Security experts have found a way to bypass the security measure of Adobe Flash that is supposed to protect against hacking attacks, reports cert.hr
Google researcher Billy Rios published a method on his personal website that bypasses the local-with-filesystem sandbox protection intended to prevent access to Flash files over the network. The so-called SWF files should be locked so that they cannot communicate with the outside world. This would prevent malicious Flash content from sending confidential data to computers controlled by attackers. Rios discovered that this security measure can be bypassed using requests that start with file://. An attacker can retrieve data from an infected computer with a simple GET request to the address file://192.168.1.1. To retrieve data over the Internet, the attacker can use application implementations of protocols that are not blacklisted by Adobe developers. An Adobe spokesperson notes that this security vulnerability is not critical because to exploit the vulnerability, an attacker must place a malicious SWF file on the local computer and prompt the user to execute it. www.cert.hr