Hacker Newsnew | comments | ask | jobs | submitlogin
Zero-day Flash exploit on all platforms, fix two weeks out (adobe.com)
171 points by vl 530 days ago | comments


bl4k 530 days ago | link

the best thing I have done recently is to disable all plugins, including flash:

http://imgur.com/mCfqQ.png

YouTube HTML5 support is good, and for any other video you can directly download. Browser runs a lot faster, web pages load faster, and I don't miss flash ads at all.

I also disabled flash on my parents' computer, and my brothers, and enabled YouTube HTML5 for them. They haven't noticed it yet. It is only a matter of time before more corporate networks uninstall/block all flash, especially with the bad reputation it has with security.

Flash is already dead to me, I can't wait until it is dead for everybody else as well

-----

agazso 530 days ago | link

Use Flashblock or something similar. By default Flash objects are turned off, but you can click on them to enable.

Firefox: https://addons.mozilla.org/en-US/firefox/addon/433/

Chrome: https://chrome.google.com/extensions/detail/cdngiadmnkhgemki...

-----

bl4k 530 days ago | link

As I mentioned below, I had Flashblock, and used it for a while until I noticed that Flash is still in memory and Flashblock is just some JS that hides flash elements.

Killing everything is much better.

-----

bgentry 530 days ago | link

I used the following FlashBlock for Chrome, and using resource tracker I could see that no SWFs were downloaded on a YouTube page until after I temporarily enabled Flash on that page.

https://chrome.google.com/extensions/detail/gofhjkjmkpinhpoi...

Is that good enough proof that the SWF is not put into memory?

Also, the FlashBlockBlock page here does not load when I have the extension enabled: https://woofle.net/flashblockblock/

-----

flatulent1 530 days ago | link

Note - The title is misleading. It's a zero day vulnerability on all platforms, but the exploits hit XP Vista and W7. It's still prudent to kill Flash on all though.

http://www.theregister.co.uk/2010/09/13/adobe_flash_0day_vul...

It is easy to turn off Flash in the Firefox plugins, and running the Better Privacy extension which kills the Flash hidden cookies normal cookie management doesn't touch. (One stalks you keeping track of every site you've visited with Flash) Better Privacy isn't yet compatible with the Firefox 4 beta but is fine with 3.x

NoScript is still a good idea for many reasons.

The malware is worse this year than last... http://www.gdatasoftware.co.uk/about-g-data/press-centre/new...

-----

blasdel 530 days ago | link

Yes, extensions named 'Flashblock' are pretty universally mediocre and don't actually keep Flash from crashing your browser — they just keep it from being displayed.

ClickToFlash for native Webkit views on OS X actually blocks Flash for real — it's a native Webkit plugin that registers for Flash's primary mimetype and preempts it. When you selectively enable a flash embed, it replaces itself with Adobe's NPAPI plugin.

-----

wtallis 530 days ago | link

Using NoScript is probably best. It actually blocks Flash content properly, and protects against most other browsing-related vulnerabilities. Plus, if you don't allow scripts to run from advertiser's domains, most ads can't load.

-----

bhiggins 530 days ago | link

I don't know what Flashblock you were using but the ones I have used do not behave this way. Maybe Flash was in memory because you clicked one of them and allowed it to run?

-----

ja27 530 days ago | link

On last months zero-day Flash exploit thread, someone linked to a demo that shows bypassing Flashblock. I think this is it (but I don't run Flashblock).

[EDIT: Note: I don't know how safe the link in this article is.] http://seclists.org/fulldisclosure/2008/Jul/444

-----

duskwuff 530 days ago | link

Here's a simple proof of concept I wrote a while back that bypasses Firefox FlashBlock: https://woofle.net/flashblockblock/

The payload is harmless but silly.

-----

ciupicri 530 days ago | link

Is it to me or the Quicktime plugin is still enabled and it even has a critical security update?

-----

ja27 530 days ago | link

I did that for a while but had issues like really needing Flash on a couple sites and the fact that every Flash or PDF update would re-enable their plugins in Chrome.

Now instead of disabling individual plugins, now in Chrome I do not allow any site to use plugins, then go back and whitelist sites as needed.

-----

aw3c2 530 days ago | link

Why not completely uninstall them instead?

-----

frou_dh 530 days ago | link

IIRC Google helpfully embed Flash inside Chrome

-----

loumf 530 days ago | link

Use the kill-flash extension for Chrome. It takes off flash elements and replaces them with a zone to click on if you want to bring it back. It has a whitelist that you can use for sites that you want flash on by default.

-----

bl4k 530 days ago | link

Flash is still in memory, and those plugins use Javascript to 'hide' the applet

-----

olalonde 530 days ago | link

I had to turn Flash back on after a few minutes after I realized that Google Analytics charts are Flash based :(

-----

swombat 530 days ago | link

To be fair, these things happen to many other platforms. Adobe's no exception. Two weeks seems a bit on the slow side from our hacker point of view, but it is in line with what you tend to get from large corporations (and actually fairly responsive... this would be a good response time for, say, Internet Explorer - and Flash has more installs on a much wider variety of OSes and hardware than IE).

Let's not all gang up on Adobe just because they're, well, just as bad as everyone else.

-----

raganwald 530 days ago | link

What is this "ganging up" you are speaking of? All I can see as of this moment are people making true statements about Adobe Flash's vulnerabilities, expressing their personal opinions about using Flash, sharing tips for avoiding or disabling Flash, and so on.

As for the two weeks, it sounds like you are saying that the appropriate response to being told that you have to stand in line a day to buy bread is to shrug your shoulders since you're already standing in line a day to buy milk.

-----

DavidBishop 530 days ago | link

Yes, but they happen on "other" platforms. Not "ALL" platforms.

I think there are too many developers out there in large and small companies that don't understand they power they wield or the responsibility they have.

I'm not a big fan of Flash. It had it's day. It wants to be everywhere, but it doesn't have the track record to be safe everywhere. I recently switched to Mac and have 3 (and only 3) crashes... all in Safari and all due to Flash.

I'm all for a company making a great product and making it prolific. I just want that company to have the integrity and follow through to make it right. After all, when an exploit takes over my machine who's out the time and money?

-----

IgorPartola 530 days ago | link

The trouble with Flash is that it is so ubiquitous. If Firefox gets a critical zero-day vulnerability, I'll use Chrome. If Chrome does, I'll use Firefox. With a Flash vulnerability over 90% of computers on the web are susceptible and there is no alternative.

-----

jrockway 530 days ago | link

I haven't had Flash installed since that first vulnerability where Adobe pulled support for x86_64 Linux. The web looks the same. (I used Adblock anyway.)

Yeah, some Youtube videos don't work... but you can get those videos elsewhere.

-----

IgorPartola 530 days ago | link

How about things like Google Analytics? Do you miss tools like that?

-----

jrockway 530 days ago | link

Never used it. I think spying on my users (with the help of Google) is unethical.

(FWIW, I did do a project for a client once which involved extracting data via the Analytics API. It was very easy to do, and all the metrics were there, so it seems possible to make your own chart without requiring Flash. Hell, there is even an in-browser Javascript Analytics API and many in-browser Javascript charting libraries... so you could probably even do this in the form of a bookmarklet or user script!)

-----

IgorPartola 530 days ago | link

Heh, spying is a strong word. Without GA I would have had a harder time figuring out that more of my users are from Spain than from the US for one of my projects.

Thanks for the info. I knew of their API but haven't used it yet.

-----

drinian 530 days ago | link

Please enumerate some of these "other platforms."

Cannot cite IE (too obvious), or Reader (also Adobe).

-----

swombat 530 days ago | link

Apple: http://www.engadget.com/2009/07/02/apple-patching-nasty-ipho... ("fix by the end of this month")

Google: http://seclists.org/webappsec/2006/q1/66 (6+ months)

I'm sure you can find more of them by searching for them (as I just did).

-----

tptacek 530 days ago | link

It would be a more interesting challenge to name a vendor who isn't routinely issuing security advisories. I can't think of any.

-----

jacquesm 530 days ago | link

Because you asked:

http://www.google.com/search?q=java+zero+day+exploit

-----

colonelxc 530 days ago | link

Finally, something that works on flash in linux!

I jest, but flash is the perfect target if you want to hit multiple OS's. Doesn't mean the malware authors will actually develop exploits/malcode for multiple OS's though.

-----

jakevoytko 530 days ago | link

Viruses that target multiple machines may not be as ridiculous as they sound. At least one researcher has a proof-of-concept that works on multiple platforms: http://www.wired.com/science/discoveries/news/2001/03/42672

As an aside, the alpha releases for Flash on Linux are surprisingly stable. The "gray rectangle" problem appears to be solved, which was the worst part of Flash on Linux in years past. Video streaming works well, but animations flicker and tear, so most online games are still unplayable.

-----

TallGuyShort 530 days ago | link

Thanks for that link - I'm enjoying the article.

I'm surprised to be reading so much talk about Flash not working very well on Linux. I'm using Fedora 13 (previously Ubuntu) on an extremely low-performance machine, and I haven't seen any problems in a very long time (at least a year). Video's, games, etc... all seem to work fine, and I generally pay a lot of attention to the Flash player because I'm a flex developer. The only time I struggle is when I watch HD video, but that's to be expected on my machine even if I'm watching a DVD.

-----

pmjordan 530 days ago | link

Yeah, I haven't encountered much in the way of compatibility problems since 10.0 was released. (I'm on OpenSUSE x86-64.) It does have a habit of crashing and/or freezing for some time, I get the impression the latter is connected to sound (ALSA). Modern browsers survive the former quite well, luckily, and everything but Firefox recovers from the latter quickly, too.

One thing that seems to reliably fail is full-screen video, though.

-----

sjtgraham 530 days ago | link

Safari OS X users, may I recommend ClickToFlash for the time being.

http://clicktoflash.com/

-----

frou_dh 530 days ago | link

Great recommendation, but I'd say the torch has been passed to the bona fide Safari extension of the same name:

http://www.math.northwestern.edu/~hoyois/safariextensions/cl...

-----

isani 530 days ago | link

One benefit that the original ClickToFlash has compared to the extension is that it works with web content embedded in applications other than Safari.

-----

rwmj 530 days ago | link

Just disable all plug-ins & Java in Safari preferences. It's a lot easier and you won't miss them. The only thing I used Flash for was watching videos, and HTML5 has that mostly covered now.

-----

shib71 530 days ago | link

Their openness about the vulnerability is refreshing. But I assume they're only publicising the vulnerability because of the people already exploiting it.

-----

rbanffy 530 days ago | link

> But I assume they're only publicising the vulnerability because of the people already exploiting it.

That and someone notified them it exists.

Were it only a vulnerability they could deny knowing, they would keep silent about it.

-----

mhw 530 days ago | link

I upgraded Flash on my old laptop just yesterday. The pain and misdirection of being pushed through installing the Adobe Download Manager extension, then restarting the browser in order to actually update the plugin, seems like enough of an obstacle to significantly slow down the roll-out of the eventual fix.

-----

prawn 530 days ago | link

Their forcing of the download manager app (painful trying to find an alternate download to upgrade Flash) should be a key reason for people to abandon the platform.

-----

chadgeidel 530 days ago | link

Nothing burns me up more than vendor-provided "download/update managers". I'll keep my app updated myself thank you very much. No, you don't actually need to run your program 24-7 when it's only used once every few months on my machine.

Just thinking about it makes my blood pressure rise.

(Yes, I know I can go back and uninstall the download manager, but now there are 2 of them - one specifically for IE/ActiveX and the one for Firefox that they recently created).

-----

frou_dh 530 days ago | link

I think Java trying to install the Yahoo Toolbar beat that. So trashy, I couldn't believe it.

-----

JoeAltmaier 530 days ago | link

Yahoo toolbar crosses the line - its a virus now, or at least mal-ware.

-----

drinian 530 days ago | link

I uninstalled Flash three months ago, and haven't encountered any serious problems. I have Greasemonkey scripts to let me download video from most of the YouTube-like sites.

-----

zackattack 530 days ago | link

please share said scripts

-----

drinian 529 days ago | link

I'm not a heavy video watcher, so --

YouTube: http://userscripts.org/scripts/show/62634 Vimeo: http://userscripts.org/scripts/show/56677

Neither of these scripts requires a third-party site.

-----

acqq 530 days ago | link

Not just Flash -- it's an all-platforms Flash and all-platforms Reader vulnerability plus the Flash exploit for Windows in the wild!

I beleive we can soon expect Reader exploits too.

-----

blasdel 530 days ago | link

The Reader exploits probably involve a PDF with embedded Flash.

Synergy!

-----

gojomo 530 days ago | link

Note that running the Adobe Flash Player uninstaller may not disable Flash in Google Chrome (which integrates a separate Flash). You need to use the 'chrome://plugins' manager to disable that Flash Player. See here for details:

http://www.google.com/support/forum/p/Chrome/thread?tid=1095...

-----

Jach 530 days ago | link

Can anyone explain some motivations behind Adobe continuing to keep the flash player closed source? The only reasonable thing I've heard before was about movie codecs, is there anything else? The Flex SDK is open, they're not exactly stellar on performance, several different SWF decoders work okay for some narrow subset... I doubt there's much in there that's top secret or thesis-worthy. Releasing it to the community would go a long way in improving Adobe's standings as well as letting the community fix these (in say one week rather than two) and work on 64-bit versions or performance...

-----

aniket_ray 530 days ago | link

The VM is open source, the frameworks are open source. The language specification is open.

The only thing closed are codecs (many of which are licensed from other companies and can't be open sourced), DRM stuff and platform level code that glues everything together. On the other hand, there are open source versions of swf players that Adobe actively promote.

Unfortunately, community involvement (developers and early testers) in all these projects have been low. My understanding is that people within Adobe (and there are many who like Open Source) have no evidence that open sourcing more stuff is any better for the player, since the community hardly gets involved.

Adobe did launch a 64-bit Linux flash player on Labs. Most 64 bit users never used it, sticking with the nspluginwrapper method instead.

I'm sure more community involvement with existing open source projects at Adobe would pave the way for opening up of more stuff.

-----

blasdel 530 days ago | link

They open sourced the parts that have been solid for years. What's always been a huge problem is the runtime — the implementation of the standard library. It's it's mostly the same across all platforms and more than just 'glue code', it's what's actually using most of the CPU cycles when a Flash applet executes, it's all native code, and it's not sandboxed at all by most browsers.

-----

smackfu 530 days ago | link

You don't think it is easier to find code bugs to exploit if you have the source?

-----

More



Lists | RSS | Bookmarklet | Guidelines | FAQ | News News | Feature Requests | Y Combinator | Apply | Library

Search: