June 16, 2002

Flash Player Cross Server Scripting Security Issue

As reported on the 5th of June 2002 in a paper from Eyes On Security (Bypassing JavaScript Filters - the Flash! Attack), Flash SWF content can allow malicious users of web sites that allow users to upload or include SWF...

Read more about Flash Player Cross Server Scripting Security Issue

Posted by jarle at 11:44 PM
June 11, 2002

Flash Cross-site scripting attack

Eyes on security has released a warning about Cross-site scripting attacks made possible on sites that allow uploadable files - Bypassing JavaScript Filters - the Flash way Basically, if you have a forum or pages where you allow users to...

Read more about Flash Cross-site scripting attack

Posted by jarle at 08:04 PM
May 27, 2002

Opera not so safe after all

Opera is a browser that I have often mentioned whenever vulnerabilities in Internet Explorer has been published (which happens a lot more often than I comment on it, but thats a digression). But all was not good in the paradise...

Read more about Opera not so safe after all

Posted by jarle at 11:33 PM | Comments (2)
May 16, 2002

More Internet Explorer vulnerabilities

If you are a Windows/Internet Explorer user, please pay attention. Quote from the Technote: Impact of vulnerability: Six new vulnerabilities, the most serious of which could allow code of attacker's choice to run. Solution? Get the 2 MB security fix...

Read more about More Internet Explorer vulnerabilities

Posted by jarle at 11:30 PM
May 05, 2002

ActiveX flaw exposes Flash users to hacks

Via Flazoom: ActiveX flaw exposes Flash users to hacks ZDNet writes about a buffer overflow vulnerability in the previous version of the Flash 6 player (revision 23), the overflow allows for attacks via some HTML e-mail clients and when visiting...

Read more about ActiveX flaw exposes Flash users to hacks

Posted by jarle at 03:15 AM
April 18, 2002

More security problems found in IE

If you are using Internet Explorer as your browser, using the back button could expose you to malicious code. Microsofts reaction? «because the proposed exploit scenario is dependent upon specific user interaction as a prerequisite, it does not meet our...

Read more about More security problems found in IE

Posted by jarle at 04:00 AM