were?? Certainly you'd put it as a deny in robots.txt, no?
Its Facebook! Everything you put on a site like that is public, or can be and will be at some point. Its a public forum, as this one is, and any promises to the contrary have been clearly proven false on about a weekly basis.
http://code.google.com/p/doctype/wiki/ArticleFlashSecurityPo...
System.security.loadPolicyFile() is an ActionScript function in a Flash application that loads any URL, of any MIME type, and attempts to read the security policy in the HTTP response. If an attacker could upload and store an image, audio, RSS feed, or other file on a server that can later be retrieved, then he or she could place the Flash security policy in that file. For example, the following RSS feed is accepted as an open security policy...
Even worse, the file does not even have to be XML. The GIF image below places the Flash security policy in a GIF comment and is also accepted as an open security policy...
In fact, an attacker can embed the security policy within the data of any valid image, audio or other data file. This is easier to do so with uncompressed file formats, like BMP image files, but is possible in virtually any file format. The only limitations are that each byte before the </cross-domain-policy> tag must:
+ Be non-zero,
+ Have no unclosed XML tags (no stray <, 0x3c), and
+ Be 7-bit ASCII (bytes 0x01 to 0x7F)
[YC admins: My trailing "emphasis" asterisk was remaining visible until I placed (this) further text following it.]