<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Encapsulating CSRF attacks inside massively distributed Flash movies &#8211; Real world example</title>
	<atom:link href="http://blog.guya.net/2008/09/14/encapsulating-csrf-attacks-inside-massively-distributed-flash-movies-real-world-example/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.guya.net/2008/09/14/encapsulating-csrf-attacks-inside-massively-distributed-flash-movies-real-world-example/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=encapsulating-csrf-attacks-inside-massively-distributed-flash-movies-real-world-example</link>
	<description>Flash and Everything Else</description>
	<lastBuildDate>Sun, 11 Dec 2011 07:35:16 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: restaurant lille</title>
		<link>http://blog.guya.net/2008/09/14/encapsulating-csrf-attacks-inside-massively-distributed-flash-movies-real-world-example/#comment-329</link>
		<dc:creator>restaurant lille</dc:creator>
		<pubDate>Fri, 25 Mar 2011 00:34:26 +0000</pubDate>
		<guid isPermaLink="false">http://blog.guya.net/2008/09/14/encapsulating-csrf-attacks-inside-massively-distributed-flash-movies-real-world-example/#comment-329</guid>
		<description>hmm nice article thank you for sharing her give my appetite want to read again and again ^ ^ my restaurant&gt;&gt; &lt;a href=&quot;http://restaurant.lille.free.fr&quot; rel=&quot;nofollow&quot;&gt;restaurant lille&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>hmm nice article thank you for sharing her give my appetite want to read again and again ^ ^ my restaurant&gt;&gt; <a href="http://restaurant.lille.free.fr" rel="nofollow">restaurant lille</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: making up</title>
		<link>http://blog.guya.net/2008/09/14/encapsulating-csrf-attacks-inside-massively-distributed-flash-movies-real-world-example/#comment-328</link>
		<dc:creator>making up</dc:creator>
		<pubDate>Wed, 16 Mar 2011 05:10:36 +0000</pubDate>
		<guid isPermaLink="false">http://blog.guya.net/2008/09/14/encapsulating-csrf-attacks-inside-massively-distributed-flash-movies-real-world-example/#comment-328</guid>
		<description>Need to find more insight the the mind of the ex-girlfriend I think. Anyhow well done.</description>
		<content:encoded><![CDATA[<p>Need to find more insight the the mind of the ex-girlfriend I think. Anyhow well done.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: making up</title>
		<link>http://blog.guya.net/2008/09/14/encapsulating-csrf-attacks-inside-massively-distributed-flash-movies-real-world-example/#comment-327</link>
		<dc:creator>making up</dc:creator>
		<pubDate>Wed, 16 Mar 2011 05:10:02 +0000</pubDate>
		<guid isPermaLink="false">http://blog.guya.net/2008/09/14/encapsulating-csrf-attacks-inside-massively-distributed-flash-movies-real-world-example/#comment-327</guid>
		<description>Is getting back with the ex-wife wise? What made you leave is still there.</description>
		<content:encoded><![CDATA[<p>Is getting back with the ex-wife wise? What made you leave is still there.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ex-girlfriend</title>
		<link>http://blog.guya.net/2008/09/14/encapsulating-csrf-attacks-inside-massively-distributed-flash-movies-real-world-example/#comment-326</link>
		<dc:creator>ex-girlfriend</dc:creator>
		<pubDate>Wed, 16 Mar 2011 05:09:39 +0000</pubDate>
		<guid isPermaLink="false">http://blog.guya.net/2008/09/14/encapsulating-csrf-attacks-inside-massively-distributed-flash-movies-real-world-example/#comment-326</guid>
		<description>Well done. I agree mostly with what you say. I think people go about making up because of always only remembering the good times.</description>
		<content:encoded><![CDATA[<p>Well done. I agree mostly with what you say. I think people go about making up because of always only remembering the good times.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jobs in graphic design</title>
		<link>http://blog.guya.net/2008/09/14/encapsulating-csrf-attacks-inside-massively-distributed-flash-movies-real-world-example/#comment-325</link>
		<dc:creator>jobs in graphic design</dc:creator>
		<pubDate>Thu, 17 Feb 2011 16:16:42 +0000</pubDate>
		<guid isPermaLink="false">http://blog.guya.net/2008/09/14/encapsulating-csrf-attacks-inside-massively-distributed-flash-movies-real-world-example/#comment-325</guid>
		<description>I unquestionably accept as true with what you have stated. In reality, I browsed through your additional content articles and I do believe you are completely correct. Great job with this particular site.</description>
		<content:encoded><![CDATA[<p>I unquestionably accept as true with what you have stated. In reality, I browsed through your additional content articles and I do believe you are completely correct. Great job with this particular site.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: String</title>
		<link>http://blog.guya.net/2008/09/14/encapsulating-csrf-attacks-inside-massively-distributed-flash-movies-real-world-example/#comment-324</link>
		<dc:creator>String</dc:creator>
		<pubDate>Thu, 20 Jan 2011 13:29:42 +0000</pubDate>
		<guid isPermaLink="false">http://blog.guya.net/2008/09/14/encapsulating-csrf-attacks-inside-massively-distributed-flash-movies-real-world-example/#comment-324</guid>
		<description>Great article! This is a really good blog! Thank you! You&#039;ll find more informations on &lt;a href=&quot;http://www.lingerie-de-charme.net&quot; rel=&quot;nofollow&quot;&gt;Lingerie de charme&lt;/a&gt;. There&#039;s everything that you need!</description>
		<content:encoded><![CDATA[<p>Great article! This is a really good blog! Thank you! You&#8217;ll find more informations on <a href="http://www.lingerie-de-charme.net" rel="nofollow">Lingerie de charme</a>. There&#8217;s everything that you need!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Making Money &#187; Blog Archive &#187; What are ways of making money for copyright and having a website?</title>
		<link>http://blog.guya.net/2008/09/14/encapsulating-csrf-attacks-inside-massively-distributed-flash-movies-real-world-example/#comment-323</link>
		<dc:creator>Making Money &#187; Blog Archive &#187; What are ways of making money for copyright and having a website?</dc:creator>
		<pubDate>Tue, 25 Nov 2008 19:59:30 +0000</pubDate>
		<guid isPermaLink="false">http://blog.guya.net/2008/09/14/encapsulating-csrf-attacks-inside-massively-distributed-flash-movies-real-world-example/#comment-323</guid>
		<description>[...] GUYA.NET » Blog Archive » Encapsulating CSRF attacks inside &#8230; [...] </description>
		<content:encoded><![CDATA[<p>[...] GUYA.NET » Blog Archive » Encapsulating CSRF attacks inside &#8230; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: guya</title>
		<link>http://blog.guya.net/2008/09/14/encapsulating-csrf-attacks-inside-massively-distributed-flash-movies-real-world-example/#comment-322</link>
		<dc:creator>guya</dc:creator>
		<pubDate>Mon, 22 Sep 2008 13:23:50 +0000</pubDate>
		<guid isPermaLink="false">http://blog.guya.net/2008/09/14/encapsulating-csrf-attacks-inside-massively-distributed-flash-movies-real-world-example/#comment-322</guid>
		<description>Adobe knows about this.
Again, all that is needed to make this kind of attack much less effective is to default the allowScriptAccess to &quot;never&quot;.

I guess Adobe don&#039;t wont to break any more existing applications for the sake of security. Every change in the behavior of an existing feature cause some applications to break and frustration for their developers.

Every Flash Player release gets more secure, similar to the browsers and most platforms. Apparently this fix won&#039;t get into the upcoming release of Flash 10 which already have its share of similar security updates, Maybe latter.

let me just clarify that CSRF flaws aren&#039;t Flash related, it relate to insecure website development. This is just an example of using Flash to elaborate such an attack and to make it more successful.</description>
		<content:encoded><![CDATA[<p>Adobe knows about this.<br />
Again, all that is needed to make this kind of attack much less effective is to default the allowScriptAccess to &#8220;never&#8221;.</p>
<p>I guess Adobe don&#8217;t wont to break any more existing applications for the sake of security. Every change in the behavior of an existing feature cause some applications to break and frustration for their developers.</p>
<p>Every Flash Player release gets more secure, similar to the browsers and most platforms. Apparently this fix won&#8217;t get into the upcoming release of Flash 10 which already have its share of similar security updates, Maybe latter.</p>
<p>let me just clarify that CSRF flaws aren&#8217;t Flash related, it relate to insecure website development. This is just an example of using Flash to elaborate such an attack and to make it more successful.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Infosec Update</title>
		<link>http://blog.guya.net/2008/09/14/encapsulating-csrf-attacks-inside-massively-distributed-flash-movies-real-world-example/#comment-321</link>
		<dc:creator>Infosec Update</dc:creator>
		<pubDate>Mon, 22 Sep 2008 11:37:06 +0000</pubDate>
		<guid isPermaLink="false">http://blog.guya.net/2008/09/14/encapsulating-csrf-attacks-inside-massively-distributed-flash-movies-real-world-example/#comment-321</guid>
		<description>This is some scary stuff. Have you spoken to Adobe about this?</description>
		<content:encoded><![CDATA[<p>This is some scary stuff. Have you spoken to Adobe about this?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: CSRF attack through flash files</title>
		<link>http://blog.guya.net/2008/09/14/encapsulating-csrf-attacks-inside-massively-distributed-flash-movies-real-world-example/#comment-320</link>
		<dc:creator>CSRF attack through flash files</dc:creator>
		<pubDate>Fri, 19 Sep 2008 09:31:57 +0000</pubDate>
		<guid isPermaLink="false">http://blog.guya.net/2008/09/14/encapsulating-csrf-attacks-inside-massively-distributed-flash-movies-real-world-example/#comment-320</guid>
		<description>[...] came across this interesting blog by guya. He has also provided working PoC alongwith. A nice explanation of this attack [...] </description>
		<content:encoded><![CDATA[<p>[...] came across this interesting blog by guya. He has also provided working PoC alongwith. A nice explanation of this attack [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

