Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Welcome to the Club, Macromedia
Shane Coursen, 2002-01-14

With the discovery of the first Flash virus, the popular format joins the growing list of ways virus-writers can attack.

Comments Mode:
Welcome to the Club, Macromedia 2002-01-15
Anonymous (1 replies)
The new flash virus may not be a big risk by itself, but people share emails with embedded flash greetings as well, would it be possible to write a flash application with ActionScript that in turns sends a piece of malicious VBScript to Outlook for example ?
...

[ more ]  [ reply ]
Welcome to the Club, Macromedia 2002-01-18
Anonymous
actually no. infection on other that a developer's machine is near impossible. see Macromedia's handling of the vulnerability:

http://www.macromedia.com/support/flash/ts/documents/swf_cle
ar.htm...

[ more ]  [ reply ]
Welcome to the Club, Macromedia 2002-01-15
Geordy Korte
I am just wondering in which way a FLASH SWF file can actualy infect a system. To my knowledge the SWF format has very limited access to file IO of the parent OS so infecting it seems quite hard. Does anyone have any idea's...

[ more ]  [ reply ]
Welcome to the Club, Macromedia 2002-01-16
Anonymous
It will be interesting to see how Macromedia closes this
security hole while at the same time giving web authors the flexibilty to read/write data.

Flash is more than just an animation tool, so whenever it's used in an environment that accesses the PC to read/write data, there's always a potent...

[ more ]  [ reply ]
Welcome to the Club, Macromedia 2002-01-16
Anonymous (1 replies)
Macromedia suxx...

[ more ]  [ reply ]
Welcome to the Club, Macromedia 2002-01-18
Anonymous
Macromedia is a little fish trying to swim with big fishes, they blow. Thanks for ruining Allaire's products!...

[ more ]  [ reply ]
Are we to blame Macormedia? 2002-01-20
NetWARioR
Are we really to blame macromedia for this? Macromedia has made a beautiful piece of software (aka Flash 5) and it has excelled in the way of multimedia for the internet. Was their a big snarl at Adobe when PDF virii came out? I dont know. The reason SWF is now used is because it is yet another way ...

[ more ]  [ reply ]
Welcome to the Club, Macromedia 2002-01-21
Anonymous
The bit I read about it said it only infected swf files, and that the virus that is proven required some manipulation in some way that made internet based infection unlikely, I guess this is due to offsets and the sandbox stopping them.
...

[ more ]  [ reply ]
Welcome to the Club, Macromedia 2002-01-21
Anonymous
The information is right here at security focus.

http://www.securityfocus.com/news/303...

[ more ]  [ reply ]
Welcome to the Club, Macromedia 2002-01-21
z3mo
I have seen this in action. Not fun, not fun at all....

[ more ]  [ reply ]
Welcome to the Club, Macromedia 2002-01-22
Bbesselink@novus-tele.net
Just a suggestion!
An embedded link to the macromedia download page
is kinda handy for your readers!

http://www.macromedia.com/support/flash/ts/documents/swf_cle
ar.htm...

[ more ]  [ reply ]
Welcome to the Club, Macromedia 2002-01-26
Sugien

What it is:

An ActiveX control which I created in conjunction with Neil Ramsbottom (prior to this email/post Neil in part because of his becoming disenchanted with our chances of obtaining any monetary recompense for our combined work on this project, has graciously given to me ...

[ more ]  [ reply ]
Welcome to the Club, Macromedia 2002-01-27
Anonymous
Quote:

"Flash" multimedia format, which can be read by more than 97 percent of Web users.


Really? I doubt that it will be much more than 50%......

[ more ]  [ reply ]
Welcome to the Club, Macromedia 2002-01-29
Anonymous (1 replies)
If it doesn not infect by clicking a link i dont see this as being any trouble. I myself wrote java-script / vbscript that infects right from the html that so far works on every IE and OS. I have no intention of releasing it to anyone but Wwat is this worth?...

[ more ]  [ reply ]
Welcome to the Club, Macromedia 2002-02-04
Anonymous
as a bug/hole it is worthless; but as a development tool if those useing it could be trusted worth a lot in saved development time; but I have decided to remove it from the market; because after trying to make it safe for all to use and to prevent script kiddies from being able to use it to cause tr...

[ more ]  [ reply ]







 

Privacy Statement
Copyright 2009, SecurityFocus