<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: BID 24856 - Flash Player SWF Vulnerability</title>
	<atom:link href="http://www.gnucitizen.org/blog/bid-24856-flash-player-swf-vulnerability/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/blog/bid-24856-flash-player-swf-vulnerability/</link>
	<description>Information Security Think Tank</description>
	<pubDate>Tue, 06 Jan 2009 18:53:07 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Â·Â¨-=[WHK]=-Â¨Â· &#187; Archive &#187; Vulnerabilidades en Flash Player permiten tomar el control total de un usuario afectado</title>
		<link>http://www.gnucitizen.org/blog/bid-24856-flash-player-swf-vulnerability/comment-page-1/#comment-43086</link>
		<dc:creator>Â·Â¨-=[WHK]=-Â¨Â· &#187; Archive &#187; Vulnerabilidades en Flash Player permiten tomar el control total de un usuario afectado</dc:creator>
		<pubDate>Sat, 25 Aug 2007 05:11:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/bid-24856-flash-player-swf-vulnerability#comment-43086</guid>
		<description>[...] Adobe Flash Player 9.0.28.0 Adobe Flash Player 8.0.34.0 Adobe Flash Player 7.0.69.0 Fuentes: http://www.gnucitizen.org/blog/bid-24856-flash-player-swf-vulnerability  http://www.securityfocus.com/bid/24856  [...]</description>
		<content:encoded><![CDATA[<p>[...] Adobe Flash Player 9.0.28.0 Adobe Flash Player 8.0.34.0 Adobe Flash Player 7.0.69.0 Fuentes: <a href="http://www.gnucitizen.org/blog/bid-24856-flash-player-swf-vulnerability" rel="nofollow">http://www.gnucitizen.org/blog.....nerability</a>  <a href="http://www.securityfocus.com/bid/24856" rel="nofollow">http://www.securityfocus.com/bid/24856</a>  [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ascii</title>
		<link>http://www.gnucitizen.org/blog/bid-24856-flash-player-swf-vulnerability/comment-page-1/#comment-37583</link>
		<dc:creator>ascii</dc:creator>
		<pubDate>Sat, 28 Jul 2007 22:50:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/bid-24856-flash-player-swf-vulnerability#comment-37583</guid>
		<description>@Giorgio Maone: let me see... thanks for your understanding, responsible disclosure MEANS that "it WAS big", if not it's not responsible disclosure.</description>
		<content:encoded><![CDATA[<p>@Giorgio Maone: let me see&#8230; thanks for your understanding, responsible disclosure MEANS that &#8220;it WAS big&#8221;, if not it&#8217;s not responsible disclosure.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Awesome AnDrEw</title>
		<link>http://www.gnucitizen.org/blog/bid-24856-flash-player-swf-vulnerability/comment-page-1/#comment-37430</link>
		<dc:creator>Awesome AnDrEw</dc:creator>
		<pubDate>Sat, 28 Jul 2007 02:59:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/bid-24856-flash-player-swf-vulnerability#comment-37430</guid>
		<description>Lovely example, but I wouldn't necessarily get too crazy on making the Nintendo Wii crash as it's easily done simply browsing normal pages. This is a pretty cool idea though seeing as how most services now use Flash players supporting the FLV file format, and generally use some shotty script to get the URL of the media from a variable in the address.</description>
		<content:encoded><![CDATA[<p>Lovely example, but I wouldn&#8217;t necessarily get too crazy on making the Nintendo Wii crash as it&#8217;s easily done simply browsing normal pages. This is a pretty cool idea though seeing as how most services now use Flash players supporting the FLV file format, and generally use some shotty script to get the URL of the media from a variable in the address.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio Maone</title>
		<link>http://www.gnucitizen.org/blog/bid-24856-flash-player-swf-vulnerability/comment-page-1/#comment-36757</link>
		<dc:creator>Giorgio Maone</dc:creator>
		<pubDate>Mon, 23 Jul 2007 22:38:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/bid-24856-flash-player-swf-vulnerability#comment-36757</guid>
		<description>@Stefano: 
I agree on the impact of slow patch deployment on mobile devices, and I've been already contacted for some NoScript portings, actually.

Again thanks for the responsible disclosure and for your detailed and enjoyable advisory.
--
Thereâ€™s a browser safer than Firefoxâ€¦ http://noscript.net</description>
		<content:encoded><![CDATA[<p>@Stefano:<br />
I agree on the impact of slow patch deployment on mobile devices, and I&#8217;ve been already contacted for some NoScript portings, actually.</p>
<p>Again thanks for the responsible disclosure and for your detailed and enjoyable advisory.<br />
&#8211;<br />
Thereâ€™s a browser safer than Firefoxâ€¦ <a href="http://noscript.net" rel="nofollow">http://noscript.net</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/bid-24856-flash-player-swf-vulnerability/comment-page-1/#comment-36749</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Mon, 23 Jul 2007 21:54:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/bid-24856-flash-player-swf-vulnerability#comment-36749</guid>
		<description>Giorgio, Stefano is right. It will take some time to upgrade all flash instances. So, the bug is very serious. In fact, I am sure that someone will take it and make into a worm of some sort. BTW, 10x to Stefano and his team responsible disclosure the impact is a lot less significant.

Stefano, always. The research is worthed.</description>
		<content:encoded><![CDATA[<p>Giorgio, Stefano is right. It will take some time to upgrade all flash instances. So, the bug is very serious. In fact, I am sure that someone will take it and make into a worm of some sort. BTW, 10x to Stefano and his team responsible disclosure the impact is a lot less significant.</p>
<p>Stefano, always. The research is worthed.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stefano</title>
		<link>http://www.gnucitizen.org/blog/bid-24856-flash-player-swf-vulnerability/comment-page-1/#comment-36709</link>
		<dc:creator>Stefano</dc:creator>
		<pubDate>Mon, 23 Jul 2007 16:19:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/bid-24856-flash-player-swf-vulnerability#comment-36709</guid>
		<description>@Giorgio, 
even if there's a Flash player/plugin new version think about wii or smart phones with flash lite installed....
when vendors will fix it with an update?
 
@Pdp, thank for you kind words and for this blog entry!:)</description>
		<content:encoded><![CDATA[<p>@Giorgio,<br />
even if there&#8217;s a Flash player/plugin new version think about wii or smart phones with flash lite installed&#8230;.<br />
when vendors will fix it with an update?</p>
<p>@Pdp, thank for you kind words and for this blog entry!:)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio Maone</title>
		<link>http://www.gnucitizen.org/blog/bid-24856-flash-player-swf-vulnerability/comment-page-1/#comment-36691</link>
		<dc:creator>Giorgio Maone</dc:creator>
		<pubDate>Mon, 23 Jul 2007 14:31:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/bid-24856-flash-player-swf-vulnerability#comment-36691</guid>
		<description>OK, I had a chance to watch the Symantec video and finally realized how really scary this bug was.

The video starts with "Example 1: Windows with Firefox", but even before they open the compromised FLV, the attack has already transformed Firefox into Internet Explorer 6 for better exploitation, OMG!!!
--
Thereâ€™s a browser safer than Firefoxâ€¦ http://noscript.net</description>
		<content:encoded><![CDATA[<p>OK, I had a chance to watch the Symantec video and finally realized how really scary this bug was.</p>
<p>The video starts with &#8220;Example 1: Windows with Firefox&#8221;, but even before they open the compromised FLV, the attack has already transformed Firefox into Internet Explorer 6 for better exploitation, OMG!!!<br />
&#8211;<br />
Thereâ€™s a browser safer than Firefoxâ€¦ <a href="http://noscript.net" rel="nofollow">http://noscript.net</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/bid-24856-flash-player-swf-vulnerability/comment-page-1/#comment-36686</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Mon, 23 Jul 2007 13:51:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/bid-24856-flash-player-swf-vulnerability#comment-36686</guid>
		<description>Giorgio,

you are right. Never the less I though it might be a good idea to mention the bug and also point out where the credits are due. :)</description>
		<content:encoded><![CDATA[<p>Giorgio,</p>
<p>you are right. Never the less I though it might be a good idea to mention the bug and also point out where the credits are due. :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio Maone</title>
		<link>http://www.gnucitizen.org/blog/bid-24856-flash-player-swf-vulnerability/comment-page-1/#comment-36676</link>
		<dc:creator>Giorgio Maone</dc:creator>
		<pubDate>Mon, 23 Jul 2007 12:07:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/bid-24856-flash-player-swf-vulnerability#comment-36676</guid>
		<description>Not to play the devil's advocate, but "it WAS big".

Stefano and Giorgio did responsible disclosure, thus the Flash Player plugin registered in my default Firefox profile (version 9.0r47) is not vulnerable.

Since, let me see... July 10th 2007... 13 days now?

Anyway Minded Security's advisory is very worth reading, many thanks for the pointer :)
--
There's a browser safer than Firefox... http://noscript.net</description>
		<content:encoded><![CDATA[<p>Not to play the devil&#8217;s advocate, but &#8220;it WAS big&#8221;.</p>
<p>Stefano and Giorgio did responsible disclosure, thus the Flash Player plugin registered in my default Firefox profile (version 9.0r47) is not vulnerable.</p>
<p>Since, let me see&#8230; July 10th 2007&#8230; 13 days now?</p>
<p>Anyway Minded Security&#8217;s advisory is very worth reading, many thanks for the pointer :)<br />
&#8211;<br />
There&#8217;s a browser safer than Firefox&#8230; <a href="http://noscript.net" rel="nofollow">http://noscript.net</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>
