PDA

View Full Version : New Firefox Plug-In Will Defeat Flash Attacks


firzen771
July 8th, 2010, 12:35 AM
an interesting little project reported by kaspersky's ThreatPost.

http://threatpost.com/en_us/blogs/new-firefox-plug-will-defeat-flash-attacks-070710

cqpreson
July 8th, 2010, 12:47 AM
Interesting.

"The tool essentially parses the entire SWF file that's encountered by the browser, drops the original file and loads the parsed code into a new, safe SWF file.",it is an amazing strategy.

cheater87
July 8th, 2010, 12:48 AM
This sounds awesome.

Mr.PC
July 8th, 2010, 04:21 AM
That's nice!

BoerenkoolMetWorst
July 8th, 2010, 09:50 AM
I think Blitzableiter can already be used in NoScript:
-{ Quote: "Experimental external filters for plugin content (e.g. Blitzableiter to sanitize Flash applets). It requires Firefox 3.5 and above, and it can be configured from the new NoScript Options|Advanced|External Filters panel. To activate the built-in Blitzableiter support you need to enable filters, download Blitzableiter binaries and tell NoScript where the executable is. Please notice that Blitzableiter is in its early development stages, and it breaks a lot of Flash content." }-

Brummelchen
July 8th, 2010, 10:04 AM
i already made my thoughts:
http://www.wilderssecurity.com/showthread.php?t=271795

dw426
July 8th, 2010, 10:17 AM
-{ Quote: "i already made my thoughts:
http://www.wilderssecurity.com/showthread.php?t=271795" }-

It's too early to tell, but if you're right and it causes Flash to have even more stability issues for browsers than it already does, I'll pass. I've got Sandboxie for these sorts of attacks.

Brummelchen
July 8th, 2010, 02:05 PM
i use ad muncher and in special cases proxomitron to filter flash - or the
flash-button for firefox to turn complete off. but all changes sometime.
best weapon is an actual flash plugin - i am not frightened.
all those re-active tools slow down - whats not present cant slow down ;)