6 ms·
Use Flashblock or something similar. By default Flash objects are turned off, but you can click on them to enable. Firefox: https://addons.mozilla.org/en-US/fi
by agazso 16y ago
Use Flashblock or something similar. By default Flash objects are turned off, but you can click on them to enable.
Firefox: https://addons.mozilla.org/en-US/firefox/addon/433/ https://addons.mozilla.org/en-US/firefox/addon/433/
Chrome: https://chrome.google.com/extensions/detail/cdngiadmnkhgemkimkhiilgffbjijcie https://chrome.google.com/extensions/detail/cdngiadmnkhgemki...
- bl4k 16y agoAs I mentioned below, I had Flashblock, and used it for a while until I noticed that Flash is still in memory and Flashblock is just some JS that hides flash elements. Killing everything is much better.
- bhiggins 16y agoI don't know what Flashblock you were using but the ones I have used do not behave this way. Maybe Flash was in memory because you clicked one of them and allowed it to run?
- bgentry 16y agoI used the following FlashBlock for Chrome, and using resource tracker I could see that no SWFs were downloaded on a YouTube page until after I temporarily enabled Flash on that page. https://chrome.google.com/extensions/detail/gofhjkjmkpinhpoiabjplobcaignabnl https://chrome.google.com/extensions/detail/gofhjkjmkpinhpoi... Is that good enough proof that the SWF is not put into memory? Also, the FlashBlockBlock page here does not load when I have the extension enabled: https://woofle.net/flashblockblock/ https://woofle.net/flashblockblock/
- blasdel 16y agoYes, extensions named 'Flashblock' are pretty universally mediocre and don't actually keep Flash from crashing your browser — they just keep it from being displayed. ClickToFlash for native Webkit views on OS X actually blocks Flash for real — it's a native Webkit plugin that registers for Flash's primary mimetype and preempts it. When you selectively enable a flash embed, it replaces itself with Adobe's NPAPI plugin.
- wtallis 16y agoUsing NoScript is probably best. It actually blocks Flash content properly, and protects against most other browsing-related vulnerabilities. Plus, if you don't allow scripts to run from advertiser's domains, most ads can't load.
- flatulent1 16y agoNote - The title is misleading. It's a zero day vulnerability on all platforms, but the exploits hit XP Vista and W7. It's still prudent to kill Flash on all though. http://www.theregister.co.uk/2010/09/13/adobe_flash_0day_vuln/ http://www.theregister.co.uk/2010/09/13/adobe_flash_0day_vul... It is easy to turn off Flash in the Firefox plugins, and running the Better Privacy extension which kills the Flash hidden cookies normal cookie management doesn't touch. (One stalks you keeping track of every site you've visited with Flash) Better Privacy isn't yet compatible with the Firefox 4 beta but is fine with 3.x NoScript is still a good idea for many reasons. The malware is worse this year than last... http://www.gdatasoftware.co.uk/about-g-data/press-centre/news/news-details/article/1760-number-of-new-computer-viruses.html http://www.gdatasoftware.co.uk/about-g-data/press-centre/new...
- ja27 16y agoOn last months zero-day Flash exploit thread, someone linked to a demo that shows bypassing Flashblock. I think this is it (but I don't run Flashblock). [EDIT: Note: I don't know how safe the link in this article is.] http://seclists.org/fulldisclosure/2008/Jul/444 http://seclists.org/fulldisclosure/2008/Jul/444
- duskwuff 16y agoHere's a simple proof of concept I wrote a while back that bypasses Firefox FlashBlock: https://woofle.net/flashblockblock/ https://woofle.net/flashblockblock/ The payload is harmless but silly.