internet.com
You are in the: Small Business Computing Channelarrow
Small Business Technology
» ECommerce-Guide | Small Business Computing | Webopedia | WinPlanet

WinPlanet Software Downloads and Reviews for Small Businesses
Search
Power Search | Tips
-
Navigate WinPlanet
WinPlanet Home Page

Software
Download Index
In-Depth Reviews
Tips & Tutorials
Updates
News

Software Categories
Browsers
Chat / Conferencing
Desktop Utilities
Development
Internet Apps
Multimedia
OS Service Packs
Productivity Tools

Software Glossary

WinPlanet Newsletter

internet.commerce
Partners & Affiliates













Small Business Computing
Small Business Computing
Ecommerce Guide
Webopedia
WinPlanet

WinPlanet / News

Download of the day
Adobe Flash Player

Most Popular Software Downloads
Windows Vista Service Pack 2 (Vista SP2)
Mozilla Firefox 3
QuickTime for Windows
Adobe Flash Player
Windows 7
Norton Internet Security 2010
Internet Explorer 8
CCleaner (Crap Cleaner)
Winamp
Skype

Most Popular Software Articles
Windows Vista Tips: Home Networking Setup Tutorial
10 Must-Have Apps: The Free Windows Networking Toolkit
How to Make Your Internet Connection Faster, Better


Software Reviews

Adobe Patches Flash, But Expect More Problems
Adobe Flash Player a Clear and Present Danger?
Richard Adhikari

Adobe's Flash application is great for creating and watching rich multimedia applications, but it's one of the applications security researchers fear most because it is highly vulnerable to hackers. The application has come under more intensive scrutiny recently after Adobe issued a patch for yet another vulnerability discovered earlier this week.

"We're spending a lot of time researching the vulnerability of Adobe Flash because we foresee the problem getting worse before it gets better," Holly Stewart, threat response manager at IBM (NYSE: IBM) Internet Security Systems' X-Force research team told InternetNews.com by e-mail.

At the end of 2008, 15 percent of all malicious links were to Flash movies containing malware, Stewart said. She added that people continue falling victim to Flash exploits because most of them do not patch Adobe applications when these are available.

The latest vulnerability lets attackers take control of victims' computers through a buffer overflow, Adobe said in a security bulletin. It occurs in Adobe Flash Player 10.0.12.36 and earlier versions, Adobe said. The vendor has issued a patch for the vulnerability, which it has named APSB09-01.

Adobe's bulletin said the user must load a malicious Shockwave Flash (SWF) file in the Flash Player before hackers can exploit the vulnerability. SWF files can contain animations or applets with different functions.

That need to download a malicious SWF file first could mean hackers would have to launch a two-pronged attack of the kind that hit the Microsoft Excel zero-day vulnerability earlier this week.

Adobe did not respond to requests for comment by press time.

The patch released this week also resolves other possible attacks. One could lead to a Denial of Service attack; another, for Linux only, could lead to privilege escalation, meaning an attacker could get more extensive privileges after hacking into a system.

Two other possible attacks are Clickjacking (define) attacks. One affects Windows systems only and the other affects Flash Player itself, Adobe's Web site said.

In with the New

Adobe's Web site recommends users update to the most current version of Flash Player available for their platform. Users can go to this Adobe site to verify the version of Flash Player on their computers.

Flash Player versions 10 and later are not available for the Microsoft Windows 98 or Windows ME, Apple Macintosh OSX 10.1 to 10.3, and Red Hat Enterprise Linux 3 and 4, Adobe said on its Web site. That is because they are not supported on older operating systems and these operating systems' manufacturers will not fix problems in them, according to Adobe's Web site.

Adobe has developed Flash Player 9.0.159.0, a patched version of Flash Player 9, for users who cannot update to version 10. It can be downloaded from this Web page.

This is the second time since November that Adobe has had to issue a patch for Flash.

Security experts contend that Flash Player has too many features that are hidden so users cannot configure it. "Flash is a frightening technology in that Adobe has tried to make it do so many things in addition to playing content," Randy Abrams, director of technical education at antivirus vendor ESET, told InternetNews.com.

"If Adobe doesn't get real smart about making the Flash Player user configurable, they may end up playing second fiddle to Microsoft Silverlight instead of being in the lead as they are now."

Flash and Silverlight are locked in a heated battle for market share.

News courtesy of internetnews.com

February 27, 2008

Download Adobe Flash Player Now!Download

Download Microsoft Silverlight Now!Download

View All Browser Add-ons

Contents:
1. Adobe Flash Player a Clear and Present Danger?


Additional Articles:

  • Macromedia Extends Flash Show
  • Flash Users Advised to Upgrade
  • Flash 9 a Multi-Codec 'Moviestar'
  • Adobe Flash Player 10 Beta Brings Smoother Streaming
  • Adobe's Latest Flash Now Includes 3D Video
  • Adobe Unveils Another Set of Critical Patches
  • Adobe Flash Player 10 Gets Ready to Mobilize
  • Adobe Flash, PDF Hit by Zero-Day Flaw
  • Is Adobe Leaving the Web Open to Attack?
  • Mozilla Firefox Upgrades 10 Million Flash Users


  • internet.commediabistro.comJusttechjobs.comGraphics.com

    Search:

    WebMediaBrands Corporate Info

    Legal Notices, Licensing, Permissions, Privacy Policy.
    Advertise | Newsletters | Shopping | E-mail Offers | Freelance Jobs