Sunday, December 23rd 2007
Flash Vulnerabilities Affect Thousands of Sites
Researchers from Google have documented serious vulnerabilities in Adobe Flash content which leave tens of thousands of websites susceptible to attacks that steal the personal details of visitors. The security bugs reside in Flash applets, the ubiquitous building blocks for movies and graphics that animate sites across the web. Also known as SWF files, they are vulnerable to attacks in which malicious strings are injected into the legitimate code through a technique known as cross-site scripting, or XSS. Currently there are no patches for the vulnerabilities, which are found in sites operated by financial institutions, government agencies and other organizations. "Lots of people are vulnerable, and right now there are no protections available other than to remove those SWFs and wait for the authoring tools and/or Flash player to be updated," says Alex Stamos, an author of the Hacking Exposed Web 2.0 book. "In the mean time, people will have to think: 'What kind of flash am I using on my site,' and manually test for vulnerabilities."
Source:
The Register
5 Comments on Flash Vulnerabilities Affect Thousands of Sites
but if it is, i'd recommend Flashblock for Firefox Users.
Works a treat.
addons.mozilla.org/en-US/firefox/addon/722