Showing posts with label Flash. Show all posts
Showing posts with label Flash. Show all posts

Thursday, February 7, 2013

Nerd News: Flash Update

YMMV but Firefox wasn't showing that I needed to update Flash yet, and this isn't the first time this has happened to me, perhaps they only update that once or twice a day or something?

Anyway, there is a new version of Flash out, and to avoided getting Hacked you should update/patch Flash if you use it.

This page http://www.adobe.com/software/flash/about/ will show you in a little box on right near top what version of Flash your running if you don't have it disabled.

It will even show the Chrome (Pepper Based) version of Flash.  Though you shouldn't have to worry about patching Chrome's version this way.


Below that little box, is a bigger box showing most recent versions of Flash for all OS & Browser combinations, so you can easily see if your running most current version or not.

You can download current version from here http://get.adobe.com/flashplayer/.

For Chrome, all you need to do to check, is click the Chrome Menu/three bar button, then click About Google Chrome, that will trigger update for Chrome.

Note I generally include full links so people can Google links easily, just highlight and right click "search Google for", instead of just clicking if they have any doubt about link being legit.

I do skip full links sometimes when they are just to long IMO, or I am using several in a row with text, where I feel the confusion factor vs transparency ratio gets out of whack.

You can also use siteadvisor https://www.siteadvisor.com/sites/ or WOT http://www.mywot.com/en/scorecard to check links.

Unshort.me, http://unshort.me/, is also a very useful tool, it will unshorten URL from Twitter or whatever, so you can see real target without having to go to site.

I tend to use siteadvisor, which is a McAfee service, don't like their AV but do like siteadvisor, I tend to use WOT for things not on siteadvisor or for "gray" sites.

Thursday, September 6, 2012

Security & Hacking: Windows 8 Internet Explorer 10 has vulnerable Flash unpatchable via Adobe

Story at http://arstechnica.com/information-technology/2012/09/internet-explorer-10s-bundled-flash-leaves-users-exploitable/

User can't patch via Adobe, have to wait till Microsoft pushes update from what I understand.

Is it just me, or do some of these company's seem to forget lessons about security they have already learned?

Thursday, February 16, 2012

PSA: XSS bug in Adobe Flash controlled users' Web accounts

Full story at Ars, but this is the part that got my attention:
Most XSS vulnerabilities are the result of coding errors on a specific website. A universal XSS, by contrast, stems from bugs present in browsers or plugins and can be exploited as they access multiple sites. Besides its zero-day status as a vulnerability—meaning it was fixed only after it was under attack—the Flash bug is noteworthy because it affects software that is installed on a majority of the world's computers. What's more, universal XSS vulnerabilities typically give an attacker the ability to run custom-written JavaScript in a victim's browser that can steal authentication cookies used to log into private accounts and take similar actions, such as send spam or messages to all addresses contained in an address book.



Security bulletin from Adobe https://www.adobe.com/support/security/bulletins/apsb12-03.html, "Adobe categorizes these as critical updates and recommends users update their installations to the newest versions."


So you might want to make sure your up to date, if you don't do that automatically. 

Personally I like to manually check upgrades on a weekly basis, more to make sure I think about security.  It helps me make thinking about security risks a habit.