the last unbiased stronghold

flashblock-bypass.txt

flashblock-bypass.txt
Posted Jul 25, 2008
Authored by Sowhat | Site nevisnetworks.com

The Flashblock extension suffers from a bypass vulnerability.

tags | advisory, bypass
MD5 | e3a1aade515a99e54bd2a9a941c55b5d

flashblock-bypass.txt

Change Mirror Download
Hi

I accidentally encountered a Flashblock bypass condition today.

For those who dont know what Flashblock it is,
"*Flashblock is an extension for the Mozilla, Firefox, and Netscape browsers
that takes a pessimistic approach to dealing with Macromedia Flash content
on a webpage and blocks ALL Flash content from loading. It then leaves
placeholders on the webpage that allow you to click to download and then
view the Flash content.* "

As stated by Philip Chee, the developer of Flashblock, "Flashblock is a
content blocker pure and simple. Flashblock is not
designed to improve your security at all.".

However, as the flash vulnerabilities become more prevalent, Flashblock is
recommended to be used to for security purpose.
At least I know lots of security researchers are using either Flashblock or
Noscripts to block flash.

OK, here comes the Demo:
For those who are using Flashblock with Firefox 3, Go to
http://secway.org/pr14/flashblock.htm

It does not work with FF2, as Philip commented:
"*Unless the embed identifies itself as a flash object in some way we
can't block it. On Firefox 2.0 we can block it because FX2 did some
mime type sniffing and silently added application/x-shockwave-flash
to the embed. Firefox 3.0 is stricter in avoiding mime-type sniffing*."

Anyway, Philip is right, *You can not rely on Flashblock to block all flash
and improve your security*.

Thanks
--
Sowhat
http://secway.org
"Life is like a bug, Do you know how to exploit it ?"

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

May 2012

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    37 Files
  • 2
    May 2nd
    53 Files
  • 3
    May 3rd
    33 Files
  • 4
    May 4th
    4 Files
  • 5
    May 5th
    10 Files
  • 6
    May 6th
    17 Files
  • 7
    May 7th
    19 Files
  • 8
    May 8th
    36 Files
  • 9
    May 9th
    34 Files
  • 10
    May 10th
    35 Files
  • 11
    May 11th
    20 Files
  • 12
    May 12th
    18 Files
  • 13
    May 13th
    11 Files
  • 14
    May 14th
    27 Files
  • 15
    May 15th
    58 Files
  • 16
    May 16th
    54 Files
  • 17
    May 17th
    25 Files
  • 18
    May 18th
    53 Files
  • 19
    May 19th
    9 Files
  • 20
    May 20th
    15 Files
  • 21
    May 21st
    25 Files
  • 22
    May 22nd
    32 Files
  • 23
    May 23rd
    35 Files
  • 24
    May 24th
    26 Files
  • 25
    May 25th
    25 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2012 Packet Storm. All rights reserved.

close