Flash vulnerabiliity

Ask for help about NoScript, no registration needed to post
kukla
Senior Member
Posts: 321
Joined: Mon May 04, 2009 12:08 am

Flash vulnerabiliity

Post by kukla »

Hackers can exploit a flaw in Adobe's Flash to compromise nearly every Web site that allows users to upload content, including Google's Gmail, then launch silent attacks on visitors to those sites, security researchers said today.
http://www.computerworld.com/s/article/ ... esearchers

NoScript is mentioned in the article linked. I'm wondering how much protection NoScript provides for this kind of exploit? Basically, if I'm using NoScript, can I load Flash content without much worry? Any tips? Thanks.
Mozilla/5.0 (Macintosh; U; PPC Mac OS X 10.5; en-US; rv:1.9.1.5) Gecko/20091102 Firefox/3.5.5
User avatar
therube
Ambassador
Posts: 7969
Joined: Thu Mar 19, 2009 4:17 pm
Location: Maryland USA

Re: Flash vulnerabiliity

Post by therube »

No, Flash runs in its own world.

See, Expert says Adobe Flash policy is risky & the linked pages therein.
Giorgio wrote:So your best bet is using NoScript, better with "Apply these restrictions to trusted sites as well".
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.19) Gecko/20110420 SeaMonkey/2.0.14 Pinball NoScript FlashGot AdblockPlus
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.6pre) Gecko/20091114 SeaMonkey/2.0.1pre
kukla
Senior Member
Posts: 321
Joined: Mon May 04, 2009 12:08 am

Re: Flash vulnerabiliity

Post by kukla »

A little clarification, please. Does that then mean one should simply not load any Flash? Isn't this what "Apply these restrictions to trusted sites" effectively accomplishes; it disables Flash from loading until the placeholder is clicked. Are you saying that once you load any Flash, you're on your own with no protection from NS? Is this a correct reading of your comment?
In other words, ClicktoFlash in Safari, or Flash disabled in Camino, would essentially accomplish the same thing, by simply not allowing the Flash to load in the first place?

Or, if this is considered a cross site scripting exploit, or something else that NS will filter, will NS protect against this? Thanks.
Mozilla/5.0 (Macintosh; U; PPC Mac OS X 10.5; en-US; rv:1.9.1.5) Gecko/20091102 Firefox/3.5.5
User avatar
therube
Ambassador
Posts: 7969
Joined: Thu Mar 19, 2009 4:17 pm
Location: Maryland USA

Re: Flash vulnerabiliity

Post by therube »

Others would have to chime in, but I believe ...

Once you click the placeholder, you are at the mercy of the Flash you clicked.
NoScript can & will help in a general & broad sense, but once Flash is running, it is then outside the scope of the browser & so NoScript.
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.19) Gecko/20110420 SeaMonkey/2.0.14 Pinball NoScript FlashGot AdblockPlus
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.4) Gecko/20091017 SeaMonkey/2.0
Post Reply