Adobe Flash Flaw Threatens Websites
A serious flaw in the way people use Adobe's Flash software could leave tens of thousands of websites vulnerable to hackers. The problem lies in Shockwave Flash files (SWFs), which appear on websites and allow the site author to include short movies or animated graphics. (Source: half-serious.com)
The way the software currently works means it's possible for hackers to insert their own code into these files. For example, they could program the file to send them copies of personal information that the user types while visiting a site. At the moment, there are no patches available.
The problem is uncovered in the new book, 'Hacking Exposed Web 2.0: Web 2.0 Security Secrets and Solutions'. The authors include researchers from Google and iSEC partners, a firm that specialises in security testing.
According to the book, which won't be officially released until January, more than 500,000 SWFs are vulnerable to hackers, including those on sites for financial firms and government agencies.
Author Alex Stamos warned that the only sure-fire way to get around the problem is to remove the SWFs from the site until a solution is found. The issue is made worse by the fact that many of the most common programs used for creating such animations automatically generate code that includes the bugs. Site owners will need to manually examine every SWF and check for problems.
The authors have been coordinating with Adobe on the problem and the software firm says a solution should be available in the next few weeks. (Source: computerworld.com)
Most popular articles
- Which Processor is Better: Intel or AMD? - Explained
- How to Prevent Ransomware in 2018 - 10 Steps
- 5 Best Anti Ransomware Software Free
- How to Fix: Computer / Network Infected with Ransomware (10 Steps)
- How to Fix: Your Computer is Infected, Call This Number (Scam)
- Scammed by Informatico Experts? Here's What to Do
- Scammed by Smart PC Experts? Here's What to Do
- Scammed by Right PC Experts? Here's What to Do
- Scammed by PC / Web Network Experts? Here's What to Do
- How to Fix: Windows Update Won't Update
- Explained: Do I need a VPN? Are VPNs Safe for Online Banking?
- Explained: VPN vs Proxy; What's the Difference?
- Explained: Difference Between VPN Server and VPN (Service)
- Forgot Password? How to: Reset Any Password: Windows Vista, 7, 8, 10
- How to: Use a Firewall to Block Full Screen Ads on Android
- Explained: Absolute Best way to Limit Data on Android
- Explained: Difference Between Dark Web, Deep Net, Darknet and More
- Explained: If I Reset Windows 10 will it Remove Malware?
My name is Dennis Faas and I am a senior systems administrator and IT technical analyst specializing in cyber crimes (sextortion / blackmail / tech support scams) with over 30 years experience; I also run this website! If you need technical assistance , I can help. Click here to email me now; optionally, you can review my resume here. You can also read how I can fix your computer over the Internet (also includes user reviews).
We are BBB Accredited
We are BBB accredited (A+ rating), celebrating 21 years of excellence! Click to view our rating on the BBB.