Live data from Hacker News

New Adobe Flash 0day, have a nice weekend

adobe.com

51–60 of 74 posts

Re: New Adobe Flash 0day, have a nice weekend

#51
post #12

I've seen Adobe do quite a few security announcements over the years but I've never actually seen any of the exploits in action or explained. I'm really curious how serious these exploits really are and if they are actually practical (or more theoretical). Any references greatly appreciated.

Visit any web page anywhere that has content controlled by an attacker, have a backdoor transparently installed on your system. Is there more you want to know?

Re: New Adobe Flash 0day, have a nice weekend

#52
post #15

Adobe Reader and Acrobat on MacOSX also include a file named authplay.dll ? (Any chance Apple's 'Preview' PDF-reading capabilities are similarly vulnerable?)

Apple's 'Preview' PDF viewer has lots of security vulnerabilities. Simple fuzzing will quickly find plenty of 0day.

That's a bold claim waiting to be backed up.

Re: New Adobe Flash 0day, have a nice weekend

#54
post #3
post #2

Shouldn't a fix come out with that announcement? If they're offering a temporary fix, shouldn't they at least push that temp fix as an update, and fully update the issue later? This leaves the non-technically inclined out in the cold, and informs those who may not know of the exploit of its existence. Just something as simple as removing authplay.dll for Acrobat and Reader, and even upgrading the current version of F…

Since it's already in the wild, better to let people know so they can use the workaround.

A thousand times, this! Paternalism on the part of vendors keeps people who are willing to make tradeoffs from defending themselves.

Re: New Adobe Flash 0day, have a nice weekend

#55
post #10
post #2

Shouldn't a fix come out with that announcement? If they're offering a temporary fix, shouldn't they at least push that temp fix as an update, and fully update the issue later? This leaves the non-technically inclined out in the cold, and informs those who may not know of the exploit of its existence. Just something as simple as removing authplay.dll for Acrobat and Reader, and even upgrading the current version of F…

I believe its Adobe policy to only announce security issues if a fix is available. At least, that's how the policy was a few years back. I assume it's still the same.

It's most vendor's policy, but it usually goes out the window when reports of exploitation surface. If you're hearing about the attacks, it's real, it's bad, and there's no point to choreography anymore.

Re: New Adobe Flash 0day, have a nice weekend

#56
post #2

Shouldn't a fix come out with that announcement? If they're offering a temporary fix, shouldn't they at least push that temp fix as an update, and fully update the issue later? This leaves the non-technically inclined out in the cold, and informs those who may not know of the exploit of its existence. Just something as simple as removing authplay.dll for Acrobat and Reader, and even upgrading the current version of F…

Since it's a 0day I think it would require ninja coders to test, go to the code and fix it in the same day, for complex and legacy code (I think Adobe software falls into these categories), from my experience watching security related lists I can say that generally you publish a measure to mitigate the vulnerability and maybe a workaround before publishing a stable fix.

Securing and maintaining software up-to-date in a non-intrusive way is hard in a way that works for all (ie, personal computers and large networks of computers), I think it is also a good business opportunity.

Re: New Adobe Flash 0day, have a nice weekend

#57
post #19

Earlier quoted context omitted.

I'm not quite sure what the relevancy of this is, unless you're actually such a rabid Apple hater that you automatically see any mention of Adobe flaws as an argument for Apple or somesuch.

Lots of software has security problems. It's pretty rare that any of them show up on the front page of HN. They just tend to blend into background noise as "not interesting" unless it's particularly interesting to the community for some reason. Given that one of Job's major points for not allowing Flash on iDevices was the security of the platform, the only conclusion one can draw for having a security notice show up…

"Yet the fact that that link is providing uncomfortable information contrary to that provided by Jobs has caused it to be annihilated by downvotes"

No, I think it was mostly the irrelevancy that got you downvoted.

"you successfully made the connection between Adobe and Apple."

Umm, what you posted was a link to something about Apple, so yeah, I think I could be justified in believing that was the connection you were trying to make.

"I bet there was never an Adobe Flash related security posting on the front page of HN."

http://news.ycombinator.com/item?id=164725 http://news.ycombinator.com/item?id=1105508 http://news.ycombinator.com/item?id=801713 http://news.ycombinator.com/item?id=164725

"Apple is also not free from issues with its platform. Yet these never make it to the front page of HN."

http://news.ycombinator.com/item?id=876334 http://news.ycombinator.com/item?id=684743

"It's pretty rare that any of them show up on the front page of HN."

http://news.ycombinator.com/item?id=1129882 http://news.ycombinator.com/item?id=692036 http://news.ycombinator.com/item?id=690592 http://news.ycombinator.com/item?id=872533 http://news.ycombinator.com/item?id=709869 http://news.ycombinator.com/item?id=393009

"the only conclusion one can draw for having a security notice show up on the front page is that there are a lot of Adobe haters out there."

The only conclusion? Really? Some people might be interested because it is an unfixed vulnerability actively being exploited in software that's on 95% of PCs. Just a thought.

"Apple wouldn't provide the necessary APIs"

You're certainly not approaching this from a standpoint of hating Apple, if that's the interpretation you put on the abysmal performance of Flash on OS X for many many years. I should note that Silverlight has always had stellar performance relative to Flash on any Mac I've used them on.

"unwanted counter information"

Or again, complete irrelevancy.

Re: New Adobe Flash 0day, have a nice weekend

#60
post #58

Chromium + Flash + Linux vulnerable as well? How does one a) even know what version of flash is embedded in Chromium b) other than constantly killing the flash process how does one disable flash in Chromium Chromium v6.0.417.0

Generally, to determine flash version, you're forced to the macromedia website to view a version test .swf .

After finding out about this 'sploit, I looked in vain for the authplay.dll . It turns out I had a newer build that wasn't listed as vulnerable (and I couldn't find the file itself, where does it usually reside?).

Post reply on HN