<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Backdooring Flash Objects (the walkthrough)</title>
	<atom:link href="http://www.gnucitizen.org/blog/backdooring-flash-objects/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/blog/backdooring-flash-objects/</link>
	<description>Information Security Think Tank</description>
	<lastBuildDate>Sat, 02 Feb 2013 17:50:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.1</generator>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/backdooring-flash-objects/comment-page-1/#comment-130590</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Mon, 09 May 2011 08:52:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-flash-objects#comment-130590</guid>
		<description>attachMovie, fixed!</description>
		<content:encoded><![CDATA[<p>attachMovie, fixed!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Backdooring Flash Objects (the receipt) &#124; GNUCITIZEN</title>
		<link>http://www.gnucitizen.org/blog/backdooring-flash-objects/comment-page-1/#comment-124986</link>
		<dc:creator>Backdooring Flash Objects (the receipt) &#124; GNUCITIZEN</dc:creator>
		<pubDate>Thu, 01 Jan 2009 20:48:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-flash-objects#comment-124986</guid>
		<description>[...] a day ago I released a quite narrative article called Backdooring Flash Objects (the walkthrough). Although, I received some quite good responds on the style of writing, I decided to write more [...]</description>
		<content:encoded><![CDATA[<p>[...] a day ago I released a quite narrative article called Backdooring Flash Objects (the walkthrough). Although, I received some quite good responds on the style of writing, I decided to write more [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Backdooring MP3 Files &#124; GNUCITIZEN</title>
		<link>http://www.gnucitizen.org/blog/backdooring-flash-objects/comment-page-1/#comment-124979</link>
		<dc:creator>Backdooring MP3 Files &#124; GNUCITIZEN</dc:creator>
		<pubDate>Thu, 01 Jan 2009 18:41:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-flash-objects#comment-124979</guid>
		<description>[...] 20th, 2006 Recently I published information on how specially crafted HTML (remote and local), Flash and QuickTime (.mov) files can be used by malicious users to target and exploit internal and [...]</description>
		<content:encoded><![CDATA[<p>[...] 20th, 2006 Recently I published information on how specially crafted HTML (remote and local), Flash and QuickTime (.mov) files can be used by malicious users to target and exploit internal and [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mmx</title>
		<link>http://www.gnucitizen.org/blog/backdooring-flash-objects/comment-page-1/#comment-123278</link>
		<dc:creator>Mmx</dc:creator>
		<pubDate>Tue, 19 Aug 2008 09:01:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-flash-objects#comment-123278</guid>
		<description>What in the world is MovieClip.attackMovie() ?</description>
		<content:encoded><![CDATA[<p>What in the world is MovieClip.attackMovie() ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: James</title>
		<link>http://www.gnucitizen.org/blog/backdooring-flash-objects/comment-page-1/#comment-90376</link>
		<dc:creator>James</dc:creator>
		<pubDate>Sat, 22 Dec 2007 23:21:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-flash-objects#comment-90376</guid>
		<description>Hi

&gt;&gt; The first tool to download was Mtasc from Nicolas Cannasse.

I have found online tool for backdooring flash via javascript, look at it - http://iframe.in/</description>
		<content:encoded><![CDATA[<p>Hi</p>
<p>&gt;&gt; The first tool to download was Mtasc from Nicolas Cannasse.</p>
<p>I have found online tool for backdooring flash via javascript, look at it &#8211; <a href="http://iframe.in/" rel="nofollow">http://iframe.in/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: amer</title>
		<link>http://www.gnucitizen.org/blog/backdooring-flash-objects/comment-page-1/#comment-54958</link>
		<dc:creator>amer</dc:creator>
		<pubDate>Thu, 04 Oct 2007 06:36:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-flash-objects#comment-54958</guid>
		<description>ineed</description>
		<content:encoded><![CDATA[<p>ineed</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/backdooring-flash-objects/comment-page-1/#comment-36203</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Fri, 20 Jul 2007 06:33:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-flash-objects#comment-36203</guid>
		<description>no worries. better late then never.</description>
		<content:encoded><![CDATA[<p>no worries. better late then never.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: raaka</title>
		<link>http://www.gnucitizen.org/blog/backdooring-flash-objects/comment-page-1/#comment-36201</link>
		<dc:creator>raaka</dc:creator>
		<pubDate>Fri, 20 Jul 2007 06:32:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-flash-objects#comment-36201</guid>
		<description>well from few weeks i am working on yahoo messenger. Trying to prove my concept of exploiting ***********, this is very useful indeed

sorry for laaaate posting.</description>
		<content:encoded><![CDATA[<p>well from few weeks i am working on yahoo messenger. Trying to prove my concept of exploiting ***********, this is very useful indeed</p>
<p>sorry for laaaate posting.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Linn</title>
		<link>http://www.gnucitizen.org/blog/backdooring-flash-objects/comment-page-1/#comment-10943</link>
		<dc:creator>Linn</dc:creator>
		<pubDate>Wed, 28 Mar 2007 18:06:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-flash-objects#comment-10943</guid>
		<description>Do you happen to have the codes or cheats to Ghost in the Shell: SAC? there are areas where I have trouble..</description>
		<content:encoded><![CDATA[<p>Do you happen to have the codes or cheats to Ghost in the Shell: SAC? there are areas where I have trouble..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/backdooring-flash-objects/comment-page-1/#comment-906</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Mon, 04 Dec 2006 02:48:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-flash-objects#comment-906</guid>
		<description>Frank, this is not really an exploit but a walkthrough how to backdoor flash movies. Depending on what attributes you are using in the object tag that contains the flash movie you get different results. It is that simple. The purpose of this article is show that flash movies can be trivially backdoored with freely available command line tools.

Your assumptions are right!</description>
		<content:encoded><![CDATA[<p>Frank, this is not really an exploit but a walkthrough how to backdoor flash movies. Depending on what attributes you are using in the object tag that contains the flash movie you get different results. It is that simple. The purpose of this article is show that flash movies can be trivially backdoored with freely available command line tools.</p>
<p>Your assumptions are right!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Frank Walsh</title>
		<link>http://www.gnucitizen.org/blog/backdooring-flash-objects/comment-page-1/#comment-899</link>
		<dc:creator>Frank Walsh</dc:creator>
		<pubDate>Sun, 03 Dec 2006 23:46:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-flash-objects#comment-899</guid>
		<description>I believe this exploit was addressed with the release of Flash 9 right? There was a way to circumvent the &lt;strong&gt;allowscriptaccess&lt;/strong&gt; tag using &lt;strong&gt;\n&lt;/strong&gt; to seperate the word javascript, but i believe that was also addressed in the flash 9 release, just wondering if i&#039;ve missed something or my assumption here is right? Could you let me know.

Thanks</description>
		<content:encoded><![CDATA[<p>I believe this exploit was addressed with the release of Flash 9 right? There was a way to circumvent the <strong>allowscriptaccess</strong> tag using <strong>\n</strong> to seperate the word javascript, but i believe that was also addressed in the flash 9 release, just wondering if i&#8217;ve missed something or my assumption here is right? Could you let me know.</p>
<p>Thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David Kierznowski</title>
		<link>http://www.gnucitizen.org/blog/backdooring-flash-objects/comment-page-1/#comment-31</link>
		<dc:creator>David Kierznowski</dc:creator>
		<pubDate>Tue, 05 Sep 2006 08:38:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/backdooring-flash-objects#comment-31</guid>
		<description>Nicely layed out and explained. Eyeonsecurity also released an article. A link to this paper can be found &lt;a href=&quot;http://www.cgisecurity.com/lib/flash-xss.htm&quot; rel=&quot;nofollow&quot;&gt;here&lt;/a&gt;.</description>
		<content:encoded><![CDATA[<p>Nicely layed out and explained. Eyeonsecurity also released an article. A link to this paper can be found <a href="http://www.cgisecurity.com/lib/flash-xss.htm" rel="nofollow">here</a>.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
