<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>gHacks technology news &#187; flash vulnerability</title>
	<atom:link href="http://www.ghacks.net/tag/flash-vulnerability/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ghacks.net</link>
	<description>A technology blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description>
	<lastBuildDate>Wed, 25 Nov 2009 11:56:41 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Adobe Flash Player Clickjacking Vulnerability</title>
		<link>http://www.ghacks.net/2008/10/08/adobe-flash-player-clickjacking-vulnerability/</link>
		<comments>http://www.ghacks.net/2008/10/08/adobe-flash-player-clickjacking-vulnerability/#comments</comments>
		<pubDate>Wed, 08 Oct 2008 12:18:22 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[adobe flash]]></category>
		<category><![CDATA[clickjacking]]></category>
		<category><![CDATA[flash clickjacking]]></category>
		<category><![CDATA[flash player]]></category>
		<category><![CDATA[flash vulnerability]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=7493</guid>
		<description><![CDATA[Dante send me a link to an interesting article that described the latest Adobe Flash Player vulnerability. Adobe published a security advisory yesterday that described a clickjacking vulnerability. In short: An attacker could lure the unsuspecting user into clicking on a link that would give the attacker access to the computer&#8217;s microphone and webcam without [...]]]></description>
			<content:encoded><![CDATA[<p>Dante send me a <a href="http://www.techworld.com/security/news/index.cfm?newsID=105430&#038;pagtype=all">link</a> to an interesting article that described the latest Adobe Flash Player vulnerability. Adobe published a security advisory yesterday that described a clickjacking vulnerability. In short: An attacker could lure the unsuspecting user into clicking on a link that would give the attacker access to the computer&#8217;s microphone and webcam without the user&#8217;s knowledge.</p>
<p>Adobe published a temporary workaround to protect the computer system against this form of attack that users should apply until the release of a patch that would fix the critical issue.</p>
<p>To apply the workaround users should visit the Flash Player&#8217;s Settings Manager by following the <a href="http://www.adobe.com/support/documentation/en/flashplayer/help/settings_manager02.html">link</a>. There they should click on the Always Deny button which would prevent any website from accessing the microphone and webcam settings. </p>
<p><span id="more-7493"></span><img src="http://www.ghacks.net/wp-content/uploads/2008/10/adobe_flash_player_settings_manager.jpg" alt="adobe flash player settings manager" title="adobe flash player settings manager" width="425" height="286" class="alignnone size-medium wp-image-7494" /></p>
<p>The new setting has to be confirmed in the popup that appears automatically after clicking on the Always deny button. The patch is said to be available before the end of October.</p>

	Tags: <a href="http://www.ghacks.net/tag/adobe/" title="adobe" rel="tag">adobe</a>, <a href="http://www.ghacks.net/tag/adobe-flash/" title="adobe flash" rel="tag">adobe flash</a>, <a href="http://www.ghacks.net/tag/clickjacking/" title="clickjacking" rel="tag">clickjacking</a>, <a href="http://www.ghacks.net/tag/flash-clickjacking/" title="flash clickjacking" rel="tag">flash clickjacking</a>, <a href="http://www.ghacks.net/tag/flash-player/" title="flash player" rel="tag">flash player</a>, <a href="http://www.ghacks.net/tag/flash-vulnerability/" title="flash vulnerability" rel="tag">flash vulnerability</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2008/05/28/vulnerabilities-in-latest-flash-version/" title="Vulnerabilities in latest Flash version (May 28, 2008)">Vulnerabilities in latest Flash version</a> (4)</li>
	<li><a href="http://www.ghacks.net/2007/05/04/flash-cookies-explained/" title="Flash Cookies explained (May 4, 2007)">Flash Cookies explained</a> (63)</li>
	<li><a href="http://www.ghacks.net/2009/11/18/adobe-releases-flash-10-1-and-air-2-0-previews/" title="Adobe Releases Flash 10.1 and Air 2.0 Previews (November 18, 2009)">Adobe Releases Flash 10.1 and Air 2.0 Previews</a> (1)</li>
	<li><a href="http://www.ghacks.net/2009/07/24/adobe-reader-acrobat-and-flash-player-zero-day-vulnerability/" title="Adobe Reader, Acrobat and Flash Player Zero Day Vulnerability (July 24, 2009)">Adobe Reader, Acrobat and Flash Player Zero Day Vulnerability</a> (3)</li>
	<li><a href="http://www.ghacks.net/2009/06/25/adobe-fixes-critical-shockwave-vulnerability/" title="Adobe Fixes Critical Shockwave Vulnerability (June 25, 2009)">Adobe Fixes Critical Shockwave Vulnerability</a> (12)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2008/10/08/adobe-flash-player-clickjacking-vulnerability/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Vulnerabilities in latest Flash version</title>
		<link>http://www.ghacks.net/2008/05/28/vulnerabilities-in-latest-flash-version/</link>
		<comments>http://www.ghacks.net/2008/05/28/vulnerabilities-in-latest-flash-version/#comments</comments>
		<pubDate>Wed, 28 May 2008 17:44:12 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[The Web]]></category>
		<category><![CDATA[adobe flash]]></category>
		<category><![CDATA[flash]]></category>
		<category><![CDATA[flash vulnerability]]></category>
		<category><![CDATA[world-of-warcraft]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=4383</guid>
		<description><![CDATA[A recent vulnerability in the latest Adobe Flash version lead to a massive attack. More than 220000 pages on the Internet have been hacked most likely with an automated tool using a SQL injection attack. Those pages, some of well respected companies such as Nokia but also many non-profit organizations and town websites, redirect the [...]]]></description>
			<content:encoded><![CDATA[<p>A recent vulnerability in the latest Adobe Flash version lead to a massive attack. More than 220000 pages on the Internet have been hacked most likely with an automated tool using a SQL injection attack. Those pages, some of well respected companies such as Nokia but also many non-profit organizations and town websites, redirect the user to websites that host the exploits for the Flash vulnerability.</p>
<p>If the system meets the requirements the exploit is used to download and execute trojans that steal information and droppers that download additional trojans. Information that are stolen are for example World of Warcraft account information while the droppers download files that add the computer to a botnet. (according to <a href="http://blog.trendmicro.com/flash-bugs-exploited-in-latest-mass-compromise/">Trendmicro</a>)</p>
<p>Most antivirus companies have already updated their software to disable the possibility that this exploit can be used on the computer the software is running on. Your best bet if you do not use antivirus software is to either disable Flash for now or use an extension like NoScript to block Flash on every domain but trusted ones.</p>
<p><span id="more-4383"></span></p>

	Tags: <a href="http://www.ghacks.net/tag/adobe-flash/" title="adobe flash" rel="tag">adobe flash</a>, <a href="http://www.ghacks.net/tag/flash/" title="flash" rel="tag">flash</a>, <a href="http://www.ghacks.net/tag/flash-vulnerability/" title="flash vulnerability" rel="tag">flash vulnerability</a>, <a href="http://www.ghacks.net/tag/world-of-warcraft/" title="world-of-warcraft" rel="tag">world-of-warcraft</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2008/05/29/new-information-about-latest-flash-vulnerability/" title="New Information about latest Flash Vulnerability (May 29, 2008)">New Information about latest Flash Vulnerability</a> (1)</li>
	<li><a href="http://www.ghacks.net/2009/09/19/mozilla-flash-upgrade-statistics/" title="Mozilla Flash Upgrade Statistics (September 19, 2009)">Mozilla Flash Upgrade Statistics</a> (5)</li>
	<li><a href="http://www.ghacks.net/2009/09/04/mozilla-checks-flash-version-after-firefox-updates/" title="Mozilla Checks Flash Version After Firefox Updates (September 4, 2009)">Mozilla Checks Flash Version After Firefox Updates</a> (14)</li>
	<li><a href="http://www.ghacks.net/2009/03/27/adobe-flash-security-scan/" title="Adobe Flash Security Scan (March 27, 2009)">Adobe Flash Security Scan</a> (2)</li>
	<li><a href="http://www.ghacks.net/2008/10/08/adobe-flash-player-clickjacking-vulnerability/" title="Adobe Flash Player Clickjacking Vulnerability (October 8, 2008)">Adobe Flash Player Clickjacking Vulnerability</a> (1)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2008/05/28/vulnerabilities-in-latest-flash-version/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
	</channel>
</rss>
