adobe flash player, Browsers, clickjacking, flash vulnerability

Adobe Flash Player Clickjacking Vulnerability

October 8, 2008

The recently reported clickjacking vulnerability affecting Adobe Flash Player could also allow a hacker to remotely activate a computer’s microphone and webcam (meaning they could see and hear what you were doing).

clickjacking flash playerThe Adobe Security Blog is reporting that a Flash Player patch should be available by the end of October and until it is released, they are encouraging users to change their browser’s Flash Player settings by following these steps as a temporary workaround:

  1. Access the Flash Player’s Global Privacy Settings panel at the following URL: http://www.adobe.com/support/documentation/en/flashplayer/help/settings_manager02.html
  2. Click “Always deny”
  3. Click ‘Confirm’

Completing those steps will keep the bad guys from remotely accessing your computer’s webcam and microphone – although I am not sure why that ability was even an option in the first place with Flash Player.  Why would someone, good guy or bad, even need the ability to remotely access and control another person’s microphone?

Since YouTube and other online video sites use Flash to display the videos, users that frequent those types of sites could be particularly vulnerable, I would think.

UPDATE: Adobe has released Flash Player 10.0.12.36 which fixes the potential clickjacking issue that still exists in previous versions.  Adobe’s security bulletin recommends downloading and installing the latest version.  If you cannot download it, you should follow the steps above and they hope to have a patch ready in November.

designer

CCT

Are You Ready?

When you are ready to get more specific information about your project, click here and fill out our handy online form for a free web design quote.

Get My Free Quote

you need a website?
we can help

    order a project

    arrow

    Recent Posts

    In Web Design

    Domain Name Services fake letter.

    adobe flash player, Browsers, clickjacking, flash vulnerability

    Domain Name Services Scam - Kind of

    Oct 8, 2008

    The recently reported clickjacking vulnerability affecting Adobe Flash Player could also allow a hacker to remotely activate a computer’s microp...

    Captivating Website Design - Morehead City NC

    adobe flash player, Browsers, clickjacking, flash vulnerability

    Web Design Basics

    Oct 8, 2008

    The recently reported clickjacking vulnerability affecting Adobe Flash Player could also allow a hacker to remotely activate a computer’s microp...

    Dynamic Web Design in Morehead City NC

    adobe flash player, Browsers, clickjacking, flash vulnerability

    Three Common Web Design Mistakes

    Oct 8, 2008

    The recently reported clickjacking vulnerability affecting Adobe Flash Player could also allow a hacker to remotely activate a computer’s microp...

    arrow

    Go to our blog