8 of the 10 Top Security Flaws Used By Cyber-Criminals This Year Were Flash Bugs (recordedfuture.com) 66
An anonymous reader writes: Adobe Flash Player provided eight of the top 10 vulnerabilities used by exploit kits in 2015. Angler is currently the most popular exploit kit, regularly tied to malware including Cryptolocker. Vulnerabilities in Microsoft's Internet Explorer and Silverlight are also major targets. All of these are the conclusions of a Recorded Future report.
Newgrounds (Score:2)
Any sites that require [the Flash Player plug-in] tend to be either Eastern European (dodgy porn) or very old.
I'm not sure what you mean by "very old". Do you mean "established long ago" or specifically "not updated in years"? In which sense are Newgrounds, Albino Blacksheep, Dagobah, and Weebl's Stuff "very old"?
Re: (Score:2)
I'm not sure what you mean by "very old". Do you mean "established long ago" or specifically "not updated in years"? In which sense are Newgrounds, Albino Blacksheep, Dagobah, and Weebl's Stuff "very old"?
What are Newgrounds, Albino Blacksheep, Dagobah, and Weebl's Stuff? Do we have to know them?
Re: (Score:2)
Archives of classic vector animations created before HTML5 had support for <canvas> and <audio>.
Re:Can windows PC runs without Adobe Flash? (Score:5, Funny)
Re: (Score:1)
Likely difficult. Windows 10 seems to be written in Flash
No this [youtube.com] is the first good version of windows that was written in flash. Now it only runs on HTML5 and is as good as ever.
Re:Can windows PC runs without Adobe Flash? (Score:5, Insightful)
Browser break, escalation, and VM escape? (Score:2)
In order to spoil such a research project, a site would have to find an exploit that busts out of not only the browser but also the user account and VirtualBox.
Re: (Score:2)
Re: (Score:2)
Has anyone tried running a PC without Adobe Flash?
Can that PC be used to surf the Net?
Any suggestion would be very much appreciated !
Assuming you have a proper web browser: You can get plugins that stop flash from running automatically. That's almost the same thing as "no flash".
And the rest we're probably Jave, Acrobat, and OS (Score:5, Insightful)
Re: (Score:2)
Re:And the rest we're probably Jave, Acrobat, and (Score:5, Informative)
In a world where Flash is not required for any functionality, and where it has been a known security risk for a long while, websites that require it are either painfully incompetent, or malicious - feel free to remind hostmasters of this.
Re: And the rest we're probably Java, Acrobat, and (Score:3)
Re: (Score:2)
Is there a reason you can't play tower defense in Flash Player in Firefox in Xubuntu in VirtualBox?
Re: (Score:2)
Eating my own dog-chow: https://twitter.com/GNious/sta... [twitter.com]
Feel free to retwat it at people who need to stop using Flash :)
Re: (Score:2)
Feel free to retwat it at people who need to stop using Flash :)
I only retweet when someone is saying something clever, and preferably when someone knows who they are. Suggesting that something you said is quotable proves that it isn't, because who would want to quote someone like that?
Re: (Score:2)
That has to be one of the most absurd assertions I have seen in quite some time.
Re: (Score:2)
My former and current employers still use Flash, Java, Silverlight, etc. :/
Re: (Score:2)
Same here. Using flash these days is gross negligence.
Re: (Score:2)
What about those Flash games, interactive http://homestarrunner.com/ [homestarrunner.com] etc.? :P
VMWare - when are you getting rid of it? (Score:5, Interesting)
Crying shame that you need it for consoles and the like.
Re: (Score:2)
Re: (Score:2)
I suspect that you are right - I just want to be able to administer stuff from a HTML5 browser running anywhere.
Your money needs an Ally (Score:2)
Have you tried switching from your Flash bank to an HTML5 bank such as Ally or Schwab?
Why is online banking dumb? (Score:2)
Seems like a dumb idea to use a bank that isn't physically located near me.
Are you referring to getting money into a bank not physically located near you, to getting money out of a bank not physically located near you, or to some other use case I haven't thought of?
As for getting money into a bank not physically located near you, you can have direct deposit of your paycheck or other ACH transfers sent to any bank. Personal checks can be mailed or in many cases deposited using an iOS or Android device with a rear-facing camera [ally.com]. Cash can be spent locally; I'll often dump cash into
Re: (Score:2)
So you recommend using two banks?
Only for about a month while you are switching to only an online bank.
many banks reimburse for ATM fees. Or you can get cash back with a purchase at any retailer that takes EFTPOS cards.
My bank charges me extra for ATM fees.
Dump it and switch to an online bank that charges no out-of-network fees and reimburses ATM operators' fees, like Ally or Schwab. Or get cash back at Walmart or wherever.
We can go without (Score:2)
Re: (Score:2)
It's* just the developers
it's = it is
Learn this.
Re: (Score:2)
In your theory, once PC desktop is killed off, with what tools will people develop HTML5 apps?
Flash Bugs running on Microsoft Windows .. (Score:3, Interesting)
Bugs in an application can only be exploited by defects in the underlying Operating System
Re: (Score:1)
That's the most ridiculous and unqualified statement on bugs I've ever read.
What happens if an application allows for arbitrary code injection and execution due to a buffer overflow bug? Injected code could easily wipe all your user space files by using standard file io operations without ever doing anything that can be construed as exploiting defects in an underlying OS.
Name one OS that can't be "exploited" in this fashion.
Lack of thorough support for jails (Score:2)
What happens if an application allows for arbitrary code injection and execution due to a buffer overflow bug? Injected code could easily wipe all your user space files by using standard file io operations without ever doing anything that can be construed as exploiting defects in an underlying OS.
Not if the application is running under a separate user account, a jail, or some other containment facility of the operating system. Lack of such a facility is the defect. An application shouldn't be able to access a resource unless both the user has access to it and the user has delegated access to it to the particular application.
Name one OS that can't be "exploited" in this fashion.
Any GNU/Linux distribution with an AppArmor policy in effect. Or iOS on Apple devices. Or IOS on Nintendo Wii for that matter. Or Android, provided the APK doesn't have the SD fu
Re: (Score:2)
Windows has the capability to run programs under different accounts.
That's a start. Bundling a GUI to create accounts for individual desktop applications would be even better.
Re: (Score:1)
Name one OS that can't be "exploited" in this fashion.
That is the point. All OSs suck. This simply should not happen. I am becoming more convinced it is intentional.
Re: (Score:2)
The foundations of a provably secure operating system (PSOS) [sri.com]
Re: (Score:2)
Not supported on most platforms anymore (Score:3)
Re: (Score:2)
Flash was never supported on iOS and Adobe Flash has not been installed by default on OS X for years now.
Fight for your bitcoins! [coinbrawl.com]
As an old Shockwave Director user (Score:2)
And engineering team member, Flash just can't die soon enough.
Re: (Score:2)
Re: (Score:2)
Awwwwww, you need a hug.