Update: Adobe has released an update to counter the zero-day exploit

Page 3 - Seeking answers? Join the AnandTech community: where nearly half-a-million members share solutions and discuss the latest tech.

balloonshark

Diamond Member
Jun 5, 2008
6,404
2,841
136
How do I disable flash not working when firefox and palemoon deem it vulnerable. I want to update when I feel like it, not when my browser forces me. I have several security layers so being outdated isn't a problem.

I tried this in about:config.

plugins.hide_infobar_for_outdated_plugin true
 

Ketchup

Elite Member
Sep 1, 2002
14,546
238
106
FYI, I told Flash to update this morning, and I am now at 16.0.0.305. No further warnings. Hopefully the zero-day exploit was taken care of.
 

Chiefcrowe

Diamond Member
Sep 15, 2008
5,049
182
116
I agree here, I see the same thing on FB and it is kind of annoying.

Of course, though I wish that blocking solutions would receive more development attention because 'ask to activate' in FF is rather hit and miss, especially on Facebook (integrated videos don't work a lot of the time and I had to open the link in a new tab for it to consistently work).
 

John Connor

Lifer
Nov 30, 2012
22,840
617
121
Only to the extent that it would block flash being loaded. It does not make the use of Flash after it's already been loaded more secure. As I've said before, using Flash in the confines of the Chrome sandbox is the most secure way to use Flash.

I use Sandboxie.
 

John Connor

Lifer
Nov 30, 2012
22,840
617
121
Admittedly I can't think of a way to answer this question, but I wonder how likely it is for a Flash exploit to be included as part of a Flash clip that a user actually wants to view.

AFAIK, I would expect the most likely sources of exploits to be a) adverts or b) phishing sites.

If I'm correct, then NoScript would probably provide better protection than anything else out there (assuming the user hasn't done something stupid like "enable JS globally" or, if there is such an option, "enable non-third party JS globally). Alternatively, the "Ask to activate" plug-in feature would also provide better protection than say Chrome sandboxing.

PS - I realise that in the case of the "phishing site" scenario I mentioned, a user might well get duped into loading dodgy JS / plug-in exploits, but it's (NoScript/Ask to Activate) still an additional hurdle for malware designers to overcome.


In NoScript you can block the plugin and collapse the block. To activate you have to click the little box and a confirmation comes up.
 

PliotronX

Diamond Member
Oct 17, 1999
8,883
107
106
What I don't get about how insecure flash is, is why does the flash application even have code that allows those things to happen? Flash is basically a client to display information. It should not actually be able to DO things that change your computer. It should only be able to display you content.

Another one that always gets me even more is PDFs. Those are basically glorified images that require an overcomplicated viewer. Why is there so many exploits in those products?

Throw java in there too. Don't think about it, it only hurts your head. A popular vehicle I am seeing besides fake java and flash updates is unofficial chrome and Firefox installers loaded with malware. A couple of systems were booting to the black screen with a cursor.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |