Skip to content

Comment on Root access to MySQL.com sold for $3k - now serving malware

Comments

Why is it that Flash is so exploitable? The web is rampant with Flash exploits and Adobe seems to do nothing about it.

Because plugins run under their own process. Not subject to the sandboxing you'd find in Chrome/Safari for instance. Plugins are given pretty high trust.

I always browse with all plugins and java disabled. If a site uses Flash, I typically will just move on unless it's something absolutely essential to what I'm doing. Surprising how many sites that use Flash don't have any usable fallback for clients that don't support it or have it disabled.

I don't think I've come across a Java applet in the last 5 years. I see NO need to allow Java in the browser unless it's for a trusted, internal-use application.

Good move. I suppose the most vulnerable are those driving desks being forced to use IE7, Standard Operating Environment that runs these plugins or some internal business application requires them.

This was a Java Exploit.

> “It exploits the visitor’s browsing platform (the browser, the browser plugins like Adobe Flash, Adobe PDF, etc, Java, …)

Both Java and Flash. Java was more dangerous, but still...

I decoded the scripts on some recent WordPress blogs that were hacked. It would try to exploit Java first, then Flash if that didn't work, and then a couple other things if I recall correctly.

Flash is likely the single most installed software in the world. Consider how many Windows, Mac, and Linux desktops and Android devices have Flash. Thus, Flash is an extremely popular target for bad guys.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.