Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 01-28-2015, 07:58 PM   #1
Rik Lear
Confirmed User
 
Rik Lear's Avatar
 
Industry Role:
Join Date: Oct 2013
Location: Jacuzzi
Posts: 112
NEWS: Updated - ADOBE Exploit Targeting Adult

At this point, I think it's safe to call the security level of Adobe's Flash player "asinine". Sometimes, it feels like full-blown OSes, such as Windows, have far fewer bugs.

Adobe issued a patch for bug CVE-2015-0311, one that exposes a user's browser to become vulnerable to code injection, and the now infamous Angler EK (Exploit Kit). To fall victim to this kind of attack, all someone needs to do is visit a website with compromised Flash files, at which point the attacker can inject code and utilize Angler EK, which has proven to be an extremely popular tool over the past year. This particular version of Angler EK is different, however. For starters, it makes use of obfuscated JavaScript and attempts to detect virtual machines and anti-virus products. Its target audience is also rather specific: porn watchers. According to FireEye, which has researched the CVE-2015-0311 vulnerability extensively, this exploit has reached people via banner ads on popular adult websites. It was also noted that even a top 1000 website was affected, so it's not as though victims are surfing to the murkiest depths of the web to come in contact with it.

Care of the beautiful ones @ SLASHDOT.ORG
__________________
52 185 317
I listen to Korn and Enya on random repeat.
Rik Lear is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-28-2015, 08:06 PM   #2
pornmasta
Too lazy to set a custom title
 
pornmasta's Avatar
 
Join Date: Jun 2006
Posts: 19,021
thanks for the news
pornmasta is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-28-2015, 08:29 PM   #3
pornmasta
Too lazy to set a custom title
 
pornmasta's Avatar
 
Join Date: Jun 2006
Posts: 19,021
Someone knows what is this top1000 website that is affected ?
pornmasta is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-28-2015, 08:41 PM   #4
Rik Lear
Confirmed User
 
Rik Lear's Avatar
 
Industry Role:
Join Date: Oct 2013
Location: Jacuzzi
Posts: 112
Quote:
Originally Posted by pornmasta View Post
Someone knows what is this top1000 website that is affected ?
It appears that this is a bit worse (much) than others over the years. If you read the article, it's pretty blowmind. Just a banner can inject code. Also, don't forget that YouTube finally made the conversion site-wide last week or so away from Flash altogether.

Flash is so pathetic, vulnerable and open, I'm amazed it's lasted this long. Any good coder will tell you that.

And, a "Top 1000" site just means that it's a matter of time before this exponentially replicates to the higher ups. But... Most here at GFY are without a doubt part of the less-than-1000 sites online around the world. I hope this leads more & more masters/mistresses AWAY from any & all Flash permanently from now on.

All of my new sites are being built with ani-gifs & JS. Any sponsor using page-peel, banner flash, and any other flash aspects should be highly suspect from now on. FLASH-IS-DEAD and should remain that way. And should not be allowed on any sites any longer - including this one.
__________________
52 185 317
I listen to Korn and Enya on random repeat.
Rik Lear is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-28-2015, 09:23 PM   #5
pornmasta
Too lazy to set a custom title
 
pornmasta's Avatar
 
Join Date: Jun 2006
Posts: 19,021
yes thanks, i create flash games and for some reasons it is more convenient that html5
Also i play from time to time with flash binaries and i have no reason to think that...

yeah cool, flash is dead for a single exploit...
pornmasta is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-28-2015, 09:36 PM   #6
Rik Lear
Confirmed User
 
Rik Lear's Avatar
 
Industry Role:
Join Date: Oct 2013
Location: Jacuzzi
Posts: 112
Quote:
Originally Posted by pornmasta View Post
yes thanks, i create flash games and for some reasons it is more convenient that html5
Also i play from time to time with flash binaries and i have no reason to think that...

yeah cool, flash is dead for a single exploit...
If you create flash games you have a lot of balls saying "flash is dead for a single exploit..."

Are you seriously saying that? Really? I'm blown away man.

Because that's like saying earthquakes have only happened once in California. You should hook up on the news for the last decade or so. You remember, back in the Macromedia days and beyond.

Get in touch with some good & experienced coders and tell them what you just posted here.
__________________
52 185 317
I listen to Korn and Enya on random repeat.
Rik Lear is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-28-2015, 09:37 PM   #7
pornmasta
Too lazy to set a custom title
 
pornmasta's Avatar
 
Join Date: Jun 2006
Posts: 19,021
Quote:
Originally Posted by Rik Lear View Post
Also, don't forget that YouTube finally made the conversion site-wide last week or so away from Flash altogether.
.
html5 is the default option for CHROME !
pornmasta is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-28-2015, 09:38 PM   #8
pornmasta
Too lazy to set a custom title
 
pornmasta's Avatar
 
Join Date: Jun 2006
Posts: 19,021
Quote:
Originally Posted by Rik Lear View Post
If you create flash games you have a lot of balls saying "flash is dead for a single exploit..."

Are you seriously saying that? Really? I'm blown away man.
it's called irony
pornmasta is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-28-2015, 09:40 PM   #9
pornmasta
Too lazy to set a custom title
 
pornmasta's Avatar
 
Join Date: Jun 2006
Posts: 19,021
Quote:
Originally Posted by Rik Lear View Post
Get in touch with some good & experienced coders and tell them what you just posted here.
anyway i know that programmers can be good to promote hyped stuff: it helps them to make more money and get a rid of their competitors.
So, no, i don't care...
pornmasta is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-28-2015, 09:49 PM   #10
Rik Lear
Confirmed User
 
Rik Lear's Avatar
 
Industry Role:
Join Date: Oct 2013
Location: Jacuzzi
Posts: 112
Quote:
Originally Posted by pornmasta View Post
anyway i know that programmers can be good to promote hyped stuff: it helps them to make more money and get a rid of their competitors.
So, no, i don't care...
This is a global news story bro, and an important one at that.

But thanks for the bumps man. And grab a good AVP.

Good luck
__________________
52 185 317
I listen to Korn and Enya on random repeat.
Rik Lear is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-28-2015, 10:02 PM   #11
pornmasta
Too lazy to set a custom title
 
pornmasta's Avatar
 
Join Date: Jun 2006
Posts: 19,021
let's see, anyway, do you really things that all these flashs games will be lost for good ?

I bet that even is adobe decides to stop flash for good, that the open source community is gonna create some free stuffs that will read flash...
pornmasta is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-28-2015, 10:32 PM   #12
Rik Lear
Confirmed User
 
Rik Lear's Avatar
 
Industry Role:
Join Date: Oct 2013
Location: Jacuzzi
Posts: 112
Quote:
Originally Posted by pornmasta View Post
let's see, anyway, do you really things that all these flashs games will be lost for good ?

I bet that even is adobe decides to stop flash for good, that the open source community is gonna create some free stuffs that will read flash...
Dude, I'm watching COPS, Season 23 Episode 12 with beer & Skyy waiting for the SEAHAWKS TO FUCKING WIN THE SUPER BOWL and I don't have time to raise you in common knowledge when it comes to flash. You've been here since 2006, and should know better. Just hook up with Ars Tech & Slashdot a bit more. And polish up the grammar.

I'm out. Some chick just got slammed with a taser.
__________________
52 185 317
I listen to Korn and Enya on random repeat.
Rik Lear is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks

Tags
angler, exploit, adult, cve-2015-0311, flash, website, adobe, popular, code, porn, researched, vulnerability, fireeye, watchers, specific, products, starters, makes, version, obfuscated, javascript, anti-virus, target, machines, virtual



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.