Flash 0-day targetting 16.0.0.257

TheRyuu

Diamond Member
Dec 3, 2005
5,479
14
81
Last edited:

John Connor

Lifer
Nov 30, 2012
22,840
617
121
Just when the hell will HTML 5 take a hold? Why doesn't YouTube just ditch Flash and force the HTML 5 revolution?

NoScript and Sandboxie FTW!
 

balloonshark

Diamond Member
Jun 5, 2008
6,401
2,838
136
I got tired of playing the update game a long time ago. I got rid of crap like java, itunes, real player, etc. Unfortunately I need flash so I also rely on noscript, sandboxie, limited user account and a few other goodies to mitigate the constant flow of vulnerabilities. It's a setup that works for me and now I update when I feel like it instead of worrying about vulnerabilities and exploits.
 

MustISO

Lifer
Oct 9, 1999
11,928
12
81
Haven't had flash in years and in the past year it's been no issue with sites like YouTube. Seems like now I can watch pretty much anything. There's still some videos I can't see but that's perfectly fine given the risk of having flash.
 

seepy83

Platinum Member
Nov 12, 2003
2,132
3
71

TheRyuu

Diamond Member
Dec 3, 2005
5,479
14
81
Just when the hell will HTML 5 take a hold? Why doesn't YouTube just ditch Flash and force the HTML 5 revolution?

NoScript and Sandboxie FTW!

Youtube already did do that. I also doubt HTML5 will be the end of the exploits. It may lead to a reduction with the possibility of a reduced attack surface but bugs can exist in the HTML5 code as well.

Came here to post this, beat me to it:
Just FYI - there was a new patch for one of the recent Flash vulnerabilities (CVE-2015-0310) released yesterday (http://helpx.adobe.com/security/products/flash-player/apsb15-02.html).

However, there is still another unpatched vulnerability (CVE-2015-0311) that is expected to be released sometime next week (http://helpx.adobe.com/security/products/flash-player/apsa15-01.html)

isc.sans.edu has raised the Infocon Threat Level to Yellow as a result of this unpatched Flash vulnerability.

Also of note, I'm not entirely sure if Chrome is also vulnerable but apparently it wasn't being targeted from what I understand[1]. I'm not sure if this is for one or both of the reported vulnerabilities.

EMET 5.1 also appears to block the exploit in IE11 32-bit[1].

[1] http://malware.dontneedcoffee.com/2015/01/unpatched-vulnerability-0day-in-flash.html
 
Last edited:

postmortemIA

Diamond Member
Jul 11, 2006
7,721
40
91
Just when the hell will HTML 5 take a hold? Why doesn't YouTube just ditch Flash and force the HTML 5 revolution?

NoScript and Sandboxie FTW!
it did took a good hold because of mobile devices. Android and OSX browsers support it, but not Flash. Many sites will automatically switch to HTML5 player when they detect browser without Flash.

I have Flash disabled, and only site that I visit that is not on HTML5 yet is ESPN. For a few months I have enjoyed many sites mostly ad-free, since flash ads would not be loaded; but now they wised up and they're playing HTML5 ads.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |