Adobe Flash Vulnarability - alert?

pumpkin pie

pumpkin pie

Furnace Stoker

Join Date: Jul 2006

behind you

bumble bee

E/

Wander if I should post this here , says theres a vulnerability in adobe flash and that we should turn it off.

Overview of a similar case earlier.

Integer overflow in Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code via a crafted SWF file with a negative Scene Count value, which passes a signed comparison, is used as an offset of a NULL pointer, and triggers a buffer overflow.


http://www.pcmag.com/article2/0,1895,2310320,00.asp

mazza558

Lion's Arch Merchant

Join Date: Mar 2006

R/

Does this affect Flash 10?

pumpkin pie

pumpkin pie

Furnace Stoker

Join Date: Jul 2006

behind you

bumble bee

E/

oh, i am not sure, but it does raise alarm since there are so many account getting hack now a days, i've block all flash and scripts to be on the safe side, beside they are very annoying.

Maca

Maca

Frost Gate Guardian

Join Date: Dec 2005

Guardians Of The Stars

Me/Mo

That warnning is on a starting screen of wow, here it goes:

wowflash.jpg

pumpkin pie

pumpkin pie

Furnace Stoker

Join Date: Jul 2006

behind you

bumble bee

E/

OMG so its quit serious then..., luckily I am using good old firefox and have the noscript lol add on, (i think noscript is a script too) lololol. b

The Way Out

The Way Out

Wilds Pathfinder

Join Date: Aug 2007

In my peanut brain

Zomg Zombies [OMG]

Mo/E

Depending on what sites you are hitting. Many people begin to surf sites that sell gold, items, or bots. Because flash is active upon hitting a site, it has always been easy to inject code through the flash plugins on your browser.

http://www.toptechnews.com/story.xht...d=1200044YL3E0

Here is an article where someone gets money for it. Sounds like a good gig to me. *wink wink*

Nazar Razak

Nazar Razak

Lion's Arch Merchant

Join Date: Mar 2006

Noscript <3 .

The Way Out

The Way Out

Wilds Pathfinder

Join Date: Aug 2007

In my peanut brain

Zomg Zombies [OMG]

Mo/E

Quote:
Originally Posted by Nazar Razak
Noscript <3 .
LMAO!!!!!!!!!!!!!!!!!!!!!

pablo24

Frost Gate Guardian

Join Date: Aug 2007

noscript doesnt work for this..... *.swf aren't javascripts....

derc

Academy Page

Join Date: Nov 2007

Hand of the Divine [HOLY]

W/A

Quote:
Originally Posted by pablo24
noscript doesnt work for this..... *.swf aren't javascripts....
Flash contains Actionscript

And besides, noscript DOES block flash
http://noscript.net/

pumpkin pie

pumpkin pie

Furnace Stoker

Join Date: Jul 2006

behind you

bumble bee

E/

option, option... and then check the box that say forbids adobe(R) flash, hope that works.

Its better then using IE, IE gave me so many virus problems I can't even begin to describe the frustration... lol, so I refuse to be frustrated, hence I am using firefox now.

Darkobra

Darkobra

Forge Runner

Join Date: Aug 2006

Scotland

Type like an idiot, I'll treat you like an idiot

E/Me

Yeah, NoScript does block flash, if you allow it to.

But anyway, I came on here after starting WoW to see if it was just WoW it was affecting, or if this might be one of the ways people are getting targeted on GW too.

Either way, update it.

MarlinBackna

MarlinBackna

Krytan Explorer

Join Date: May 2007

[TAM]

W/

Quote:
Either way, upgrade it.
End of the story. There is a link in the first article to check your version of Flash (should be 9.0.124.0).

The Way Out

The Way Out

Wilds Pathfinder

Join Date: Aug 2007

In my peanut brain

Zomg Zombies [OMG]

Mo/E

Quote:
Originally Posted by pablo24
noscript doesnt work for this..... *.swf aren't javascripts....
I almost pissed myself when he said noscript. hahahahaha

Nazar Razak

Nazar Razak

Lion's Arch Merchant

Join Date: Mar 2006

Quote:
Originally Posted by The Way Out
I almost pissed myself when he said noscript. hahahahaha
Im here to Entertain ;D

noob4sure

Ascalonian Squire

Join Date: Feb 2006

Middle of nowhere, U.S.A.

[LGBT]

A/

Quote:
Originally Posted by The Way Out
I almost pissed myself when he said noscript. hahahahaha
Since when has noscript not autoblocked .swf on a site which isn't whitelisted....?

Snograt

Snograt

rattus rattus

Join Date: Jan 2006

London, UK GMT??0 ??1hr DST

[GURU]GW [wiki]GW2

R/

Ok, I'll bite...

...Why the hilarity over NoScript?

Brianna

Brianna

Insane & Inhumane

Join Date: Feb 2006

I know youtube uses flash, is it safe to browse youtube?

Quote:
Originally Posted by Snograt
Ok, I'll bite...

...Why the hilarity over NoScript?
Wondering myself.

Kumu Honua

Kumu Honua

Jungle Guide

Join Date: Feb 2008

Quote:
Originally Posted by Snograt
Ok, I'll bite...

...Why the hilarity over NoScript?
Ignorance over what NoScript actually blocks.

My guess at the hilarity is that since the word "Script" is in the name of NoScript that it only blocks Javascript when in fact it blocks everything from Javascript to Silverlight to Flash to XSS to IFRAME to....

Of course, this tool only works if it's active.

Darkobra

Darkobra

Forge Runner

Join Date: Aug 2006

Scotland

Type like an idiot, I'll treat you like an idiot

E/Me

Quote:
Originally Posted by Brianna
I know youtube uses flash, is it safe to browse youtube?
If you value sanity, has it ever been?

free_fall

free_fall

Wilds Pathfinder

Join Date: Oct 2005

Ya, I use Flash BLocker myself. It's always on, except when I turn it off to visit YouTube.