<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.3" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: Yet Another Adobe Flash Unpatched Vulnerability Actively Exploited in the Wild</title>
	<link>http://hackademix.net/2010/09/14/yet-another-adobe-flash-unpatched-vulnerability-actively-exploited-in-the-wild/</link>
	<description>Giorgio Maone's answers to the Web, the Universe, and Everything</description>
	<pubDate>Wed, 16 May 2012 22:14:34 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.3</generator>

	<item>
		<title>By: Alan Baxter</title>
		<link>http://hackademix.net/2010/09/14/yet-another-adobe-flash-unpatched-vulnerability-actively-exploited-in-the-wild/#comment-23978</link>
		<dc:creator>Alan Baxter</dc:creator>
		<pubDate>Mon, 20 Sep 2010 01:55:29 +0000</pubDate>
		<guid>http://hackademix.net/2010/09/14/yet-another-adobe-flash-unpatched-vulnerability-actively-exploited-in-the-wild/#comment-23978</guid>
		<description>@Dan:
I haven't figured out how to do that either.  So, whenever I'm on a site where I want to allow all Flash instead of just using the placeholder, I use NoScript's Blocked Objects flyout to temporarily enable it for the whole site (on trusted sites only, of course).</description>
		<content:encoded><![CDATA[<p>@Dan:<br />
I haven&#8217;t figured out how to do that either.  So, whenever I&#8217;m on a site where I want to allow all Flash instead of just using the placeholder, I use NoScript&#8217;s Blocked Objects flyout to temporarily enable it for the whole site (on trusted sites only, of course).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dan</title>
		<link>http://hackademix.net/2010/09/14/yet-another-adobe-flash-unpatched-vulnerability-actively-exploited-in-the-wild/#comment-23977</link>
		<dc:creator>Dan</dc:creator>
		<pubDate>Mon, 20 Sep 2010 00:57:12 +0000</pubDate>
		<guid>http://hackademix.net/2010/09/14/yet-another-adobe-flash-unpatched-vulnerability-actively-exploited-in-the-wild/#comment-23977</guid>
		<description>How can I run NoScript in &#34;Flashblock mode&#34; but still whitelist some sites for Flash? I can't seem to get it to work after a bit of trying. If it's not that simple, then getting people to migrate from Flashblock will be more difficult.</description>
		<content:encoded><![CDATA[<p>How can I run NoScript in &quot;Flashblock mode&quot; but still whitelist some sites for Flash? I can&#8217;t seem to get it to work after a bit of trying. If it&#8217;s not that simple, then getting people to migrate from Flashblock will be more difficult.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: JB</title>
		<link>http://hackademix.net/2010/09/14/yet-another-adobe-flash-unpatched-vulnerability-actively-exploited-in-the-wild/#comment-23968</link>
		<dc:creator>JB</dc:creator>
		<pubDate>Fri, 17 Sep 2010 18:09:05 +0000</pubDate>
		<guid>http://hackademix.net/2010/09/14/yet-another-adobe-flash-unpatched-vulnerability-actively-exploited-in-the-wild/#comment-23968</guid>
		<description>Any idea when you'll fix the &#34;Backup NoScript configuration in a bookmark for easy synschronization feature&#34; for Firefox 4, when I check that feature, no bookmark is created.  Works fine on Firefox 3.6.9.</description>
		<content:encoded><![CDATA[<p>Any idea when you&#8217;ll fix the &quot;Backup NoScript configuration in a bookmark for easy synschronization feature&quot; for Firefox 4, when I check that feature, no bookmark is created.  Works fine on Firefox 3.6.9.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: AnonymousCoward</title>
		<link>http://hackademix.net/2010/09/14/yet-another-adobe-flash-unpatched-vulnerability-actively-exploited-in-the-wild/#comment-23967</link>
		<dc:creator>AnonymousCoward</dc:creator>
		<pubDate>Fri, 17 Sep 2010 13:30:00 +0000</pubDate>
		<guid>http://hackademix.net/2010/09/14/yet-another-adobe-flash-unpatched-vulnerability-actively-exploited-in-the-wild/#comment-23967</guid>
		<description>Oh man, what a bad beta that EMET is in XP so far.  Enhanced Mitigation EXPERIMENT Tool. The promised version was NOT in the DL link, and no way could I get Flash on the block list.  And a hefty 18MB needed on the disc.
Nice idea though, and if you get the video http://technet.microsoft.com/en-us/security/ff859539.aspx you can see that MS means really to stop legacy applications getting hit.  Those guys are just too sweet :-)

It's just that for stuff out here on the Web, Fx with NS just does it with no mess and no fuss :-)</description>
		<content:encoded><![CDATA[<p>Oh man, what a bad beta that EMET is in XP so far.  Enhanced Mitigation EXPERIMENT Tool. The promised version was NOT in the DL link, and no way could I get Flash on the block list.  And a hefty 18MB needed on the disc.<br />
Nice idea though, and if you get the video <a href="http://technet.microsoft.com/en-us/security/ff859539.aspx" rel="nofollow">http://technet.microsoft.com/en-us/security/ff859539.aspx</a> you can see that MS means really to stop legacy applications getting hit.  Those guys are just too sweet :-)</p>
<p>It&#8217;s just that for stuff out here on the Web, Fx with NS just does it with no mess and no fuss :-)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2010/09/14/yet-another-adobe-flash-unpatched-vulnerability-actively-exploited-in-the-wild/#comment-23966</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Fri, 17 Sep 2010 07:08:36 +0000</pubDate>
		<guid>http://hackademix.net/2010/09/14/yet-another-adobe-flash-unpatched-vulnerability-actively-exploited-in-the-wild/#comment-23966</guid>
		<description>@&lt;a href="http://hackademix.net/2010/09/14/yet-another-adobe-flash-unpatched-vulnerability-actively-exploited-in-the-wild/#comment-23964" rel="nofollow"&gt;Cement Head&lt;/a&gt;:
Plugins run out of process now in most recent browser versions, so you should actually protect the plugin-host process.
Even so, many plugins (including Flash and Java) can't be effectively protected because contain JIT compilers, which need write access to executable memory.</description>
		<content:encoded><![CDATA[<p>@<a href="http://hackademix.net/2010/09/14/yet-another-adobe-flash-unpatched-vulnerability-actively-exploited-in-the-wild/#comment-23964" rel="nofollow">Cement Head</a>:<br />
Plugins run out of process now in most recent browser versions, so you should actually protect the plugin-host process.<br />
Even so, many plugins (including Flash and Java) can&#8217;t be effectively protected because contain JIT compilers, which need write access to executable memory.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cement Head</title>
		<link>http://hackademix.net/2010/09/14/yet-another-adobe-flash-unpatched-vulnerability-actively-exploited-in-the-wild/#comment-23964</link>
		<dc:creator>Cement Head</dc:creator>
		<pubDate>Fri, 17 Sep 2010 03:25:01 +0000</pubDate>
		<guid>http://hackademix.net/2010/09/14/yet-another-adobe-flash-unpatched-vulnerability-actively-exploited-in-the-wild/#comment-23964</guid>
		<description>@exceed:
Why can't you use EMET to protect the web browser in which the Flash plug-in is running?</description>
		<content:encoded><![CDATA[<p>@exceed:<br />
Why can&#8217;t you use EMET to protect the web browser in which the Flash plug-in is running?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alan Baxter</title>
		<link>http://hackademix.net/2010/09/14/yet-another-adobe-flash-unpatched-vulnerability-actively-exploited-in-the-wild/#comment-23956</link>
		<dc:creator>Alan Baxter</dc:creator>
		<pubDate>Wed, 15 Sep 2010 04:29:49 +0000</pubDate>
		<guid>http://hackademix.net/2010/09/14/yet-another-adobe-flash-unpatched-vulnerability-actively-exploited-in-the-wild/#comment-23956</guid>
		<description>@Giorgio:
Oh, I get it now after rereading it.  The joke was good, but it was too early in the morning for me to get it the first time.</description>
		<content:encoded><![CDATA[<p>@Giorgio:<br />
Oh, I get it now after rereading it.  The joke was good, but it was too early in the morning for me to get it the first time.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: exceed</title>
		<link>http://hackademix.net/2010/09/14/yet-another-adobe-flash-unpatched-vulnerability-actively-exploited-in-the-wild/#comment-23953</link>
		<dc:creator>exceed</dc:creator>
		<pubDate>Tue, 14 Sep 2010 23:07:34 +0000</pubDate>
		<guid>http://hackademix.net/2010/09/14/yet-another-adobe-flash-unpatched-vulnerability-actively-exploited-in-the-wild/#comment-23953</guid>
		<description>Unfortunatelly it's not possible to EMET-ize Flash... but there's a NoScriot anyway :D</description>
		<content:encoded><![CDATA[<p>Unfortunatelly it&#8217;s not possible to EMET-ize Flash&#8230; but there&#8217;s a NoScriot anyway :D</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: computerfreaker</title>
		<link>http://hackademix.net/2010/09/14/yet-another-adobe-flash-unpatched-vulnerability-actively-exploited-in-the-wild/#comment-23948</link>
		<dc:creator>computerfreaker</dc:creator>
		<pubDate>Tue, 14 Sep 2010 19:54:57 +0000</pubDate>
		<guid>http://hackademix.net/2010/09/14/yet-another-adobe-flash-unpatched-vulnerability-actively-exploited-in-the-wild/#comment-23948</guid>
		<description>&#34;3 or 4 Flash users&#34; is probably going to be pretty darn accurate if Adobe keeps getting their products pwned like this. Between Flash and their PDF reader, Adobe is in deep trouble IMHO.

I'm glad NoScript is blocking this in Firefox, but I think it's finally time for me to uninstall Flash and Adobe PDF Reader, regardless of what breaks as a result. I have to use at least one non-Firefox browser every day, so NoScript's great protection regrettably won't cover me 100% of the time.</description>
		<content:encoded><![CDATA[<p>&quot;3 or 4 Flash users&quot; is probably going to be pretty darn accurate if Adobe keeps getting their products pwned like this. Between Flash and their PDF reader, Adobe is in deep trouble IMHO.</p>
<p>I&#8217;m glad NoScript is blocking this in Firefox, but I think it&#8217;s finally time for me to uninstall Flash and Adobe PDF Reader, regardless of what breaks as a result. I have to use at least one non-Firefox browser every day, so NoScript&#8217;s great protection regrettably won&#8217;t cover me 100% of the time.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio</title>
		<link>http://hackademix.net/2010/09/14/yet-another-adobe-flash-unpatched-vulnerability-actively-exploited-in-the-wild/#comment-23947</link>
		<dc:creator>Giorgio</dc:creator>
		<pubDate>Tue, 14 Sep 2010 18:00:35 +0000</pubDate>
		<guid>http://hackademix.net/2010/09/14/yet-another-adobe-flash-unpatched-vulnerability-actively-exploited-in-the-wild/#comment-23947</guid>
		<description>@&lt;a href="http://hackademix.net/2010/09/14/yet-another-adobe-flash-unpatched-vulnerability-actively-exploited-in-the-wild/#comment-23944" rel="nofollow"&gt;Alan Baxter&lt;/a&gt;:
It was "3 or 4" as written, my poor attempt at irony :)
All them are vulnerable, though.

@&lt;a href="http://hackademix.net/2010/09/14/yet-another-adobe-flash-unpatched-vulnerability-actively-exploited-in-the-wild/#comment-23945" rel="nofollow"&gt;Citizendruide&lt;/a&gt;:
I really doubt Firefox will blacklist an high profile plugin like Flash. Maybe when HTML 5 starts to be seen (and most important, deployed) as a credible replacement.

@&lt;a href="http://hackademix.net/2010/09/14/yet-another-adobe-flash-unpatched-vulnerability-actively-exploited-in-the-wild/#comment-23946" rel="nofollow"&gt;Giovanni Bajo&lt;/a&gt;:
Sandboxes are overrated. A compromised plugin with full network access (like Flash) can do a lot of damage even if it couldn't touch anything on your local system, now that &lt;a href="http://hackademix.net/2008/01/12/malware-20-is-now/" rel="nofollow"&gt;our lives move more and more "in the cloud"&lt;/a&gt;.</description>
		<content:encoded><![CDATA[<p>@<a href="http://hackademix.net/2010/09/14/yet-another-adobe-flash-unpatched-vulnerability-actively-exploited-in-the-wild/#comment-23944" rel="nofollow">Alan Baxter</a>:<br />
It was &#8220;3 or 4&#8243; as written, my poor attempt at irony :)<br />
All them are vulnerable, though.</p>
<p>@<a href="http://hackademix.net/2010/09/14/yet-another-adobe-flash-unpatched-vulnerability-actively-exploited-in-the-wild/#comment-23945" rel="nofollow">Citizendruide</a>:<br />
I really doubt Firefox will blacklist an high profile plugin like Flash. Maybe when HTML 5 starts to be seen (and most important, deployed) as a credible replacement.</p>
<p>@<a href="http://hackademix.net/2010/09/14/yet-another-adobe-flash-unpatched-vulnerability-actively-exploited-in-the-wild/#comment-23946" rel="nofollow">Giovanni Bajo</a>:<br />
Sandboxes are overrated. A compromised plugin with full network access (like Flash) can do a lot of damage even if it couldn&#8217;t touch anything on your local system, now that <a href="http://hackademix.net/2008/01/12/malware-20-is-now/" rel="nofollow">our lives move more and more &#8220;in the cloud&#8221;</a>.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

