Readers: 8 | Updated: 04-11

Adobe Fixes Seven Flaws in its Flash Player [That Damn PC]

Translate Into:

Adobe has recently upgraded its own Flash player to fix seven vulnerabilities in the graphics and video software that is widely used for interactive Web pages and banner advertisements. Adobe classifies the patches as “critical” and advises people upgrade to the latest version, 9.0.124.0. All of the vulnerabilities could allow a hacker to execute code on a machine.

Exploiting vulnerabilities in Flash software has become an increasingly popular vector for hackers to compromise machines for two reasons. Most Web browsers have the Flash Player installed, and malicious banner advertisements — which can achieve wide distribution on Web sites pulling ads from a network — can take advantage of those vulnerabilities.

“These vulnerabilities could be accessed through content delivered from a remote location via the user’s web browser, e-mail client, or other applications that include or reference the Flash Player,” Adobe wrote in its advisory.

If a malicious banner advertisement is widely distributed, a hacker has the potential to take control of many PCs. Lately, these “malvertisements” have been popping up everywhere, wrote Sandi Hardmeier, a Microsoft Most Valued Professional and security blogger.

On Sunday, Hardmeier wrote that she observed a fake FedEx banner ad that causes a user to be redirected to a Web site selling dodgy security software.

On Tuesday, security vendor Websense blogged about a malicious banner ad on the Web site of USA Today, a national U.S. newspaper. Websense wrote that if a user simply viewed the malicious ad, the person’s browser window is immediately minimized, and a warning appears saying the computer is infected with malware, according to a description of the attack. Even if the user hits “cancel,” the browser is redirected to another Web site selling spyware, which tries to download code to the PC.

In January, Adobe and other software vendors fixed some of their Flash development tools to stop hackers from creating malicious Shockwave Flash (.swf) files that enabled cross-site scripting attacks. That style of attack makes a browser execute malicious code via security weaknesses in a Web site.

At least 10,000 buggy Web sites were still serving up buggy Flash files around mid-March, as developers worked to fix the problem.

The latest fixes focus solely on the Flash Player. One fix adds a feature Adobe calls a “cross-domain policy check.” The Flash Player uses policy files, which allow it to use content from other domains. The feature allows for more richer capabilities in the player, wrote Deneb Meketa, a Flash engineer for Adobe, on the company’s developer site.

But hackers can also build a policy file. If the policy file is accepted by the server, the hacker can then write a “.swf” file and load other data from outside the particular server’s domain, which could lead to a security problem.

Source



From The Blogs

Internet Observation

04-29
一封致Flash的情书
最最亲爱的Flash:      我发现就去年一年中,人们还是对你这么的不友善,说你没用,说你讨厌,说你在这个以内容为主的网络上就是个祸害。我也知道,有些暴徒仍旧在不断的败坏你的名声,他们侮辱你,用各... 查看全文

Wake Up Later: Freelance + Passive Income

04-11
A Love Letter to Flash
Dearest Flash,It's come to my attention that even in the past year, people have continued to be unkind to you, calling you useless, annoying, and the bane of a content-driven internet. I've heard that... 查看全文

Product Reviews Net

03-28
Japan gets seven new Mickey Mouse-inspired MPlayers: Do you like?
The Mplayer was first seen way back in June 2007, well now iRiver have just introduced seven new variations of the Mickey Mouse-inspired MPlayer with matching a speaker.Judging on the looks of these M... 查看全文

iTech News Net

04-20
GamePark GP2X F-200 Gaming Handheld Reviewed
ArsTechnica has done a review on the GamePark GP2X F-200 portable gaming device. The GamePark GP2X F-200 is powered by an ARM920T processor and ARM940T video processor, 64MB Flash memory. It has a 320... 查看全文

OhGizmo!

04-18
7-Inch LCD Monitor Tries To Make Your Wii Portable
By Andrew LiszewskiThe Nintendo Wii just doesn’t come across as a highly portable gaming system to me. I think it’s mostly because the majority of the games require you to be some distance from the sc... 查看全文

Coolbuzz

04-15
The world’s most suspicious looking spy cam with clock and MP4 player
Asmita:Common sense would generally dictate that when you want to catch someone with a spy cam, you do it in the most inconspicuous manner possible. Unfortunately, the makers of this Racing Rim Camera... 查看全文

Coolbuzz

04-16
Pebble MP3 player is more of a Pendant
MP3 players were as cool as the Pebble MP3 player from designer Smith Newman they would have been around every neck by now. They truly could have been for this MP3 player is more like a pedant than a ... 查看全文

Culture, Geography, Science, Tourism

07-22
Flash about Stadiums in Beijing for Olympic Games
One of page of New York Times (newspaper) showed new buildings in Beijing including two big Olympic stadiums, whcih are Water Cube (National Aquatics Center), Bird's Nest (main Olympic stadium), Beiji... 查看全文

Coolbuzz

02-27
Ugly Lego-themed MP3 player
Asmita:I bet the idea looked like an instant bestseller on paper but in real life, this Lego-style MP3 player not only sucks design wise, but the fact that it features no internal memory, it fails jus... 查看全文

Coolbuzz

02-27
Cola Shaped OLED MP3 Player from Neux
Asmita:Cola fans all across China have just been treated to a brand new Cola can-shaped MP3 player from Neux which features a cool 2 color OLED screen and supports a ton of stunning functions like dig... 查看全文
More Articles
Elanso is a professional online platform which provides translation service for corporate or individule clients, opportunities for translation practice and translation jobs, and translation tool/software-download. Our online translators provide about 186 languages' translation service, including Japanese,Korean, French, German, Spanish, etc, among which, 20,000 are English translators. And some big translation service companies in Shanghai, Beijing, Nanjing also registered here.