Latest Comments
"when i login to face book it tells me i am cookies enabled what does this mean"
by celeste | Nov 21, 2008 5:15 PM
 
"Hi this is the mail I received Brett Karpman show details Nov 17 (3 days ago) Reply Atten..."
by Rodney Churchyard | Nov 20, 2008 6:13 PM
 
"security through obscurity...shows how detached HIPAA is from reality."
by priceOfFishInChina | Nov 20, 2008 1:19 PM
 
"Umm. no. The 6.5 product is mounting the offline VM image and performing a scan for patch ..."
by eric | Nov 20, 2008 8:15 AM
 
"it's great i tried it"
by divyacharan | Nov 20, 2008 12:24 AM

Exploits target new Adobe Flash bug

  • Email a Friend
  • Print Page
By Dan Kaplan
May 28, 2008 10:01 AM
Tags: Exploits | target | new | Adobe | Flash | bug
Oliver Friedrichs, director of Symantec Security Response, told SCMagazineUS.com on Tuesday that some 20,000 web pages were compromised via SQL injection to redirect visitors to one of three China-based domains serving up exploit code.

The threat is new, so researchers have yet been unable to determine how victims are arriving at the redirects or what the payload entails, Friedrichs said. But, it appears, once they reach one of the infected web pages, no user interaction is required for exploitation.

"It's as bad as you can get," he said of the drive-by-download technique.

According to the SANS Internet Storm Center, which broke news of the incident, the vulnerability affects version 9.0.124.0 and earlier installments.

An Adobe representative said the company was investigating.

"We are aware of today's report of a Flash Player exploit in the wild," Sandy Lo, an Adobe spokeswoman, told SCMagazineUS.com in an email. "We are working with Symantec to investigate the potential SWF [the Flash file format] vulnerability and will have an update once we get more information."

Friedrichs said Flash Player is a built-in component to most web browsers.

"It's (Flash) really inherent to many websites today," he said.

In lieu of a fix, corporate IT administrators should consider disabling Flash by setting the kill-bit on the application, or uninstalling Flash, Friedrichs said. In additions, users should be discouraged from visiting untrusted sites.

Turning off Flash will make the web a less desirable place to visit, - for example, users will be unable to view YouTube videos - but it will make it more secure, he said.

"Do you want to become infected or do you want to protect your environment?" Friedrichs said.

Last month, Adobe issued a new version of Flash to close seven vulnerabilities that, if exploited, could have permitted cross-site scripting attacks or system takeover.

See original article on scmagazineus.com

Secure Computing Magazine

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
 
Vulnerabilities & Exploits Whitepapers