Header Ziff Davis Enterprise
Advertisement
Advertisement
Thursday, October 16, 2008 2:07 PM/EST

Flash 10 Fixes Clickjacking Flaw

Not long after "clickjacking" attacks appeared several weeks ago it became clear that the culprit was Adobe's Flash. And the problem, as we say in the software biz, wasn't a bug, it was a feature. This feature has been modified in the new Flash 10 player to address the problem.

The problem is clipboard access. By default, Flash 9 allowed a Flash program to read and write to the clipboard. Clickjacking attacks took advantage of this to persistently stuff a value, usually a malicious URL, into the clipboard, in the hope the user would visit it. The attack is as cross-platform as Flash, working on Macs as well as Windows.

In Flash 10 the clipboard methods will only work when called through ActionScript, which originates with a user action, like pressing a button. No longer will a silent Flash application be able to hijack the clipboard completely without the user noticing.

This change was just one of many security changes in the Flash 10 player. Changes in how Flash handles policy files mean that developers will have to address their use of them. Errors on socket connect() calls will be handled differently. And much as with clipboards, file uploads and downloads may only occur in script that begins with a user action. There are other changes as well.

The flip side of this fix is that it is not implemented in Flash 9. This means that the only way to escape clickjacking attacks is to upgrade to Flash 10.

TrackBack

TrackBack

http://blogs.eweek.com/cgi-bin/mte/mt-tb.cgi/15331

Comments (1)

Amanda :

Solution from Search-and-destroy.
If you own a computer, you must have antispyware to keep it running at its best. The problem is choosing a scan that works. I have tried many different types of scans in the past and then I ran across Search-and-destroy Antispyware. I have to say that the antispyware solution from Search-and-destroy is the best that I have used to date. It gets the job done and keeps my computer working like new. If you are interested in seeing for yourself just how good this antispyware works you can click on http://www.Search-and-destroy.com/antispyware.html to learn more. I’m sure it would be worth your time to check it out.

Post a Comment

 
 
Advertisement
Advertisement