{"id":638,"date":"2008-03-26T13:38:59","date_gmt":"2008-03-26T08:08:59","guid":{"rendered":"http:\/\/blog.i2fly.com\/?p=638"},"modified":"2008-03-26T18:10:31","modified_gmt":"2008-03-26T12:40:31","slug":"adobe-flash-player-9-update-to-destroy-and-save-web-apps","status":"publish","type":"post","link":"http:\/\/blog.i2fly.com\/?p=638","title":{"rendered":"Adobe Flash Player 9 update to destroy and save Web apps!!"},"content":{"rendered":"<p id=\"top\" \/><img SRC=\"http:\/\/blog.i2fly.com\/wp-content\/uploads\/2008\/03\/flash-player-9.png\" ALT=\"flash player 9\" \/><\/p>\n<p><a TARGET=\"_blank\" HREF=\"http:\/\/www.adobe.com\">Adobe<\/a> is issuing an update to <a TITLE=\"flash player 9\" TARGET=\"_blank\" HREF=\"http:\/\/www.adobe.com\/products\/flashplayer\/\">Flash Player 9<\/a> that it hopes will prevent Flash-based Web applications being used to launch attacks against consumers but the update may also stop Flash apps working if developers don&#8217;t heed Adobe&#8217;s recommendations.<\/p>\n<p><u>The April update addresses two security flaws in Adobe Flash 9, relating to cross-site scripting (XSS) and DNS rebinding attacks &#8212; common techniques used to attack computer systems by exploiting flaws in Web applications.<\/u><\/p>\n<p>The update focuses on features in Adobe used by Web developers to communicate with third party servers. Those likely to be affected will be using sockets or XMLSockets; or addRequestHeader or URLRequest.requestHeaders in a network API to access content from sites outside their own domain.<br \/>\nIf a site provides access to content on remote domains as a Web service provider, or if it has Flash content in pre-Flash 8 format that communicates with the hosting HTML, then the site could be affected. The update could also impact a site if it uses javascript to communicate outside of a Flash SWF. In all cases, Adobe advises following its recommendations to avoid problems.<\/p>\n<p><a TARGET=\"_blank\" HREF=\"http:\/\/www.adobe.com\">Adobe<\/a> says that the April 2008 Flash Player update will help defend against malicious HTTP headers sent from other domains by performing a cross-domain policy file check before allowing SWFs to send headers to another domain.<\/p>\n<p><a TITLE=\"builderau\" TARGET=\"_blank\" HREF=\"http:\/\/www.builderau.com.au\/news\/soa\/Adobe-Flash-9-update-to-destroy-and-save-Web-apps\/0,339028227,339287670,00.htm\">Read more<\/a><\/p>\n<p>vivek<\/p>\n\n<div class=\"twitter-share\"><a href=\"https:\/\/twitter.com\/intent\/tweet?via=i2fly\" class=\"twitter-share-button\" data-size=\"large\">Tweet<\/a><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Adobe is issuing an update to Flash Player 9 that it hopes will prevent Flash-based Web applications being used to launch attacks against consumers but the update may also stop Flash apps working if developers don&#8217;t heed Adobe&#8217;s recommendations. The April update addresses two security flaws in Adobe Flash 9, relating to cross-site scripting (XSS)&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19,15,6],"tags":[1500,205,202,203,206,204],"class_list":["post-638","post","type-post","status-publish","format-standard","hentry","category-adobe","category-flash","category-web","tag-adobe","tag-dns","tag-flash-player-9","tag-swf","tag-xmlsockets","tag-xss"],"_links":{"self":[{"href":"http:\/\/blog.i2fly.com\/index.php?rest_route=\/wp\/v2\/posts\/638","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/blog.i2fly.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/blog.i2fly.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/blog.i2fly.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/blog.i2fly.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=638"}],"version-history":[{"count":0,"href":"http:\/\/blog.i2fly.com\/index.php?rest_route=\/wp\/v2\/posts\/638\/revisions"}],"wp:attachment":[{"href":"http:\/\/blog.i2fly.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=638"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/blog.i2fly.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=638"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/blog.i2fly.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=638"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}