Two more Flash 0-days emerge in Hacking Team leak
theregister.co.uk
theregister.co.uk
This is important because Microsoft seems to use a lot of Flash advertisements without checking them (I've had plenty of "MICROSOFT VERIFIED DRIVER FIXING" ads come up inside of Skype, so I'm sure some zero day could slip though their ad system)
I don't understand what they are thinking - it used to be such a progressive company.
I don't know about US Government, but many Governments and sensitive organisations are still using VMware, and this isn't likely to change.
I lul'd.
If you're running an update to date flash, that means you're probably running it in a sandbox and probably have silent auto updates turned on. That's good enough for most people.
If you're the kind of person that's going to get specifically targeted, then you should not only reconsider running flash on your computer, but any other program written in an unsafe language.
Or, you know, segregate your data.
I certainly HOPE most software I use can do better than this: http://www.cvedetails.com/vulnerability-list/vendor_id-53/pr...
To be certain, Flash gets a lot of attention because of its install base - but it's been a never-ending FOUNTAIN of RCE bugs for much of the last decade.
it's not awesome
month rows 10 7
2015-07 35 28 29
2015-06 14 7 7
2015-05 17 10 10
2015-04 22 19 19
2015-03 11 7 9
2015-02 19 19 19
2015-01 12 9 11
2014-12 6 5 5
2014-11 19 16 18
2014-10 3 3 3
2014-09 12 11 12
2014-08 8 7 7
2014-07 3 0 2
2014-06 6 1 3
2014-05 5 0 5
2014-04 4 1 2
2014-03 4 2 2
2014-02 4 3 4
2014-01 2 2 2
[...]
2015 has not been kind to them, but it's been a continuous trickle of remote severity 10s every month for a year and a halftruncated because it took too much space; full results: https://gist.github.com/anonymous/763e28612b74d3a1817a
NB: only months with at least one cve event show up, but given adobe's focus on security, it wasn't really necessary to fill in months with 0 events to get the point across
download each screen full of results from the cve site into a single directory and run this script: https://gist.github.com/anonymous/990bfe126d273ef84134
"It is time for Adobe to announce the end-of-life date for Flash and to ask the browsers to set killbits on the same day. — Alex Stamos (@alexstamos) July 12, 2015"
Flash has been insecure since originally launched.
Compare FF, Safari, IE, Chrome. Same number of bugs per yet but Chrome has 10x less code execution bugs (ie, 10x less likely for your machine to be owned by unknown bugs)
Flash runs in a low-priv environment is nearly every major browser, includes application-specific exploit mitigations, and it silently auto-updates, just like Chrome. It's all a matter of the Flash install base: it's in 90%+ of browsers and it's running the same-ish codebase in all of them, making it a relatively stable platform to develop exploits for. That's it! It's more a factor of market share and not "security."
Every document reader, HTML renderer, JavaScript engine, browser, media player, etc that you use is the same -- a house of cards built on poor memory management :-/.
> Chrome pushes out a dozen or more fixes
> for remotely exploitable vulnerabilities
> every 2 weeks.
That equates to 288 remotely exploitable vulnerabilities in Chrome per year.Here is a chart from the same source with a timeline of sorts: http://www.cvedetails.com/product/15031/Google-Chrome.html?v...
Your statement about Chrome is clearly way off, and that's what your parent was addressing. He never said Chrome was bug-free. And he was right to say that Chrome is way ahead of the other browsers (according to these stats, at least).
Edit: those stats show Chrome is better in terms of CVE severity, not number of annual CVEs.
Shit, this is the most accurate description of modern software that I've seen so far.
On Windows, you get a pop-up to update manually, which just sends you to their website so you need to download and run the installer by yourself.
If you don't update manually, Flash will wait 45 days before triggering an automatic update. I never waited that long, so I don't know whether it's "silent" or not.
As for consequences, the best thing most of us could do is disable Flash from the browser. I’ve done it since YouTube defaulted to HTML5 video and never looked back since.
Just look at the news for the past years and there's only 1 conclusion: uninstall Flash or accept increased risk of catching a virus.
A lot of people seemed to be surprised this is the case but tell me what single live streaming protocol is supported across all browsers without a plugin?
With Flash you can stream HLS (HTTP Live Streaming) to a Flash player in full browsers while just directly loading the same HLS playlist in mobile browsers via native players (iOS / Android).
This means you can deliver live streaming over the same audio/video codec (H.264/AAC) and over the same protocol (HLS). This vastly simplifies your streaming infrastructure and removes the need for transcoding on the server, unless you just want to create different qualities for adaptive bitrate streaming.
It would be nice if "desktop" browsers all supported HLS and H.264/AAC natively, that would be a real Flash killer.
- Plain old HTTP WebM stream. Only one resolution, but it works. - MPEG-DASH - very similar to HLS, but implementable in Javascript via MSE APIs in browsers today. - WebRTC - low latency streaming, in some cases it might make sense to use this over MPEG-DASH even for one-to-many streaming cases, like interactive lectures and the like.
Unfortunately several browsers lag behind in implementing the required APIs, so this does not solve all problems yet. But the problem isn't creating any new protocols, it's just getting adoption.
As for H.264, it's mostly a solved problem with hardware decoders and OpenH264 (currently not used for <video> playback, but could be). AAC, however, costs more to license and is much more problematic, so there will always be some browser vendors that don't ship it.
That said, I truly wish these remaining use cases for Flash were unnecessary, I would not miss it at all.
Also, it used to be the case that Flash had better DRM controls on it, but I'm pretty sure that reason is no longer the case since Encrypted Media Extensions got rolled out.
However, that doesn't explain why Facebook's on-site video player uses Flash.
If uninstalling flash only causes you to miss out on ads, it makes uninstalling flash that much more attractive. Which makes the advertisers want to get off flash that much sooner.
It needs probably just one or two more use cases to disappear (Facebook video is one of them), and its final death will be quite quick.
Honestly, one of the biggest reasons to run an ad blocker is the significantly reduced attack surface.
Not only that, but images flagged as "gif" also prompt me to install flash (amazing how oddly these new features get implemented!).
It seems to be the case in general for most sites that offer HTML5 alternatives that the Flash version is much more solid. Maybe using HTML5 video in these domains is inherently error-prone, maybe it isn't, but in practice it almost always gets screwed up.
Plus people still use flash games and sites like Newgrounds.
Among the various issues I've seen:
* Sometimes refuses to play anything, without showing any errors, requiring a reload of the page.
* Occasional poor performance.
* Audio/video desynchronization
* Scrubbing the video often causes it to get stuck, refusing to play, until I scrub it again
* Videos often take longer to start playing than with the flash player.
* Fullscreen is sometimes broken
* Switching from regular mode to "theater" mode sometimes leaves the video playing in its original size, anchored to the corner of the now-larger black area that it should be playing in.
I think it's gotten a little better recently (i.e. I see issues less often), but it's still far from great.
And before you ask, I've seen these issues in both Safari and Chrome.
As for the issues you're experiencing - are you sure you have GPU acceleration turned on?
I'm using Chrome and CPU usage is only 45-50% for perfect 1080p 60FPS playback.
Not on older (3y+) machines.
> make me think of some kind of adobe shills maybe
Delusions or paranoia may be?
Also 9 year old is quite a frac cry from your initial post of "(3y+) machines", 9 year old machine almost guaranteed has absolutely no support in hardware for modern codecs. So no wonder has strong limitations on resolution. Still flash working better than HTML5 players is still suspicious to me, I still believe with correct configuration reverse should be true, as flash is basically just another layer in between screen and bits on the net. Though possibly not applicable in all cases.
> Still flash working better than HTML5 players is still suspicious to me,
Do you write programs for life or what? It is not a problem with HTML5 players, it a problem the way they are written. Flash is an older product, with better support of legacy or underpowered products.
> I still believe with correct configuration reverse should be true
Yes, the correct configuration is "more powerful CPU".
For reference, I use chromium (not chrome) on Linux (which does not come with flash bundled).
And there's still a truckload of fun games available only in flash form, which makes flash relevant even if the number of new stuff coming out in it dwindles.
I'd say they're open to ditching Flash.
IRC for chat is absolutely new to me and would actually be quite nice..
Edit: proof: http://i.imgur.com/myfsoNv.png
The HTML5 solution is usually to run DASH via a JS demuxer utilizing MSE.
I actually just filed a complaint on their forums.
http://community.ubnt.com/t5/UniFi-Wireless/BUG-Adobe-Flash-...
For all I know they're doing Unifi 5 in pure flash. I wouldn't be surprised.
Unifi 4.x is still beta and I'm not sure if it still requires flash (Though for Ubnt stable means beta, beta means alpha, alpha is unlikely to even run.)
Last I checked AirControl did too (managing many AirOS devices)
I'm guessing that Facebook encodes video h264 which isn't natively supported in Firefox; rather it relies on support in the operating system. I'm not sure if Chrome on Linux supports h264, however since Chrome also includes its own Flash player I guess that Facebook may be using their own flash player anyway.
And chat trough their irc server.
[1]: https://krebsonsecurity.com/2015/07/adobe-to-patch-hacking-t...
"A spokesperson for Google confirmed that attackers could evade the Chrome sandbox by using the Flash exploit in tandem with another Windows vulnerability that appears to be unpatched at the moment."
Thanks.
Say you discover a very powerful attack on AES which allows you under many circumstances to recover the key:
1. do you have an ethical obligation to warn affected parties?
2. If you don't and instead secretly sell this decryption capability to governments and/or private actors, do you have an obligation to ensure that this capability isn't used illegally or unethically?
3. What due diligence is required to protect a vulnerability of this scale?
I just think we should be clear that exploit developers, brokers, and users don't actually create vulnerabilities; software companies do.
I also think people should give Adobe a little bit of a break --- not much of one, but a little. Adobe got monstrously successful off a codebase that largely predates the concept of software security. It's a nightmare problem for them, and they are working on it. They should work harder.
First, they were incompetent enough to not correctly develop their software.
Second, non-assholes would have a standing price-match policy for bugs. Adobe should give you 110% of the highest bid you get for any 0-day. They could have fixed these a long time ago if they'd paid the discoverer $45k (or $150k -- times three for exclusivity.) These companies are effectively outsourcing security testing and remediation of their software, then whinging that independent developers don't work for free.
I agree Adobe is at fault for producing insecure software.
Blame is not a limited resource, there is always extra blame to go around. If I am driving recklessly and my brakes fail due to a manufacturing error, both I and the car company are at fault for the accident. One can always, as HT has done, make a bad situation worse but behaving in a reckless and unethical matter.
>Adobe should give you 110% of the highest bid you get for any 0-day.
This! This so hard.
(For that matter, while reputation is certainly a thing, what stops a security researcher from selling the same 0-day to several different buyers, and then selling it to the company to fix? Do the typical contracts to sell 0-days involve continued payment based on the amount of time the bug remains unfixed?)
And if a security dev resells, who cares? The company still got the 0-day and still gets it fixed asap. It's far better than our current situation where these can persist for years.
People willing to pay 5 or 6-digit sums for a zero-day are likely... not nice. One wouldn't double-cross them willy-nilly. Multiple-sale to multiple third-parties scenarios are likely happening every day, but selling to developers could be considered an act of sabotage against all buyers, so there is no incentive really.
2. If one is the kind of person that thinks that the answer to 1 is no then probably the answer to 2 is no too (sorry if this sounds harsh).
3. Probably an effort proportional to the competitive advantage it gives to you.
At worst, such a devastating bug has a decent chance of harboring its own RCE which has yet to be discovered or disclosed; at best, it's one of the most extreme local DOS attacks that a webpage could possibly launch against a client.
Just because it's much more trendy to bash Adobe than it is to bash Firefox doesn't mean that Firefox's problems are nonexistent.
Firefox RCE found on January 20, 2015: https://community.rapid7.com/community/metasploit/blog/2015/...
Firefox RCE found on February 25, 2015: https://msisac.cisecurity.org/advisories/2015/2015-018.cfm
Firefox RCE found on March 1, 2015: https://www.mozilla.org/en-US/security/advisories/mfsa2015-3...
Firefox RCE found on April 22, 2015: https://msisac.cisecurity.org/advisories/2015/2015-046.cfm
etc.
Pot calling the kettle black.
I have not once every missed having flash on my system. It's not just the case that the web is useable, it's that, with the single exception of the BBC, it doesn't seem to use it anywhere I visit.
Presumably they could implement a non-flash fallback for users but unfortunately they just haven't bothered.
I tried to cheat by modifying my User-Agent to pretend to be an iPad but had no luck...
I'm surprised that websites can do any kind of file path detection on a client...
That seems unlikely. Maybe HN users, but that's not really representative of web users overall
[citation needed]
http://www.cbsnews.com/news/adobe-abandons-flash-player-on-m...
http://www.telegraph.co.uk/technology/news/8879783/Adobe-aba...
Absolutely no new major content sites as of around 2014 or so support flash as an option - they are all starting with HTML5 and/or thick local clients.
Flash needs to be EOL'd, and the sooner the better for the security of the Internet.
1. Get the video id. Retrieve HTML containing youtube /watch?v= urls or other urls that contain the video id. Extract the urls from the HTML or other markup garbage.
2. Retrieve the video. Feed the /watch?v= url to a script that does some "find and replace" on the absurdly long googlevideo urls. Below I have given an example of such a script. Complaints welcome. It takes a /watch?v= url on stdin and retrieves the video in the format specified on the command line.
3. Play the video. ffmpeg libraries, mplayer, etc.
Whatever it is Flash does in the process of watching youtube videos (I am quite sure it is not step 3), I do not need it.
Thus even if by not using Flash or a complex "modern" web browser to watch youtube videos somehow were to reduce my exposure to vulnerabilities that routinely occur in such software, I would not care. Because the reason I do not use Flash is.... because I do not need it.
# proof of concept: video retrieval
# requirements:
# sh, sed, tr, openssl, ftp
# Adobe Flash not required
# HTML5 not required
# Python not required
# Awk not required
# web browser not required
curl=ftp
file=1.mp4 # default outfile
url=www.youtube.com # example
# itag #s are on the wikipedia page for youtube
f061(){
sed '
s,%3D,=,g;
s,%3A,:,g;
s,%2F,/,g;
s,%3F,?,g;
s/
//g;
'
} f060(){
sed -e '
s/&itag=5//;t1
s/&itag=1[78]//;t1
s/&itag=22//;t1
s/&itag=3[4-8]//;t1
s/&itag=4[3-6]//;t1
s/&itag=1[346][0-9]//;t1
' -e :1
}
f062(){
sed '
s,http,\
&,g'
}
f063(){
sed '
/%3A%2F/!d;
/videoplayback/!d'
}
f064(){
sed '
s,%26,\
,g;
s,&,\
,g;
'
}
f065(){
sed 's/&https/\
\
https/g;'
}
f066(){
sed 's/\\u0026.*//'
}
f067(){
sed '/itag='"${1-.}"'/!d;'
}
f068(){
sed 's/%25/%/g'
}
f069(){
tr '\012' '&'
}
f070(){
sed 's/&$//'; echo
}
f071(){
local a061 a062 a063;
while read a; do
case $a in
https://*)a061=${a#https://*/} ;;
http://*)a061=${a#http://*/} ;;
*)a061=${a#*/} ;;
esac;
a062=${a#*://};
a063=${a062%%/*};
printf "%b" "${1-GET} /${a061} HTTP/1.0\r\n"
printf "Host: ${a063}\r\n";
printf "User-Agent: GoogleAnalytics 1.5.1\r\n";
printf "Connection: Close\r\n";
printf "\r\n";
done;
}
f072(){
openssl s_client -ign_eof -connect $1:${2-443} -verify 9
}
case $# in
[12])
{
f071 \
|f072 $url \
|f062 \
|f063 \
|f061 \
|f060 \
|f064 \
|f068 \
|f069 \
|f070
} \
|f061 \
|f065 \
|f066 \
|f067 $1 \
|{
read a;
exec $curl -4o ${2-$file} $a ;
}
;;
*)
exec echo \
"usage: $0 itagno [outfile]
outfile: $file"
esachttps://www.indiegogo.com/projects/real-time-video-frame-rat...
I simply use mplayer and javascript oneliner extracting direct mp4 link from YouTubeCenter plugin = streaming video in mplayer without downloading.
A: "holy crap that is convuluted"
I do not use Python nor a Javascript-enabled web browser to download video.
Both are big, convoluted, slow(!) and unnecessary.
But I do agree with using mplayer for playback.
Firefox - "no", it doesn't have Flash built-in but uses Flash installed in the operating system. However, Flash installed separately for example in Windows/OS X also updates itself.
However, you are screwed either way: always running the latest Flash player version which is known to be constantly full of security bugs, just like in the past 3 years... :)
Also not everyone knows how bad Flash is for their security, only few geeks care about reading cve-s. So until it goes to mainstream media not enough people will care.
Flash: 382 code exploit vulnerabilities.
Looks like Flash has a way to go.
The last release I've found is 11.2, which seems to be years old and the last ever.
So I guess Linux users are immute to this new zero-day?
And I wouldn't even sort of consider hiring or even working with anyone that thinks work experience in a language makes them a liability.
We need public disclosure of the code check-in that created the bug, with names. People need to be fired for this.
Firing people for software bugs is the stupidest thing I've heard in a while. Everyone writes horrific software flaws. Everyone. The best of the best programmers just write less of them. Firing people for bugs is a job perk that will only motivate any good developers to find a less stupid employer as soon as possible.
In a 64-bit environment, at least for development purposes, why can't every single malloc() cause an allocation from new memory page(s)? Then free() removes the page(s) from accessible virtual memory.
Too much overhead for production, but it would sure catch a lot of use-after-free bugs during development. Is nobody doing something like that, or is that part of what you consider "the easiest flaws"?
This comment was heavily voted down a day or so ago (not by me, I voted it up). But just now I'm reading about yet another zero-day, this time against Java.
So the question is, when are we going to get disgusted, sick and tired of all this sloppy code? When will "heads will roll for this" revert to being a meaningful punishment instead of just a historic cliche?
Enough is enough! If there are no consequences there will be no improvement.