Guide to the TechWeb Network


The InformationWeek -- Blogs
Security

Topics:   Security

  • Email this page E-mail this page
  • |  Print this page Print this page
  • |   Bookmark and Share

Adobe Flash Player Under Attack


Posted by George Hulme, May 28, 2008 12:03 PM

Security researchers are warning that an in-the-wild exploit within the Adobe Flash Player has been planted in from 20,000 to 250,000 Web pages. If that wide range of potentially affected Web pages isn't enough disparity for you, try this on: it's not entirely clear what versions of Flash are at risk. Read on...

The attacks started from sites hosting the exploits (attack code) in China. But once these things get rolling, the front line spreads everywhere.

First, if you're a Flash media player user, and haven't downloaded and applied the patch from Adobe released last month: Do so now. If you're not sure, check what version of Flash you're running (from the "About Flash") in each of your Firefox and Explorer browsers. I had to do this seven times this morning. The most recent version of Flash is available here.

Make sure you have version 9.0.124.0 or higher. (If you don't use Flash, go read Alex Wolfe's post on Joomia. Looks like really cool stuff.)

If you don't do these things, you run the risk of coming across a malicious SWF (Shockwave Flash) file, which could really happen from just about anywhere. That's one of the things that makes these types of attacks so risky. The attackers are currently attempting to install malware and Trojans on at-risk systems designed to pilfer passwords. But since these exploits are targeting a buffer overflow vulnerability (thanks for not checking your inputs, Mr. Adobe Developer), attackers could probably do whatever they so choose to your system.

At first, researchers thought this was a zero-day attack; now they're leaning toward the possibility that these attacks are targeting a flaw discovered and detailed by Mark Dowd at IBM a few weeks back.

Symantec offers a rather convoluted analysis of the vulnerability and attacks to date here. For those not interested in deconstructing these sort of events, the takeaway is that Symantec advises disabling or uninstalling Flash until this mess is sorted out. They also mention setting a kill bit on CLSID d27cdb6e-ae6d-11cf-96b8-444553540000. But setting kill bits requires adult supervision, and I wouldn't advise doing this unless you really know what you're doing.

If you're a Firefox user, consider installing NoScript. It's perfect for days like this.

« Windows 7 Shows Microsoft Hasn't Learned Vista Lessons | Main | In Your Face, Climate Alarmists »



Tomorrow's CIO: Do you have what it takes?
Find out at the 2008 InformationWeek 500 Conference
Sept. 14-16, St. Regis Resort, Monarch Beach, Calif.


Sign up now for the weekly InformationWeek Blog Newsletter.


This is a public forum. United Business Media and its affiliates are not responsible for and do not control what is posted herein. United Business Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.

Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of United Business Media LLC and may be edited and republished in print or electronic format as outlined in United Business Media's Terms of Service.

Important Note: This comment area is NOT intended for commercial messages or solicitations of business.






  1. Google Chrome: Browser Or Cloud Operating System?
  2. You Thought Vista Was Bad?
  3. Windows Vista: The OS About Nothing
  4. Apple Nixes 'Pull My Finger' App, Even Though It's A Gas
  5. Walt Mossberg Posts In-Depth Review Of Google's Chrome


  1. Microsoft Virtualization Products Due In Thirty Days
  2. Radical Desktops Deliver Power To The People. But What About IT?
  3. Need Disaster Recovery On The Cheap? Think Virtualization
  4. No Virtualizing Without A License
  5. Smart Stuff: The State Of Business Intelligence 2008
  6. Down To Business: Are Technology Leaders Focusing Too Much On The Small Stuff?

 
 

  Ars Technica
Boing Boing
Channel 9 Forums
CRN Blogs
Dr.Dobb's Portal: Blogs
Engadget
Gizmodo
GrokLaw
  Lifehacker
Schneier on Security
Slashdot
TechCrunch
Techdirt
Techmeme
Valleywag

  FEBRUARY 2008
JANUARY 2008
DECEMBER 2007
NOVEMBER 2007
OCTOBER 2007
SEPTEMBER 2007
AUGUST 2007
JULY 2007
  JUNE 2007
MAY 2007
APRIL 2007
MARCH 2007
FEBRUARY 2007
JANUARY 2007
DECEMBER 2006
NOVEMBER 2006