7 ms·
New Adobe Flash 0day, have a nice weekend
- adamdecaf 16y agoI will have a nice weekend, for I don't even have flash on this laptop (Linux). :) </sarcasm>
- ihodes 16y agoShouldn't a fix come out with that announcement? If they're offering a temporary fix, shouldn't they at least push that temp fix as an update, and fully update the issue later? This leaves the non-technically inclined out in the cold, and informs those who may not know of the exploit of its existence. Just something as simple as removing authplay.dll for Acrobat and Reader, and even upgrading the current version of Flash Player to the 10.1 beta, just temporarily… anything other than just announcing it and not patching it at all. I don't know if this is a standard way of dealing with zero day exploits, but it sure doesn't seem like a good way.
- dminor 16y agoSince it's already in the wild, better to let people know so they can use the workaround.
- tptacek 16y agoA thousand times, this! Paternalism on the part of vendors keeps people who are willing to make tradeoffs from defending themselves.
- pan69 16y agoI believe its Adobe policy to only announce security issues if a fix is available. At least, that's how the policy was a few years back. I assume it's still the same.
- tptacek 16y agoIt's most vendor's policy, but it usually goes out the window when reports of exploitation surface. If you're hearing about the attacks, it's real, it's bad, and there's no point to choreography anymore.
- yock 16y agoAn inadequately-tested update is going to carry some risk of causing its own harm. If this Flash update is indeed not-ready-for-prime-time (heck, they may even know of specific issues) then it becomes irresponsible to push it out to all users. You've essentially traded a known problem for an unknown problem, as well as complicated the process by which the original problem is resolved.
- ja27 16y agoIt was a good reminder for me to disable Flash and PDF (and 30 other plugins) in Chrome. I use Chrome for almost all my browsing, but if I need Flash or something else on a specific site, I can open it in IE or Firefox. Maybe someday Chrome will have a plugin "whitelist" for sites so I can only allow Flash on the sites I want to.
- DrSprout 16y agoThat's really weird. I use firefox with NoScript for all my browsing, and if I need Flash or something I fire up Chrome. Of course, this is on desktop Ubuntu. On my Droid I guess I just use Chrome...
- CrazedGeek 16y agoFlashblock? https://chrome.google.com/extensions/detail/gofhjkjmkpinhpoiabjplobcaignabnl?hl=en https://chrome.google.com/extensions/detail/gofhjkjmkpinhpoi...
- zppx 16y agoSince it's a 0day I think it would require ninja coders to test, go to the code and fix it in the same day, for complex and legacy code (I think Adobe software falls into these categories), from my experience watching security related lists I can say that generally you publish a measure to mitigate the vulnerability and maybe a workaround before publishing a stable fix. Securing and maintaining software up-to-date in a non-intrusive way is hard in a way that works for all (ie, personal computers and large networks of computers), I think it is also a good business opportunity.
- icefox 16y agoflash block?
- tomlin 16y agoIt would be nice to know we're not just beating up on them because it's trendy and perhaps hold them accountable on the same level as other software companies. It's possible that they were in the right by announcing an issue, rather than ignoring it.
- datd00d 16y agoThe fix is to install 10.1 RC, and delete/rename/ACL authplay.dll. I wont comment on the whole "use our RC release" as a mitigation path in production env's....
- blocke 16y ago10.1 has had 7 release candidate releases so far. Been running them for a while and they don't seem anymore crashy than 10.0 and the GPU acceleration is nice. Also it would be a great time to upgrade Firefox to the 3.6.4 release candidate for those using Firefox. Plugin process separation... yummo. http://blog.mozilla.com/blog/2010/06/01/firefox-3-6-4-release-candidate-available-for-download-and-testing/ http://blog.mozilla.com/blog/2010/06/01/firefox-3-6-4-releas...
- sliverstorm 16y agoHonestly it seems much more like a statement of the facts so you can make a choice. I'd rather also know the RC is unaffected than ONLY know that the current version is vulnerable. Obviously an RC release is not a long term fix, but this is a breaking bug.
- bobbyi 16y agoAnother reason to be running 10.1
- rmorrison 16y agoAdobe has desensitized me to updating their software, since every time I open Acrobat it asks me to download a new version. It's like the boy who cried wolf, but since this sounds serious maybe I'll get over this mental hurdle.
- JoachimSchipper 16y agoActually, every time you open Acrobat it's had a new security issue. At least, it's that way for me (though Windows is not my primary OS, so I don't open Acrobat that often).
- Niten 16y agoEven if Windows is your primary OS, there's no reason for the typical user to have to run Adobe Reader on a regular basis. Just use a nice lightweight viewer like PDF-XChange, Sumatra, or Foxit instead. Windows is my primary OS, and I don't even have Adobe Reader installed.
- nitrogen 16y agoI've found Sumatra to render extremely slowly when zoomed in past 100%, particularly on PDFs with high-res images and/or vector images. Are the other non-Adobe readers better at this?
- elblanco 16y agoand? http://www.engadget.com/2010/03/19/charlie-miller-to-reveal-20-zero-day-security-holes-in-mac-os-x/ http://www.engadget.com/2010/03/19/charlie-miller-to-reveal-...
- ptomato 16y agoI'm not quite sure what the relevancy of this is, unless you're actually such a rabid Apple hater that you automatically see any mention of Adobe flaws as an argument for Apple or somesuch.
- elblanco 16y agoLots of software has security problems. It's pretty rare that any of them show up on the front page of HN. They just tend to blend into background noise as "not interesting" unless it's particularly interesting to the community for some reason. Given that one of Job's major points for not allowing Flash on iDevices was the security of the platform, the only conclusion one can draw for having a security notice show up on the front page is that there are a lot of Adobe haters out there. Within one sentence (and with absolutely no commentary or statements from me in any way) you successfully made the connection between Adobe and Apple. This connection is obvious and I shouldn't really have to explain it -- in other words, it's painfully obvious why a security bulletin for Flash has shown up on the front page of HN and why I've never seen one for an Apple product despite fairly wide ranging security concerns in the community about Apple products. Here's Jobs on the topic. https://www.apple.com/hotnews/thoughts-on-flash/ https://www.apple.com/hotnews/thoughts-on-flash/ "Symantec recently highlighted Flash for having one of the worst security records in 2009. We also know first hand that Flash is the number one reason Macs crash. We have been working with Adobe to fix these problems, but they have persisted for several years now. We don’t want to reduce the reliability and security of our iPhones, iPods and iPads by adding Flash." Before Jobs explicitly banned Flash from the platform, the only thing I ever remember seeing on HN regarding flash was that it performed a bit poorly under Apple's operating systems because Apple wouldn't provide the necessary APIs that would allow Adobe to make it as performant as it is under Windows (and the occasional comment regarding the Linux port that like most software ported to Linux, it was a few generations behind the times). But these complaints are pretty much the same for lots of cross platform software and generally blended into the background noise, even canvas runs poorly on most systems! One thing I don't ever recall hearing about on HN was any commentary about Flash as insecure. That all changed with "Thoughts on Flash". Before Thoughts on Flash, I bet there was never an Adobe Flash related security posting on the front page of HN. Yet Flash has had its share of security issues, the same as anything. Which is what my link was meant to demonstrate. In other words, it's essentially a non-issue. My point in posting one of a million links regarding Apple security problems is that Apple is also not free from issues with its platform. Yet these never make it to the front page of HN. More importantly, Apple is rather poor at self-reporting security problems, yet here we are bashing Adobe for doing the responsible thing and reporting the problem themselves. It's actually an interesting example of social dynamics, demonstrating how people will follow the direction a chosen leader and orient their opinions regarding their own safety to be in line with what that leader says rather than an objective review of the actual situation. People often follow leaders as a proxy for doing their own thinking. I've just demonstrated why this is dangerous. Jobs doesn't want to bring attention to the security issues of his own platforms and has tried, successfully, to direct natural concerns for that to somebody else. It's a masterful piece of political manipulation. Most politicians would sell a limb to have this kind of mind share. My link provided no commentary, no judgment, no counter-statements, no Apple bashing or Apple praise, in fact no statements of any kind. Yet the fact that that link is providing uncomfortable information contrary to that provided by Jobs has caused it to be annihilated by downvotes (meta-comment: pg has obviously changed something in the karma scoring because it only shows -4, but my account is down -9 since yesterday and that's the only change I can find, either the karma math is screwy, or he's experimenting with some social engineering of his own and counting all downvotes but only showing -4 no matter what. I find this interesting since, if that were true, people have continued to downvote a link to unwanted counter information even though it already stands at -4). I actually cannot find a statement from Jobs regarding platform security other than "Thoughts on Flash". Even in response to things like this http://www.theinquirer.net/inquirer/news/1495591/security-experts-mock-mac-security http://www.theinquirer.net/inquirer/news/1495591/security-ex.... Considering that Jobs is among the more chatty CEOs of a major corporation, this omission is rather perplexing. This leads to the obvious conclusion that Jobs has taken the opportunity to call out Flash security as a red herring, to turn our attention away from the problems on his own platform. And, as is demonstrated here by bashing on Adobe for flash security, bashing on people who point out apple security, people have bought his play -- hook, line and sinker. I provoked the response I expected to get based on the history of how the dynamics of the situations has occurred. A swarm of downvotes for a link regarding Apple security problems flies directly in the face of what Jobs has said. It's a shame he had to put "Thoughts on Flash" out there. I found his comments on Flash at D8 far more coherent and sensible and without the obvious manipulative language he used in "Thoughts". What I find a shame is how easily and gullible people who follow Jobs have been regarding the entire issue -- people who are otherwise very smart and very bright. edit I'm actually down -10 on my karma now. I guess pg does count all downvotes even if -4 is all that's displayed. edit 2 this poor comment was similarly in negative territory as well, further reinforcing my point. http://news.ycombinator.com/item?id=1406477 http://news.ycombinator.com/item?id=1406477
- TheKid 16y agoAnd read the fine print regarding 10.1 RC: "The Flash Player 10.1 Release Candidate available at ... does not APPEAR to be vulnerable." Very different than "Here's a fix." (Snarky comment removed.)
- drivebyacct 16y agoNo, no it does not sum up why there's no Flash on the iPhone. Thanks for playing though. Enjoy your consolation prize.
- deleted 16y ago[deleted]
- DMiner 16y agoI wish your comment was a fact. But Apple is a business and they have business interests when it comes to these outsider platforms. My understanding is that Apple doesnt allow Java ,Silverlight , Qt or any of those, because these platforms could gradually in-signify the need for a walled garden of apps. App Store is a real cash cow with a lot of potential and Apple clearly doesnt want to purge it off(and that is a good business move.) IMHO, the same even applies to html5. Apple runs huge campaigns and invests in Safari development to make sure that webkit could gradually insignify the need for a plugin to run interactive content. But try running most of these html5 apps on an iphone/ipad.The rendering framerate is very low and is almost not usable. While native apps run real good, the discrimination against webkit could be that Apple is purposefully delaying the iDevice users' dependency on web apps . I believe Apple's all-control policy is more of a business move than a security related one
- ROFISH 16y agoI understand the business move, but I never understood the "cash cow" reasoning. Most apps appear to be in the $2.99 to $.99 range. The 60 cents Apple gains from a $1.99 app barely covers credit card fees (for multiple currencies), bandwidth fees, bank fees to send money to developer, and paying salaries for all those app reviewers. Occam's Razor suggests that they want to build "only the best apps" so the way to do that is to "completely control the build toolchain". Has nothing to do with "cash cow" conspiracy theories.
- pan69 16y agoI've seen Adobe do quite a few security announcements over the years but I've never actually seen any of the exploits in action or explained. I'm really curious how serious these exploits really are and if they are actually practical (or more theoretical). Any references greatly appreciated.
- jsz0 16y agoThey're practical. The biggest one I can remember was attacking WoW players by posting links to forums to sites with Flash banner ads that utilized an exploit to install a key logger and some other nasty stuff. The classic fake Flash update tactic is wildly successful also which of course isn't a Flash problem but just a side effect of users expecting to install/update browser plugins and becoming oblivious to the risks.
- mukyu 16y agohttp://chargen.matasano.com/chargen/2007/7/3/this-new-vulnerability-dowds-inhuman-flash-exploit.html http://chargen.matasano.com/chargen/2007/7/3/this-new-vulner...
- tptacek 16y agoVisit any web page anywhere that has content controlled by an attacker, have a backdoor transparently installed on your system. Is there more you want to know?
- mikeytown2 16y agoLink to 10.1 RC7 http://labs.adobe.com/downloads/flashplayer10.html#flashplayer10 http://labs.adobe.com/downloads/flashplayer10.html#flashplay...
- gojomo 16y agoAdobe Reader and Acrobat on MacOSX also include a file named authplay.dll? (Any chance Apple's 'Preview' PDF-reading capabilities are similarly vulnerable?)
- bradleyland 16y agoApple's Preview app uses it's own PDF interpreter, so it is unaffected.
- DrewHintz 16y agoApple's 'Preview' PDF viewer has lots of security vulnerabilities. Simple fuzzing will quickly find plenty of 0day.
- sans-serif 16y agoThat's a bold claim waiting to be backed up.
- mish 16y agoI think the poster was referring to Charlie Miller's CSW 2010 presentation, where he finds a number of trivial, exploitable vulnerabilities in Preview. You can see the slide deck here: http://securityevaluators.com/files/slides/cmiller_CSW_2010.ppt http://securityevaluators.com/files/slides/cmiller_CSW_2010....
- deleted 16y ago[deleted]
- jared314 16y agoThe Linux 64-bit version needs some love. It has not been updated since Feb.
- logic 16y agoSo, 10.0.45.2 is vulnerable. Oh look, that's the only available version of the 64-bit Linux plugin, because they don't do 64-bit builds along with their 32-bit builds: http://labs.adobe.com/technologies/flashplayer10/64bit.html http://labs.adobe.com/technologies/flashplayer10/64bit.html
- seanlinmt 16y agoI don't use Adobe Reader anymore. Foxit Reader, http://www.foxitsoftware.com/pdf/reader/ http://www.foxitsoftware.com/pdf/reader/, is way smaller and faster. And it's not by Adobe. :)
- kwyjibo 16y agoI used foxitreader as well, until they had that feature that they would execute whatever command on your computer and you couldn't disable it... (and you could do this, or at least add a warning in adobe's reader)
- natch 16y agoPerfect headline. It straddles the ambiguity between the two possible meanings: the sarcastic one, about IT personnel scrambling to put fixes in place over their 'nice' weekend, and the non-sarcastic one, addressed to hackers who could have some fun with this. In any case, Adobe, the timing has exactly the level of thoughtfulness we have come to expect from the Flash team. The only way you could have done more damage would be to have done it last week when the US had a long weekend, or some other even longer holiday.
- ck2 16y agoWell that's ONE way to get everyone onto 10.1
- gmlk 16y agoYesterday I removed flash from my Mac Internet Plugins folder. I can't say I'm missing it. Nearly all website work, a lot of ads are gone. Strangely, html5/h.264 is often the fall back for flash, I really would wish they did that the other wise around.
- oscardelben 16y agoYou could give http://clicktoflash.com/ http://clicktoflash.com/ a try
- andrewtj 16y agoThat made me curious so I removed Flash from /Library/Internet\ Plug-Ins/ and rebooted. I'm unable to play video on either Vimeo or YouTube so I'll be sticking with Click to Flash for the moment.
- tuacker 16y agoYoutube: http://www.youtube.com/html5 http://www.youtube.com/html5 Vimeo: Right below the description, see: http://imgur.com/yuf4R http://imgur.com/yuf4R Obviously not an automatic fallback but I guess that's because it is still in 'beta'. Youtube videos with ads won't work, or embedded ones (I think the same goes for embedded vimeo vids)
- andrewtj 16y agoThanks for the links — I'd just expected the sites to fallback. For anyone else who's tempted to try this out, unless I missed it there is also no 'Switch to HTML5 player' link for channels on Vimeo.
- gmlk 16y agoI had to put the plugin back: http://twitter.com/gideonklok/status/15475873118 http://twitter.com/gideonklok/status/15475873118 Btw. I did already opted into the html5 beta tests here and there. That might have influenced the result. I'm using http://clicktoflash.com/ http://clicktoflash.com/
- gojomo 16y agoThey suggest addressing the Flash vulnerability by installing the prerelease 10.1 version, which "does not appear to be vulnerable". But the first step of installing 10.1 (on Windows and MacOS) is to run an uninstaller, also available on the download page: http://labs.adobe.com/downloads/flashplayer10.html http://labs.adobe.com/downloads/flashplayer10.html Perhaps the prudent should stop after that uninstall step, for safety from other future exploits, as well.
- Tichy 16y agoAlso, I couldn't find any other way to uninstall Flash on OS X to begin with.
- endtime 16y agoAre you sure about the uninstallation part? I was able to install 10.1 without uninstalling anything. Took about 10 seconds. And http://www.adobe.com/software/flash/about/ http://www.adobe.com/software/flash/about/ tells me "You have version 10,1,53,64 installed".
- gojomo 16y agoThe preview version's Release Notes say to run the uninstaller first, but perhaps it's not necessary.
- JoachimSchipper 16y agoDid anybody else read "The Flash Player 10.1 Release Candidate (...) does not appear to be vulnerable" as "we ran the exploit and it didn't work"?
- jmount 16y agoMore as "we thought the last one didn't have this flaw- but we are tired of being wrong."
- Tichy 16y agoSorry for my ignorance, but is there still no way to watch YouTube and other videos without Flash? I thought some browsers would ship with suitable codecs and be able to play them directly?
- tuacker 16y agoVisit http://www.youtube.com/html5 http://www.youtube.com/html5 and join the beta. It won't work for all videos though and not at all for embedded videos.
- obama012369 16y agoThis is my very favorite a shopping site: http://wowcool.org http://wowcool.org The website wholesale for many kinds of fashion shoes, like the nike,jordan,prada,adidas, also including the jeans,shirts,bags,hat and the decorations. All the products are free shipping, and the the price is competitive, and also can accept paypal payment.,after the payment, can ship within short time. free shipping competitive price any size available they do wholesale and retail! All are extremely CHEAP: http://wowcool.org http://wowcool.org their products: jordan air max oakland raiders. Ed Hardy AF JUICY POLO Bikini. Christan Audigier BIKINI JACKET. gstar coogi evisu true jeans. coach chanel gucci LV handbags. coogi DG edhardy gucci t-shirts. CA edhardy vests.paul smith shoes. jordan dunk af1 max gucci shoes. EDhardy gucci ny New Era cap. coach okely Adidas CHANEL DG Sunglass. Worthy of my recommendation, go and see: http://wowcool.org http://wowcool.org
- againstyou 16y agogreat, now we need to use the Release Candidate to be safe ? probably we get another features (aka remote exploits) using RC and not a stable version. btw, adobe really released a stable version of flash ? someday ?
- boskone 16y agoChromium + Flash + Linux vulnerable as well? How does one a) even know what version of flash is embedded in Chromium b) other than constantly killing the flash process how does one disable flash in Chromium Chromium v6.0.417.0
- PidGin128 16y agoGenerally, to determine flash version, you're forced to the macromedia website to view a version test .swf . After finding out about this 'sploit, I looked in vain for the authplay.dll . It turns out I had a newer build that wasn't listed as vulnerable (and I couldn't find the file itself, where does it usually reside?).
- Bakes 16y agoThe bug is between Acrobat Reader and Flash, not Flash and any browser. It's not a problem for you to worry about.
- stalker 16y agoI think they must put an alert in the download page.