<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Encapsulating CSRF attacks inside massively distributed Flash movies &#8211; Real world example</title>
	<atom:link href="http://blog.guya.net/2008/09/14/encapsulating-csrf-attacks-inside-massively-distributed-flash-movies-real-world-example/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.guya.net/2008/09/14/encapsulating-csrf-attacks-inside-massively-distributed-flash-movies-real-world-example/</link>
	<description>Flash And Everything Else</description>
	<lastBuildDate>Thu, 11 Mar 2010 23:41:10 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Artiaga</title>
		<link>http://blog.guya.net/2008/09/14/encapsulating-csrf-attacks-inside-massively-distributed-flash-movies-real-world-example/comment-page-1/#comment-3280</link>
		<dc:creator>Artiaga</dc:creator>
		<pubDate>Thu, 11 Mar 2010 23:41:10 +0000</pubDate>
		<guid isPermaLink="false">http://blog.guya.net/2008/09/14/encapsulating-csrf-attacks-inside-massively-distributed-flash-movies-real-world-example/#comment-3280</guid>
		<description>I&#039;ve read sobe posts and i like your blog.I&#039;m just start8ng up my own and only hope that i can write as well , thanks!.;</description>
		<content:encoded><![CDATA[<p>I&#39;ve read sobe posts and i like your blog.I&#39;m just start8ng up my own and only hope that i can write as well , thanks!.;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: games</title>
		<link>http://blog.guya.net/2008/09/14/encapsulating-csrf-attacks-inside-massively-distributed-flash-movies-real-world-example/comment-page-1/#comment-3117</link>
		<dc:creator>games</dc:creator>
		<pubDate>Fri, 05 Mar 2010 15:06:33 +0000</pubDate>
		<guid isPermaLink="false">http://blog.guya.net/2008/09/14/encapsulating-csrf-attacks-inside-massively-distributed-flash-movies-real-world-example/#comment-3117</guid>
		<description>I&#039;ve read some posts and i like your blog.I&#039;m just starting up my own and only hope that i can write as well , thanks!.</description>
		<content:encoded><![CDATA[<p>I&#8217;ve read some posts and i like your blog.I&#8217;m just starting up my own and only hope that i can write as well , thanks!.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: High speed movies online</title>
		<link>http://blog.guya.net/2008/09/14/encapsulating-csrf-attacks-inside-massively-distributed-flash-movies-real-world-example/comment-page-1/#comment-3104</link>
		<dc:creator>High speed movies online</dc:creator>
		<pubDate>Fri, 05 Mar 2010 06:44:39 +0000</pubDate>
		<guid isPermaLink="false">http://blog.guya.net/2008/09/14/encapsulating-csrf-attacks-inside-massively-distributed-flash-movies-real-world-example/#comment-3104</guid>
		<description>Hey!  Very good post,I like it,I hope you&#039;ll continue doing great job!</description>
		<content:encoded><![CDATA[<p>Hey!  Very good post,I like it,I hope you&#8217;ll continue doing great job!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Making Money &#187; Blog Archive &#187; What are ways of making money for copyright and having a website?</title>
		<link>http://blog.guya.net/2008/09/14/encapsulating-csrf-attacks-inside-massively-distributed-flash-movies-real-world-example/comment-page-1/#comment-289</link>
		<dc:creator>Making Money &#187; Blog Archive &#187; What are ways of making money for copyright and having a website?</dc:creator>
		<pubDate>Tue, 25 Nov 2008 19:59:30 +0000</pubDate>
		<guid isPermaLink="false">http://blog.guya.net/2008/09/14/encapsulating-csrf-attacks-inside-massively-distributed-flash-movies-real-world-example/#comment-289</guid>
		<description>[...] GUYA.NET » Blog Archive » Encapsulating CSRF attacks inside &#8230; [...]</description>
		<content:encoded><![CDATA[<p>[...] GUYA.NET » Blog Archive » Encapsulating CSRF attacks inside &#8230; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: guya</title>
		<link>http://blog.guya.net/2008/09/14/encapsulating-csrf-attacks-inside-massively-distributed-flash-movies-real-world-example/comment-page-1/#comment-288</link>
		<dc:creator>guya</dc:creator>
		<pubDate>Mon, 22 Sep 2008 13:23:50 +0000</pubDate>
		<guid isPermaLink="false">http://blog.guya.net/2008/09/14/encapsulating-csrf-attacks-inside-massively-distributed-flash-movies-real-world-example/#comment-288</guid>
		<description>Adobe knows about this.
Again, all that is needed to make this kind of attack much less effective is to default the allowScriptAccess to &quot;never&quot;.

I guess Adobe don&#039;t wont to break any more existing applications for the sake of security. Every change in the behavior of an existing feature cause some applications to break and frustration for their developers.

Every Flash Player release gets more secure, similar to the browsers and most platforms. Apparently this fix won&#039;t get into the upcoming release of Flash 10 which already have its share of similar security updates, Maybe latter.

let me just clarify that CSRF flaws aren&#039;t Flash related, it relate to insecure website development. This is just an example of using Flash to elaborate such an attack and to make it more successful.</description>
		<content:encoded><![CDATA[<p>Adobe knows about this.<br />
Again, all that is needed to make this kind of attack much less effective is to default the allowScriptAccess to &#8220;never&#8221;.</p>
<p>I guess Adobe don&#8217;t wont to break any more existing applications for the sake of security. Every change in the behavior of an existing feature cause some applications to break and frustration for their developers.</p>
<p>Every Flash Player release gets more secure, similar to the browsers and most platforms. Apparently this fix won&#8217;t get into the upcoming release of Flash 10 which already have its share of similar security updates, Maybe latter.</p>
<p>let me just clarify that CSRF flaws aren&#8217;t Flash related, it relate to insecure website development. This is just an example of using Flash to elaborate such an attack and to make it more successful.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Infosec Update</title>
		<link>http://blog.guya.net/2008/09/14/encapsulating-csrf-attacks-inside-massively-distributed-flash-movies-real-world-example/comment-page-1/#comment-287</link>
		<dc:creator>Infosec Update</dc:creator>
		<pubDate>Mon, 22 Sep 2008 11:37:06 +0000</pubDate>
		<guid isPermaLink="false">http://blog.guya.net/2008/09/14/encapsulating-csrf-attacks-inside-massively-distributed-flash-movies-real-world-example/#comment-287</guid>
		<description>This is some scary stuff. Have you spoken to Adobe about this?</description>
		<content:encoded><![CDATA[<p>This is some scary stuff. Have you spoken to Adobe about this?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: CSRF attack through flash files</title>
		<link>http://blog.guya.net/2008/09/14/encapsulating-csrf-attacks-inside-massively-distributed-flash-movies-real-world-example/comment-page-1/#comment-286</link>
		<dc:creator>CSRF attack through flash files</dc:creator>
		<pubDate>Fri, 19 Sep 2008 09:31:57 +0000</pubDate>
		<guid isPermaLink="false">http://blog.guya.net/2008/09/14/encapsulating-csrf-attacks-inside-massively-distributed-flash-movies-real-world-example/#comment-286</guid>
		<description>[...] came across this interesting blog by guya. He has also provided working PoC alongwith. A nice explanation of this attack [...]</description>
		<content:encoded><![CDATA[<p>[...] came across this interesting blog by guya. He has also provided working PoC alongwith. A nice explanation of this attack [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: James</title>
		<link>http://blog.guya.net/2008/09/14/encapsulating-csrf-attacks-inside-massively-distributed-flash-movies-real-world-example/comment-page-1/#comment-285</link>
		<dc:creator>James</dc:creator>
		<pubDate>Fri, 19 Sep 2008 00:03:57 +0000</pubDate>
		<guid isPermaLink="false">http://blog.guya.net/2008/09/14/encapsulating-csrf-attacks-inside-massively-distributed-flash-movies-real-world-example/#comment-285</guid>
		<description>Hi, I found your blog on this new directory of WordPress Blogs at blackhatbootcamp.com/listofwordpressblogs.  I dont know how your blog came up, must have been a typo, i duno.  Anyways, I just clicked it and here I am.  Your blog looks good.  Have a nice day.  James.</description>
		<content:encoded><![CDATA[<p>Hi, I found your blog on this new directory of WordPress Blogs at blackhatbootcamp.com/listofwordpressblogs.  I dont know how your blog came up, must have been a typo, i duno.  Anyways, I just clicked it and here I am.  Your blog looks good.  Have a nice day.  James.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: guya</title>
		<link>http://blog.guya.net/2008/09/14/encapsulating-csrf-attacks-inside-massively-distributed-flash-movies-real-world-example/comment-page-1/#comment-284</link>
		<dc:creator>guya</dc:creator>
		<pubDate>Thu, 18 Sep 2008 13:19:17 +0000</pubDate>
		<guid isPermaLink="false">http://blog.guya.net/2008/09/14/encapsulating-csrf-attacks-inside-massively-distributed-flash-movies-real-world-example/#comment-284</guid>
		<description>As long as the allowScriptAccess is defaulted to &quot;sameDomain&quot; and not to &quot;never&quot; this kind of attack will work.

I havn&#039;t seen it&#039;s going to change in the upcoming Flash 10:
http://www.adobe.com/devnet/flashplayer/articles/fplayer10_security_changes.html

It&#039;ll work similarly on Flash Players 6, 7 when using the getURL(&#039;javascript:&#039;)
and with Flash Players 8, 9, 10 with ExternalInterface.call</description>
		<content:encoded><![CDATA[<p>As long as the allowScriptAccess is defaulted to &#8220;sameDomain&#8221; and not to &#8220;never&#8221; this kind of attack will work.</p>
<p>I havn&#8217;t seen it&#8217;s going to change in the upcoming Flash 10:<br />
<a href="http://www.adobe.com/devnet/flashplayer/articles/fplayer10_security_changes.html" rel="nofollow">http://www.adobe.com/devnet/flashplayer/articles/fplayer10_security_changes.html</a></p>
<p>It&#8217;ll work similarly on Flash Players 6, 7 when using the getURL(&#8216;javascript:&#8217;)<br />
and with Flash Players 8, 9, 10 with ExternalInterface.call</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Joeflash</title>
		<link>http://blog.guya.net/2008/09/14/encapsulating-csrf-attacks-inside-massively-distributed-flash-movies-real-world-example/comment-page-1/#comment-283</link>
		<dc:creator>Joeflash</dc:creator>
		<pubDate>Wed, 17 Sep 2008 21:20:12 +0000</pubDate>
		<guid isPermaLink="false">http://blog.guya.net/2008/09/14/encapsulating-csrf-attacks-inside-massively-distributed-flash-movies-real-world-example/#comment-283</guid>
		<description>Specifically what version(s) of the Flash Player were you testing against? This information is crucial to a complete understanding of the issue, which may enable Adobe to issue a security patch.</description>
		<content:encoded><![CDATA[<p>Specifically what version(s) of the Flash Player were you testing against? This information is crucial to a complete understanding of the issue, which may enable Adobe to issue a security patch.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
