Home  >  

Adobe Flash Clipboard Hack

Author photo
AddThis Social Bookmark Button
flashplayer

Although this was first brought to the attention of the world on August 18th in a ZDNet article, "Adobe Flash ads launching clipboard hijack attack", it seems little has been said about it since.

Apparently there is a mechanism by which a Flash movie can insert any kind of content into the clipboard. You can see it demoed here (warning once you click on this link you'll need to close down your browser if you want to use your clipboard again).

It's really spooky. While writing this blog I copied on the above demo URL and when I tried to paste into this blog entry all I got was (http://www.evil.com) instead. And the clipboard is hijacked across all applications - not just your browser.

The good news is that Adobe plans to fix this with the release of Adobe Flash Player 10. The bad news is that that everyone who uses Flash can be victimized by this attack until Flash player 10 is released (its in pre-release now). Short of uninstalling all players proceeding Flash Player 10, I'm not sure if there is any way to avoid getting your clipboard hijacked.

Read more from Richard Monson-Haefel. Richard Monson-Haefel's Atom feed

Comments

18 Comments

Quentin said:

AVAST detected the threat, which is cool.

Adrian Parr said:

Yeah, I got that too. I wonder how Avast picked it up?

Screenshot here ...

http://www.adrianparr.com/images/avast_warning.gif

Rich Tretola said:

I am running Flash Player 10 and I get an error on the test site so I assume this is blocking the hack. It does occur on Flash Player 9

Error: Error #2176: Certain actions, such as those that display a pop-up window, may only be invoked upon user interaction, for example by a mouse click or button press.
at flash.system::System$/setClipboard()
at test_fla::MainTimeline/setClip()
at Function/http://adobe.com/AS3/2006/builtin::apply()
at SetIntervalTimer/onTimer()
at flash.utils::Timer/_timerDispatch()
at flash.utils::Timer/tick()

Dillon said:

Avast shivers me timbers. Arrg! Another virus blown out of the water!

Mandy said:

Clickjacking has been fixed now already. People using it for the old copy clipboard function (which Flash 10 broke) should look for other solutions. I saw a good example here:

http://groups.google.com/group/Snipurl/web/copy-to-clipboard-not-working

dear hi all said:

AJAX does have its own category. As there ankara nakliyat are many AJAX frameworks (dojo, YUI, prototype, jQuery, Ext JS, etc). We simply ankara nakliyat chose to include AJAX as a single choice. Perhaps a future poll can drill into individual AJAX framework preferences among developers.

ankara evden eve nakliyat said:

Clickjacking has been fixed now already. People using it for the old copy clipboard function ankara nakliyat (which Flash 10 broke) should look for other solutions. I saw a good example here:

Nakliyat firmaları said:

Transportation of ankara moving express

ev taşıma said:


Clickjacking has been fixed now already. People using it for the old copy clipboard function (which Flash 10 broke) should look for other solutions

nakliyat

ankara aslanlar nakliyat said:

Clickjacking has been fixed now already. People using it for the old copy clipboard function ankara aslanlar nakliyat (which Flash 10 broke) should look for other solutions. I saw a good example here:

Nakliyeci Rehberi said:

if adobe flash 10 currently is being used, the output can be interpreted as good news

Evdeneve Naklederiz said:

if adobe flash 10 currently is being used, the output can be interpreted as good news
www.evdenevenaklederiz.biz
www.nakliyecirehberi.com

Erd said:

[Supplier directory] (www.nakliyecirehberi.com) adobe flash 10 is used, the output can be interpreted as good news

www.gaziogluevdenevenakliyat.com said:

evden eve nakliyat Adobe Flash 10 kullanılmakta faydalarını çok gördummmm

www.gaziogluevdenevenakliyat.com said:

evden eve nakliyat Adobe Flash 10 kullanılmakta faydalarını çok gördummmm

www.gaziogluevdenevenakliyat.com said:

evden eve nakliyat Adobe Flash 10 kullanılmakta faydalarını çok gördummmm

www.gaziogluevdenevenakliyat.com said:

www.gaziogluevdenevenakliyat.com

Halı Yıkama said:

do we really hack flash clipboard???

Halı Yıkama

Leave a comment


Tag Cloud

iPad

What's your take on the iPad? (Putting aside the Flash/iPad flame war)

Answer

Latest Features

Recommended for You

@InsideRIA on Twitter

Archives

  • Or, visit our complete archive.  

About This Site

Welcome to the premiere community site for all things RIA sponsored by O'Reilly Media and Adobe Systems Incorporated.