1. Home
  2. Computing & Technology
  3. Animation
photo of Adrien-Luc Sanders
Adrien-Luc's Animation Blog

By Adrien-Luc Sanders, About.com Guide to Animation since 2005

Has Flash made your website vulnerable?

Wednesday December 26, 2007
screencapped from the Adobe website, copyright AdobeWhile it's been known for some time that Flash possesses security vulnerabilities that allow malicious code exploits, The Register reports that researchers from Google estimate thousands of websites may be susceptible to attacks and theft of personal data. Cross-site scripting, or XSS, allows for the insertion of malicious code through bugs in simple ActionScripting. Adobe currently hasn't released a patch, but according to the article has promised patches within the next few weeks. Until then, however, Firefox users can make use of the plugin NoScript to block Flash content on sites that transmit personal data or other sensitive information. Another plugin is NoFlash for IE.

Is your site vulnerable? Ask yourself if you gather any sensitive data, what kind of encryption you use, and whether or not any Flash files are used on the pages that gather that data or pages that the data is passed to. Ask yourself, too, if you can minimize the inclusion of Flash in just those pages. At the moment data protection is neither easy nor quick, but until the promised patches are released, it's better to be safe than sorry.

Comments

No comments yet. Leave a Comment

Leave a Comment

Line and paragraph breaks are automatic. Some HTML allowed: <a href="" title="">, <b>, <i>, <strike>

Explore Animation
About.com Special Features

Stay connected and entertained with reviews on tips on the latest HDTVs, cellphones and more. More >

Easy ways to connect two computers for networking purposes. More >

  1. Home
  2. Computing & Technology
  3. Animation

©2009 About.com, a part of The New York Times Company.

All rights reserved.