Text Size

Symantec: Flash exploit in widespread use

updated 11:10 am EDT, Wed May 28, 2008

Widespread Flash exploit

Hundreds of thousands of webpages have been affected by a vulnerability in Adobe's Flash Player, says security vendor Symantec. Since at least Monday, approximately 220,000 pages have been been hacked to add redirection scripts, which send Flash users to some 57 servers that attempt to deliver malware, including botnet code and apps that steal World of WarCraft identities and passwords. Only Flash Player versions 9.0.124.0 and 9.0.115.0 appear to be at risk; the attack also seems to be directed primarily at Windows, says Symantec, although problems may yet arise on other operating systems (including Mac OS X) unless Adobe can close the exploit.

Sites victimized by the redirection scripts are generally said to be those belonging to small towns, businesses and non-profit organizations, which may have been chosen through a tool that uses Google to trawl for pages with security holes. If an attack fails, Symantec notes that it may still crash a user's browser.

Adobe has yet to confirm or deny the security issue. "We are working with Symantec to investigate the potential SWF vulnerability," an official statement reads, "and will have an update once we get more information."

 
Previous Comments

MacNN

05/28, 01:15pm reply

you might want to get an updated Flash Player Icon

That one has not been in use for over a year now

UberFu

Fresh-Faced Recruit

Joined: Oct 2002

0

No Flash for me

05/28, 01:20pm reply

I don't like Flash at all. Flash is nothing but a tool for advertisers.

Gepard

Fresh-Faced Recruit

Joined: Sep 2000

-1

Great!

05/28, 01:31pm reply

Another reason to hate Flash web sites!

gskibum3

Fresh-Faced Recruit

Joined: Nov 2006

+1

Flashblock

05/28, 01:50pm reply

Well, I use Firefox with the Flashblock extension anyway. It saves a lot of headache when I surf.

Grendelmon

Fresh-Faced Recruit

Joined: Dec 2007

+3

I Wonder

05/28, 02:57pm reply

If the old Macromedia garb people are chuckling now

Roehlstation

Fresh-Faced Recruit

Joined: Aug 2001

+2

Flash exploit

05/28, 04:03pm reply

Isn't that a bit redundant?

ff11

Fresh-Faced Recruit

Joined: Apr 2004

+3

harshing on flash

05/28, 10:11pm reply

I like Flash, but it's overused and improperly used by bad designers.

climacs

Fresh-Faced Recruit

Joined: Sep 2001

+5

Popular News