SHARE
Facebook X Pinterest WhatsApp

Black Hat : Blinded by Flash security

Feb 19, 2009
blackhat.jpg

From the

flash isn’t always secure’

files:

WASHINGTON DC — Adobe’s Flash format is everywhere on the web, but be warned : Flash files could potentially be carriers of security exploits.

At least that’s the allegation of HP security researcher  Prajakta Jagdale who today talked about Flash security in a session at Black Hat DC. There are a number of different types of vulnerabilites that could affect Flash including information disclosure and cross site scripting issues.  Though ultimately Jagdale argued that it comes down to proper coding and validation to secure Flash.

On the low hanging fruit side, Jagdale noted that some Flash developers hardcode username and password information into files.  A simple Google search with the search query  “Filetype:swf inurl:login  ” was used by Jagdale to show how easy it is to identify vulnerable flash sites.

Additionally she noted that Flash allows for text boxes that could have HTML values – as such HTML injection could lead to exploit.

“You always need to validate inputs,” Jagdale said.

Again she did a basic Google search to try and find potentially vulnerable Flash sites for HTML injection. She used the query “filetype:swf inurl:clickTag”. When she did the search she claimed that she got at least 200 results of which in her analysis  120 were found to be vulnerable to XSS.

Jagdale advised that in addition to input validation developers should use SSL and should avoid storing sensitive information in the Flash application.

Recommended for you...

Facebook Becomes Meta, But Did It Move Too Soon?
Rob Enderle
Oct 29, 2021
Microsoft Gets Rid Of Passwords: I Can Almost Hear Angels Singing
Rob Enderle
Sep 17, 2021
Why AMD Has Been So Successful: Mark Papermaster
Rob Enderle
Sep 9, 2021
Another Crazy Week in Cybersecurity
Paul Shread
Jul 2, 2021
Internet News Logo

InternetNews is a source of industry news and intelligence for IT professionals from all branches of the technology world. InternetNews focuses on helping professionals grow their knowledge base and authority in their field with the top news and trends in Software, IT Management, Networking & Communications, and Small Business.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.