online security computer security vulnerabilities information security
pix Xatrix Security
 
pix
Main
Security
Downloads
Forum
Free e-books
Security
Advisories
Vulnerabilities
IT News
Virus Central
Services
Advertise
Newsletter
Shop
Search
Wap-PDA/mobile
Other
Affiliates
Contact
RSS feeds
Computer, Online and Information Security News
  Show printable version  Show printable version  |   Send this article to a friend  Send this article to a friend  

'Flash!' Aaargghh... here to hack every one of us

Posted by: Nikola Strahija on December 18, 2002

A new threat is being posed to computer security, with a warning that Macromedia Flash
files can be adjusted to compromise a PC or Mac as long as its user views the file in a
web browser - or even an email.
A flaw found in Macromedia's animation software leaves web surfers vulnerable to attack when they visit an internet site or, even open an email according to security firm eEye Digital Security.

An attacker could create a hand-edited Macromedia Flash, or SWF, file that can compromise a PC or Macintosh if its user views the file with the Shockwave Flash Player plug-in for Internet Explorer, Netscape or other browsers.

The flaw's danger is compounded by the fact that Flash is so widespread and the software doesn't have a built-in upgrade system, said Marc Maiffret, chief hacking officer for eEye.

Maiffret said: "Almost every user is going to have Flash, so they can become compromised. Unless the user is smart enough to get the latest version of Flash, then they are going to be vulnerable."

More than 90 per cent of web browsers have the Flash software installed, according to Macromedia. While nearly 53 per cent of web surfers use the latest version, Shockwave Flash Player 6, the number still falls well short of the total, underscoring the problem of convincing people to upgrade.

Macromedia warned its developers of the problem last Friday, said Troy Evans, product manager for the Flash Player. He added that the only way to notify software users that they need to get the latest software is by modifying Flash animations to require the newest versions, so the company is focused on getting developers to do more updates.

Although getting users to upgrade is a challenge, Evans said, the company has been fairly successful. "We have three million downloads per day, so the players that are out there are getting updated," he said.

The flaw affects the Flash plug-in for browsers on Windows, Unix, Linux and Mac.

By editing the header of a Flash file, an attacker can cause the file to execute commands and compromise the computer system. In some cases, it's possible to cause HTML email to perform a similar attack, eEye said in its advisory.

The danger of flaws that require a victim to go to a specific website tends to be offset by the fact that a website can be shut down fairly quickly. For that reason, a virus that attempts to use a vulnerability in Flash or another web technology usually has a limited effect.

In many respects, the flaw resembles another vulnerability that eEye found in the Flash Player in August. That flaw also allowed an attacker to modify the header of an SWF file and cause the Flash Player to compromise the machine on which the software was running.

Maiffret said: "The outcome of the attack is basically identical to the one back in August. It just goes to show that the average software company is in great need of real-world security" checking.

- article available from http://www.silicon.com -
Xatrix Security
Show printable version  Show printable version  |   Send this article to a friend  Send this article to a friend  
Latest information, online and computer Security News
Hack Attack: Get Windows XP SP3 Throu...  (Nov 29, 2007)
TPB files charges against media compa...  (Sep 22, 2007)
Storm worm: again.  (Aug 7, 2007)
Onslaught on .ORGs  (Feb 7, 2007)
OpenOffice.org insecure  (Aug 12, 2006)
Latest Vendor Advisories
Firefox vulnerabilities
Ruby safe-level vulnerability
Seamonkey critical security vulnerabilities
Drupal several remote vulnerabilities
Kernel local race condition
  Our Services     Information     Our Online Shop     Community Forum Topics
  Free weekly Newsletter
Advertise on Xatrix
Monthly News Archive
Community Forum
  Impressum/about
Contributing
Newsletter archive
Latest bugs
  Top sellers
New Items
Books
Software
  RMC3IENGINE - VMWar...
VMWare CC3 Server -...
C2k Commissioning CDs
On Sale New Apple i...
Our Privacy Policy | Contact Us
Powered by TiP / Rapid IT | HITB.org
All content on this website is property of Xatrix Security if not noted otherwise.
Copyright 2000 - 2010 Xatrix Security
Get news on your PDA or mobile phone Latest events Search our extensive database Get the latest books and software Download the latest tools Contact Us Advertise on Xatrix Security