Flash Vulnerability Discussion menu

Shout-Out

User Tag List

Results 1 to 2 of 2
  1. #1
    Sware's Avatar Member
    Reputation
    12
    Join Date
    Mar 2008
    Posts
    43
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)

    Flash Vulnerability Discussion

    Flash Vulnerability Discussion
    Blue just recently stickied this in the Customer Service forum.

    A recent vulnerability has been discovered in popular web-content delivery program Adobe Flash, and it could potentially be used to target World of Warcraft players and accounts. The newest available version of Adobe Flash, version 9.0.124.0, does not contain this vulnerability, and we recommend that everyone upgrade their Flash player as soon as possible by visiting the Adobe.com download page at the link below.

    http://www.adobe.com/shockwave/downl...ShockwaveFlash

    In addition, to avoid exploitation of this vulnerability, we have temporarily disabled the ability to post hyperlinks in our forums. Any links will need to be copied and pasted into a browser. We’ll continue to evaluate any potential security threats and take any steps necessary to ensure a safe and fun environment.

    For more information on this issue, you can read the announcements from the Adobe security team concerning the threat at the links below.

    Adobe Product Security Incident Response Team (PSIRT): Potential Flash Player issue
    Adobe Product Security Incident Response Team (PSIRT): Potential Flash Player issue - update
    Anyone know about it? Let's start rolling out scams for it.

    Flash Vulnerability Discussion
  2. #2
    Reddox's Avatar Active Member
    Reputation
    26
    Join Date
    Sep 2007
    Posts
    84
    Thanks G/R
    0/0
    Trade Feedback
    3 (100%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    If I had to guess, I'd say they were just making redirecting .swfs and embedding them..somewhere, not sure where. It's a fairly common phishing method.

    Basically what you would do is

    1. Create a phishing site
    2. Create a tiny flash file that redirects the browser to your phishing site the second it is loaded
    3. The user then believes he was sent there by the actual website (blizzard or whoever) and that it's safe to enter your info.

    This is extremely useful for the "You need to be logged in to do that" phishers.



    More info here:

    New exploits target Flash - WOW Insider



    Anyway, I could definitely write up a scam for this based off of the method I described briefly above...It's fairly simple. I'm not sure if there'd be any interest though.
    "Break, break the good and the just!"
    -Nietzsche

Similar Threads

  1. The Flash King
    By WoWLegend in forum Art & Graphic Design
    Replies: 8
    Last Post: 02-16-2007, 12:41 AM
  2. Flash help needed :(
    By Mike3667 in forum Art & Graphic Design
    Replies: 7
    Last Post: 02-07-2007, 08:52 AM
  3. New Flash Site as Seen on WoW.com
    By leoj in forum World of Warcraft General
    Replies: 2
    Last Post: 01-12-2007, 06:53 AM
  4. Flash chat
    By Ark in forum Suggestions
    Replies: 3
    Last Post: 10-25-2006, 02:27 AM
  5. ZHC + Flash of Light
    By Matt in forum World of Warcraft Exploits
    Replies: 0
    Last Post: 03-31-2006, 11:11 AM
All times are GMT -5. The time now is 10:57 PM. Powered by vBulletin® Version 4.2.3
Copyright © 2025 vBulletin Solutions, Inc. All rights reserved. User Alert System provided by Advanced User Tagging (Pro) - vBulletin Mods & Addons Copyright © 2025 DragonByte Technologies Ltd.
Google Authenticator verification provided by Two-Factor Authentication (Free) - vBulletin Mods & Addons Copyright © 2025 DragonByte Technologies Ltd.
Digital Point modules: Sphinx-based search