<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Backdooring Flash Objects (the receipt)</title>
	<atom:link href="http://www.gnucitizen.org/blog/backdooring-flash-objects-receipt/feed/" rel="self" type="application/rss+xml" />
	<link>/blog/backdooring-flash-objects-receipt/</link>
	<description>Information Security Think Tank</description>
	<pubDate>Thu, 21 Aug 2008 20:08:21 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.1</generator>
		<item>
		<title>By: Sploiter Splog &#124; GNUCITIZEN</title>
		<link>/blog/backdooring-flash-objects-receipt/#comment-33146</link>
		<dc:creator>Sploiter Splog &#124; GNUCITIZEN</dc:creator>
		<pubDate>Sun, 01 Jul 2007 08:28:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-flash-objects-receipt#comment-33146</guid>
		<description>[...] the techniques such as persistent channels, backdoors in QuickTime, backdoors in Flash, backdoors in PDF, backdoors in RealMedia and backdoors in RSS feeds in conjunction with splogs one [...]</description>
		<content:encoded><![CDATA[<p>[...] the techniques such as persistent channels, backdoors in QuickTime, backdoors in Flash, backdoors in PDF, backdoors in RealMedia and backdoors in RSS feeds in conjunction with splogs one [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GNUCITIZEN &#187; Backdooring Images</title>
		<link>/blog/backdooring-flash-objects-receipt/#comment-4396</link>
		<dc:creator>GNUCITIZEN &#187; Backdooring Images</dc:creator>
		<pubDate>Fri, 16 Feb 2007 21:56:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-flash-objects-receipt#comment-4396</guid>
		<description>[...] OK, weï¿½ve covered how to backdoor Flash, QuickTime, QuickTime Link, PDF and simple HTML files, but we havenï¿½t discussed how to backdoor images yet. In this post I am going to outline some of the techniques available for maliciously infecting Image (Picture) files with JavaScript code. I must worn you that what you are about to read is not intended to describe new issues but rather to clarify and provide scenarios where the discussed attack vectors can be implemented. [...]</description>
		<content:encoded><![CDATA[<p>[...] OK, weï¿½ve covered how to backdoor Flash, QuickTime, QuickTime Link, PDF and simple HTML files, but we havenï¿½t discussed how to backdoor images yet. In this post I am going to outline some of the techniques available for maliciously infecting Image (Picture) files with JavaScript code. I must worn you that what you are about to read is not intended to describe new issues but rather to clarify and provide scenarios where the discussed attack vectors can be implemented. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GNUCITIZEN &#187; DANGER, DANGER, DANGER</title>
		<link>/blog/backdooring-flash-objects-receipt/#comment-1778</link>
		<dc:creator>GNUCITIZEN &#187; DANGER, DANGER, DANGER</dc:creator>
		<pubDate>Wed, 03 Jan 2007 09:04:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-flash-objects-receipt#comment-1778</guid>
		<description>[...] The WEB has gone crazy. I know that this is not news for some of you but you will be surprised to what extend this craziness has just developed. It seams that the entire WEB is falling apart and someone has to do something otherwise we risk to lose too much. Among the traditional QuickTime Movie, QTL, Flash, Image, HTML and PDF backdoors, there is another one trivially achievable with high degree of impact. [...]</description>
		<content:encoded><![CDATA[<p>[...] The WEB has gone crazy. I know that this is not news for some of you but you will be surprised to what extend this craziness has just developed. It seams that the entire WEB is falling apart and someone has to do something otherwise we risk to lose too much. Among the traditional QuickTime Movie, QTL, Flash, Image, HTML and PDF backdoors, there is another one trivially achievable with high degree of impact. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Frank Walsh</title>
		<link>/blog/backdooring-flash-objects-receipt/#comment-900</link>
		<dc:creator>Frank Walsh</dc:creator>
		<pubDate>Mon, 04 Dec 2006 00:06:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-flash-objects-receipt#comment-900</guid>
		<description>above you say allowscriptaccess="never" kills your POC but javascript isn't nessecary , you can do with with purse ActionScript...isn't there also a tag allowNetworking="internal" would cover this... just wondering if I'm missing something in your response..not trying to be a dick.</description>
		<content:encoded><![CDATA[<p>above you say allowscriptaccess=&#8221;never&#8221; kills your POC but javascript isn&#8217;t nessecary , you can do with with purse ActionScript&#8230;isn&#8217;t there also a tag allowNetworking=&#8221;internal&#8221; would cover this&#8230; just wondering if I&#8217;m missing something in your response..not trying to be a dick.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>/blog/backdooring-flash-objects-receipt/#comment-168</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Fri, 29 Sep 2006 06:53:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-flash-objects-receipt#comment-168</guid>
		<description>Have you actually spend time going through &lt;a href="http://www.gnucitizen.org/projects/attackapi" rel="nofollow" rel="nofollow"&gt;AttackAPI&lt;/a&gt;? 

Or, Is it fine with you if attackers are able to break into a couple of websites from your own browser, or maybe compromise your home router?

If yes, than I agree, primitive javascript access shouldn't harm you at all.

:) cheers</description>
		<content:encoded><![CDATA[<p>Have you actually spend time going through <a href="http://www.gnucitizen.org/projects/attackapi" rel="nofollow" rel="nofollow">AttackAPI</a>? </p>
<p>Or, Is it fine with you if attackers are able to break into a couple of websites from your own browser, or maybe compromise your home router?</p>
<p>If yes, than I agree, primitive javascript access shouldn&#8217;t harm you at all.</p>
<p>:) cheers</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: chown</title>
		<link>/blog/backdooring-flash-objects-receipt/#comment-166</link>
		<dc:creator>chown</dc:creator>
		<pubDate>Fri, 29 Sep 2006 04:34:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-flash-objects-receipt#comment-166</guid>
		<description>Primitive javascript access - within the confines of the browsers security restrictions, can hardly be classified as "system resources". If it were, then you could say you have access to the "system resources" of me, and anyone else who visits this site.
By your logic, the following is a VBScript backdoor in a batch file

&lt;pre&gt;&lt;code&gt;@echo off
echo msgbox "foo" &#62; bar.vbs
start bar.vbs&lt;/code&gt;&lt;/pre&gt;</description>
		<content:encoded><![CDATA[<p>Primitive javascript access - within the confines of the browsers security restrictions, can hardly be classified as &#8220;system resources&#8221;. If it were, then you could say you have access to the &#8220;system resources&#8221; of me, and anyone else who visits this site.<br />
By your logic, the following is a VBScript backdoor in a batch file</p>
<pre><code>@echo off
echo msgbox "foo" &gt; bar.vbs
start bar.vbs</code></pre>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>/blog/backdooring-flash-objects-receipt/#comment-162</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Thu, 28 Sep 2006 02:00:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-flash-objects-receipt#comment-162</guid>
		<description>shizkani,
the short answer is "NO", unless you use something like the IE VML vulnerability.

chown,
&lt;blockquote&gt;A type of Remote Control Software that enables a third party to covertly control system resources.&lt;a href="http://www.google.com.my/url?sa=X&#038;start=1&#038;oi=define&#038;q=http://www.wetstonetech.com/page/page/1972572.htm" rel="nofollow" rel="nofollow" rel="nofollow"&gt;wetstonetech&lt;/a&gt;&lt;/blockquote&gt;

What do you think a backdoor is?</description>
		<content:encoded><![CDATA[<p>shizkani,<br />
the short answer is &#8220;NO&#8221;, unless you use something like the IE VML vulnerability.</p>
<p>chown,</p>
<blockquote><p>A type of Remote Control Software that enables a third party to covertly control system resources.<a href="http://www.google.com.my/url?sa=X&#038;start=1&#038;oi=define&#038;q=http://www.wetstonetech.com/page/page/1972572.htm" rel="nofollow" rel="nofollow" rel="nofollow">wetstonetech</a></p></blockquote>
<p>What do you think a backdoor is?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: chown</title>
		<link>/blog/backdooring-flash-objects-receipt/#comment-159</link>
		<dc:creator>chown</dc:creator>
		<pubDate>Wed, 27 Sep 2006 04:19:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-flash-objects-receipt#comment-159</guid>
		<description>How can you call it backdooring? You're simply embedding javascript in flash.
Please explain your definition of 'backdoor'</description>
		<content:encoded><![CDATA[<p>How can you call it backdooring? You&#8217;re simply embedding javascript in flash.<br />
Please explain your definition of &#8216;backdoor&#8217;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: shizkani</title>
		<link>/blog/backdooring-flash-objects-receipt/#comment-157</link>
		<dc:creator>shizkani</dc:creator>
		<pubDate>Tue, 26 Sep 2006 23:52:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-flash-objects-receipt#comment-157</guid>
		<description>can you make this exploit download and execute a RAT server to someine who views the corrupted .swf file ..??
if so can someone please explain to me how i would make it possible..
thanks..</description>
		<content:encoded><![CDATA[<p>can you make this exploit download and execute a RAT server to someine who views the corrupted .swf file ..??<br />
if so can someone please explain to me how i would make it possible..<br />
thanks..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>/blog/backdooring-flash-objects-receipt/#comment-75</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Fri, 15 Sep 2006 15:51:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-flash-objects-receipt#comment-75</guid>
		<description>I know. This article is just a POC on how easy it is to backdoor any given flash object.</description>
		<content:encoded><![CDATA[<p>I know. This article is just a POC on how easy it is to backdoor any given flash object.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Vladislav 'dgtlscrm' Mysla</title>
		<link>/blog/backdooring-flash-objects-receipt/#comment-73</link>
		<dc:creator>Vladislav 'dgtlscrm' Mysla</dc:creator>
		<pubDate>Fri, 15 Sep 2006 13:59:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-flash-objects-receipt#comment-73</guid>
		<description>Using javascript protocol is well known technique</description>
		<content:encoded><![CDATA[<p>Using javascript protocol is well known technique</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>/blog/backdooring-flash-objects-receipt/#comment-54</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Fri, 08 Sep 2006 07:25:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-flash-objects-receipt#comment-54</guid>
		<description>Definitely,

I would like to see your malware. I won't be able to attend these conferences but I will be vary happy to get some of your slides.

I am also working on some advance techniques that will go into AttackAPI and my blog quite soon.</description>
		<content:encoded><![CDATA[<p>Definitely,</p>
<p>I would like to see your malware. I won&#8217;t be able to attend these conferences but I will be vary happy to get some of your slides.</p>
<p>I am also working on some advance techniques that will go into AttackAPI and my blog quite soon.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Acidus</title>
		<link>/blog/backdooring-flash-objects-receipt/#comment-53</link>
		<dc:creator>Acidus</dc:creator>
		<pubDate>Fri, 08 Sep 2006 02:50:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-flash-objects-receipt#comment-53</guid>
		<description>pdp,

I love what you are doing so please keep up the good work. For far too long people have thought that JavaScript is a toy language and that XSS can only annoy and steal the occasional cookie. I applaud the work you have been doing.

Acidus,

ps: I'm going to be dropping some JavaScript malware 0day in a week of back to back conferences (Toorcon-Ajax World-Security Opus) that I thhink you will find interesting...</description>
		<content:encoded><![CDATA[<p>pdp,</p>
<p>I love what you are doing so please keep up the good work. For far too long people have thought that JavaScript is a toy language and that XSS can only annoy and steal the occasional cookie. I applaud the work you have been doing.</p>
<p>Acidus,</p>
<p>ps: I&#8217;m going to be dropping some JavaScript malware 0day in a week of back to back conferences (Toorcon-Ajax World-Security Opus) that I thhink you will find interesting&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>/blog/backdooring-flash-objects-receipt/#comment-45</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Wed, 06 Sep 2006 20:51:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-flash-objects-receipt#comment-45</guid>
		<description>Well, then my POC won't work. It is that simple. However, keep in mind that JavaScript access is not required. Flash objects can be backdoored with ActionScript quite successfully and the attacker is given the same level accessibility; sometimes even more.</description>
		<content:encoded><![CDATA[<p>Well, then my POC won&#8217;t work. It is that simple. However, keep in mind that JavaScript access is not required. Flash objects can be backdoored with ActionScript quite successfully and the attacker is given the same level accessibility; sometimes even more.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dev&#62;null</title>
		<link>/blog/backdooring-flash-objects-receipt/#comment-40</link>
		<dc:creator>dev&#62;null</dc:creator>
		<pubDate>Wed, 06 Sep 2006 17:15:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-flash-objects-receipt#comment-40</guid>
		<description>um ... what about allowScriptAccess="never"?</description>
		<content:encoded><![CDATA[<p>um &#8230; what about allowScriptAccess=&#8221;never&#8221;?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>/blog/backdooring-flash-objects-receipt/#comment-37</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Wed, 06 Sep 2006 07:02:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-flash-objects-receipt#comment-37</guid>
		<description>There are no stupid questions.

I don't think that there is simple way of protecting against media file malware. Of course the most obvious approach will be to disable or filter out embed an object tags. However, this will make MySpace pages highly inaccessible because people won't be able to show their YouTube movies for example.

Yeh, I might think about favicon. Why not?</description>
		<content:encoded><![CDATA[<p>There are no stupid questions.</p>
<p>I don&#8217;t think that there is simple way of protecting against media file malware. Of course the most obvious approach will be to disable or filter out embed an object tags. However, this will make MySpace pages highly inaccessible because people won&#8217;t be able to show their YouTube movies for example.</p>
<p>Yeh, I might think about favicon. Why not?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: nrg</title>
		<link>/blog/backdooring-flash-objects-receipt/#comment-35</link>
		<dc:creator>nrg</dc:creator>
		<pubDate>Wed, 06 Sep 2006 01:05:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-flash-objects-receipt#comment-35</guid>
		<description>"First of all, wrapping your malicious code inside flash files will bypass all XSS filtering systems (...)"

Hadn't thought about that.
It's clear for me now, thanks for the fast explanation. Actually after thinking a bit about it was a really dumb question.

So how can websites like myspace protect them selfs from being hijacked by an 'infected' swf? (i'm not a user from my space but i think they allow the use of SWFs in users accounts).

Time to read how you managed to do it with quicktime.

PS: Stupid suggestion, can you get a favicon? I would like to have it on my bookmark.</description>
		<content:encoded><![CDATA[<p>&#8220;First of all, wrapping your malicious code inside flash files will bypass all XSS filtering systems (&#8230;)&#8221;</p>
<p>Hadn&#8217;t thought about that.<br />
It&#8217;s clear for me now, thanks for the fast explanation. Actually after thinking a bit about it was a really dumb question.</p>
<p>So how can websites like myspace protect them selfs from being hijacked by an &#8216;infected&#8217; swf? (i&#8217;m not a user from my space but i think they allow the use of SWFs in users accounts).</p>
<p>Time to read how you managed to do it with quicktime.</p>
<p>PS: Stupid suggestion, can you get a favicon? I would like to have it on my bookmark.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>/blog/backdooring-flash-objects-receipt/#comment-34</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Wed, 06 Sep 2006 00:42:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-flash-objects-receipt#comment-34</guid>
		<description>hi there,

First of all, wrapping your malicious code inside flash files will bypass all XSS filtering systems, simply becouse they don't understand how to read SWF files not to mention that even if they know how to do that, it would be highly inefficient approach.

The second thing is that attackers are able to infect popular video, audio and interactive material and spread it on the web. This approach can be quite easily defined as viral infection. The next time you visit youtube.com or video.google.com beware that what you see might not be what you get. Sneeky JavaScript code can scan your internal LAN, hack into your WIFI router and enable the admin interface on the Internet side so attackers have direct access to you, your personal details and your bank account numbers.

I don't want to cover DDOS attacks because it is getting scary.

I hope it is clear now :)</description>
		<content:encoded><![CDATA[<p>hi there,</p>
<p>First of all, wrapping your malicious code inside flash files will bypass all XSS filtering systems, simply becouse they don&#8217;t understand how to read SWF files not to mention that even if they know how to do that, it would be highly inefficient approach.</p>
<p>The second thing is that attackers are able to infect popular video, audio and interactive material and spread it on the web. This approach can be quite easily defined as viral infection. The next time you visit youtube.com or video.google.com beware that what you see might not be what you get. Sneeky JavaScript code can scan your internal LAN, hack into your WIFI router and enable the admin interface on the Internet side so attackers have direct access to you, your personal details and your bank account numbers.</p>
<p>I don&#8217;t want to cover DDOS attacks because it is getting scary.</p>
<p>I hope it is clear now :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: nrg</title>
		<link>/blog/backdooring-flash-objects-receipt/#comment-33</link>
		<dc:creator>nrg</dc:creator>
		<pubDate>Tue, 05 Sep 2006 23:10:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-flash-objects-receipt#comment-33</guid>
		<description>Hello mate, i enjoyed vey much reading your recent posts, but there is something in these last 2 that i didn't really understood. Whats so important about injecting javascript into a flash? can't you do the same that you would with a simple html with javascript inside? I get the idea about infecting SWFs wich is preaty cool but i don't see what's so special about it. Am I missing something?

Anyway keep posting mate :)

-nrg</description>
		<content:encoded><![CDATA[<p>Hello mate, i enjoyed vey much reading your recent posts, but there is something in these last 2 that i didn&#8217;t really understood. Whats so important about injecting javascript into a flash? can&#8217;t you do the same that you would with a simple html with javascript inside? I get the idea about infecting SWFs wich is preaty cool but i don&#8217;t see what&#8217;s so special about it. Am I missing something?</p>
<p>Anyway keep posting mate :)</p>
<p>-nrg</p>
]]></content:encoded>
	</item>
</channel>
</rss>
