Psyke
14 years ago
latest #15
Psyke
14 years ago
basically you can upload a valid file to a website with an appended or prepended malicious file and then have it run when another user ...
Madame Maracas
14 years ago
YIKES!
Psyke
14 years ago
looks at it. Forexample you can look at an uploaded zip file and the flash program will also run
立即下載
Clara 🦄 says
14 years ago
My AV covers flash files :-D It's actually blocked sites on-the-fly.
Psyke
14 years ago
It is not just a flash problem flash is just one example of appending code
Psyke
14 years ago
GMail Flash Exploit
Psyke
14 years ago
The Gmail hack is very difficult and wont affect most people but gives an idea of how risky this all is
Psyke
14 years ago
Someone could perhaps append something the avatar pic in here
Clara 🦄 says
14 years ago
And then there are businesses and institutions that disallow end users installing things, so Flash is perpetually out of date.
Psyke
14 years ago
its all one big mess. If they dont allow updates they should auto update!
Psyke
14 years ago
We did some social hacking at work and can update our boxes now :-)
Clara 🦄 says
14 years ago
Can't auto-update when each version has to go through an approval process. Yay Bureaucracy!
Psyke
14 years ago
Firefox users should get NoScript and IE users should get ToggleFlash to control what Flash runs.
Psyke
14 years ago
I'd also suggest blocking ads as a uploaded graphic might have appended flash or something else and your browser might run it
Clara 🦄 says
14 years ago
Oh, gods. Corrupted banner ads are a nightmare >_<
back to top