<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" 
      xmlns:thr="http://purl.org/syndication/thread/1.0">
  <link rel="alternate" type="text/html" href="http://www.insideria.com/2008/09/adobe-flash-clipboard-hack.html" />
  <link rel="self" type="application/atom+xml" href="http://www.insideria.com/atom.xml" />
  <id>tag:www.insideria.com,2009://34/tag:www.insideria.com,2008://34.33484-</id>
  <updated>2009-11-05T19:56:44Z</updated>
  <title>Comments for Adobe Flash Clipboard Hack (http://www.insideria.com/2008/09/adobe-flash-clipboard-hack.html)</title>
  <generator uri="http://www.sixapart.com/movabletype/">Movable Type 4.21-en</generator>
  <entry>
    <id>tag:www.insideria.com,2008://34.33484</id>
    <link rel="alternate" type="text/html" href="http://www.insideria.com/2008/09/adobe-flash-clipboard-hack.html" />
    <link rel="service.edit" type="application/atom+xml" href="http://blogs.oreilly.com/cgi-bin/mt/mt-atom.cgi/weblog/blog_id=34/entry_id=33484" title="Adobe Flash Clipboard Hack" />
    <published>2008-09-22T15:09:18Z</published>
    <updated>2008-09-23T00:47:37Z</updated>
    <title>Adobe Flash Clipboard Hack</title>
    <summary>Adobe Flash players are make it possible hijack the system clipboard.  It&apos;s really spooky. While writing this blog I clicked on the above demo and when I tried to past in a URL for the demo it posted in the hijacked value (http://www.evil.com) instead. And the clipboard is hijacked across all applications - not just your browser.</summary>
    <author>
      <name>Richard Monson-Haefel</name>
      <uri>http://www.curl.com</uri>
    </author>
    
    <category term="Blogs" />
    
    <content type="html" xml:lang="en" xml:base="http://www.insideria.com/">
      <![CDATA[<div class="ap_r"><a href="http://www.insideria.com/upload/2008/06/logo_flashplayer.jpg" class="highslide" onclick="return hs.expand(this)"><img src="http://www.insideria.com/upload/2008/06/logo_flashplayer.jpg" alt="flashplayer" title="Click to enlarge" width="148"/></a></div>

<p>Although this was first brought to the attention of the world on August 18th in a ZDNet article, "<a href="http://blogs.zdnet.com/security/?p=1733" target="_blank">Adobe Flash ads launching clipboard hijack attack</a>",  it seems little has been said about it since.</p>

<p>Apparently there is a mechanism by which a Flash movie can insert any kind of content into the clipboard.  You can see it demoed <a href="http://raffon.net/research/flash/cb/test.html" target="_blank">here</a> (warning once you click on this link you'll need to close down your browser if you want to use your clipboard again).  </p>

<p>It's really spooky. While writing this blog I copied on the above demo URL and when I tried to paste into this blog entry all I got was (http://www.evil.com) instead. And the clipboard is hijacked across all applications - not just your browser.</p>

<p>The good news is that Adobe plans to fix this with the release of Adobe Flash Player 10. The bad news is that that everyone who uses Flash can be victimized by this attack until Flash player 10 is released (its in pre-release now).  Short of uninstalling all players proceeding Flash Player 10, I'm not sure if there is any way to avoid getting your clipboard hijacked.</p>]]>
      
    </content>
  </entry>

  <entry>
    <id>tag:www.insideria.com,2008://34.33484-comment:2043057</id>
    <thr:in-reply-to ref="tag:www.insideria.com,2008://34.33484" type="text/html" href="http://www.insideria.com/2008/09/adobe-flash-clipboard-hack.html"/>
    <link rel="alternate" type="text/html" href="http://www.insideria.com/2008/09/adobe-flash-clipboard-hack.html#comment-2043057" />
    <title>Comment from Quentin on 2008-09-22</title>
    <author>
        <name>Quentin</name>
        <uri>http://toki-woki.net</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://toki-woki.net">
        <![CDATA[<p>AVAST detected the threat, which is cool.</p>]]>
    </content>
    <published>2008-09-22T16:23:30Z</published>
  </entry>

  <entry>
    <id>tag:www.insideria.com,2008://34.33484-comment:2043063</id>
    <thr:in-reply-to ref="tag:www.insideria.com,2008://34.33484" type="text/html" href="http://www.insideria.com/2008/09/adobe-flash-clipboard-hack.html"/>
    <link rel="alternate" type="text/html" href="http://www.insideria.com/2008/09/adobe-flash-clipboard-hack.html#comment-2043063" />
    <title>Comment from Adrian Parr on 2008-09-22</title>
    <author>
        <name>Adrian Parr</name>
        <uri>http://www.adrianparr.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.adrianparr.com">
        <![CDATA[<p>Yeah, I got that too. I wonder how Avast picked it up?</p>

<p>Screenshot here ...</p>

<p><a href="http://www.adrianparr.com/images/avast_warning.gif">http://www.adrianparr.com/images/avast_warning.gif</a></p>]]>
    </content>
    <published>2008-09-22T19:17:32Z</published>
  </entry>

  <entry>
    <id>tag:www.insideria.com,2008://34.33484-comment:2043077</id>
    <thr:in-reply-to ref="tag:www.insideria.com,2008://34.33484" type="text/html" href="http://www.insideria.com/2008/09/adobe-flash-clipboard-hack.html"/>
    <link rel="alternate" type="text/html" href="http://www.insideria.com/2008/09/adobe-flash-clipboard-hack.html#comment-2043077" />
    <title>Comment from Rich Tretola on 2008-09-22</title>
    <author>
        <name>Rich Tretola</name>
        <uri>http://blog.everythingflex.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://blog.everythingflex.com">
        <![CDATA[<p> I am running Flash Player 10 and I get an error on the test site so I assume this is blocking the hack. It does occur on Flash Player 9</p>

<p>Error: Error #2176: Certain actions, such as those that display a pop-up window, may only be invoked upon user interaction, for example by a mouse click or button press.<br />
	at flash.system::System$/setClipboard()<br />
	at test_fla::MainTimeline/setClip()<br />
	at Function/http://adobe.com/AS3/2006/builtin::apply()<br />
	at SetIntervalTimer/onTimer()<br />
	at flash.utils::Timer/_timerDispatch()<br />
	at flash.utils::Timer/tick()</p>]]>
    </content>
    <published>2008-09-23T01:39:26Z</published>
  </entry>

  <entry>
    <id>tag:www.insideria.com,2008://34.33484-comment:2046052</id>
    <thr:in-reply-to ref="tag:www.insideria.com,2008://34.33484" type="text/html" href="http://www.insideria.com/2008/09/adobe-flash-clipboard-hack.html"/>
    <link rel="alternate" type="text/html" href="http://www.insideria.com/2008/09/adobe-flash-clipboard-hack.html#comment-2046052" />
    <title>Comment from Dillon on 2008-11-10</title>
    <author>
        <name>Dillon</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>Avast shivers me timbers.  Arrg! Another virus blown out of the water! </p>]]>
    </content>
    <published>2008-11-11T02:20:54Z</published>
  </entry>

  <entry>
    <id>tag:www.insideria.com,2008://34.33484-comment:2046255</id>
    <thr:in-reply-to ref="tag:www.insideria.com,2008://34.33484" type="text/html" href="http://www.insideria.com/2008/09/adobe-flash-clipboard-hack.html"/>
    <link rel="alternate" type="text/html" href="http://www.insideria.com/2008/09/adobe-flash-clipboard-hack.html#comment-2046255" />
    <title>Comment from Mandy on 2008-11-14</title>
    <author>
        <name>Mandy</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>Clickjacking has been fixed now already. People using it for the old copy clipboard function (which Flash 10 broke) should look for other solutions. I saw a good example here: </p>

<p><a href="http://groups.google.com/group/Snipurl/web/copy-to-clipboard-not-working">http://groups.google.com/group/Snipurl/web/copy-to-clipboard-not-working</a></p>]]>
    </content>
    <published>2008-11-14T08:48:13Z</published>
  </entry>

  <entry>
    <id>tag:www.insideria.com,2008://34.33484-comment:2050585</id>
    <thr:in-reply-to ref="tag:www.insideria.com,2008://34.33484" type="text/html" href="http://www.insideria.com/2008/09/adobe-flash-clipboard-hack.html"/>
    <link rel="alternate" type="text/html" href="http://www.insideria.com/2008/09/adobe-flash-clipboard-hack.html#comment-2050585" />
    <title>Comment from dear hi all on 2009-01-09</title>
    <author>
        <name>dear hi all</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>AJAX does have its own category. As there <a href="http://www.nakliyatankara.com ">ankara nakliyat</a>  are many AJAX frameworks (dojo, YUI, prototype, jQuery, Ext JS, etc). We simply <a href="http://www.uluslararasi-nakliyat.org ">ankara nakliyat</a>  chose to include AJAX as a single choice. Perhaps a future poll can drill into individual AJAX framework preferences among developers.<br />
</p>]]>
    </content>
    <published>2009-01-09T09:27:27Z</published>
  </entry>

  <entry>
    <id>tag:www.insideria.com,2008://34.33484-comment:2055516</id>
    <thr:in-reply-to ref="tag:www.insideria.com,2008://34.33484" type="text/html" href="http://www.insideria.com/2008/09/adobe-flash-clipboard-hack.html"/>
    <link rel="alternate" type="text/html" href="http://www.insideria.com/2008/09/adobe-flash-clipboard-hack.html#comment-2055516" />
    <title>Comment from ankara evden eve nakliyat on 2009-03-19</title>
    <author>
        <name>ankara evden eve nakliyat</name>
        <uri>http://www.nakliyatankara.net</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.nakliyatankara.net">
        <![CDATA[<p>Clickjacking has been fixed now already. People using it for the old copy clipboard function <a href="http://www.nakliyatankara.net">ankara nakliyat</a> (which Flash 10 broke) should look for other solutions. I saw a good example here: </p>]]>
    </content>
    <published>2009-03-19T08:32:08Z</published>
  </entry>

  <entry>
    <id>tag:www.insideria.com,2008://34.33484-comment:2057846</id>
    <thr:in-reply-to ref="tag:www.insideria.com,2008://34.33484" type="text/html" href="http://www.insideria.com/2008/09/adobe-flash-clipboard-hack.html"/>
    <link rel="alternate" type="text/html" href="http://www.insideria.com/2008/09/adobe-flash-clipboard-hack.html#comment-2057846" />
    <title>Comment from Nakliyat firmaları on 2009-04-19</title>
    <author>
        <name>Nakliyat firmaları</name>
        <uri>http://www.nakliyatfirmalariankara.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.nakliyatfirmalariankara.com">
        <![CDATA[<p>Transportation of ankara moving express</p>]]>
    </content>
    <published>2009-04-19T11:33:46Z</published>
  </entry>

  <entry>
    <id>tag:www.insideria.com,2008://34.33484-comment:2067668</id>
    <thr:in-reply-to ref="tag:www.insideria.com,2008://34.33484" type="text/html" href="http://www.insideria.com/2008/09/adobe-flash-clipboard-hack.html"/>
    <link rel="alternate" type="text/html" href="http://www.insideria.com/2008/09/adobe-flash-clipboard-hack.html#comment-2067668" />
    <title>Comment from ev taşıma on 2009-07-02</title>
    <author>
        <name>ev taşıma</name>
        <uri>http://www.ekintas.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.ekintas.com">
        <![CDATA[<p><br />
Clickjacking has been fixed now already. People using it for the old copy clipboard function (which Flash 10 broke) should look for other solutions</p>

<p></p>

<p><a href="http://www.ekintas.com">nakliyat</a></p>]]>
    </content>
    <published>2009-07-02T14:35:55Z</published>
  </entry>

  <entry>
    <id>tag:www.insideria.com,2008://34.33484-comment:2068891</id>
    <thr:in-reply-to ref="tag:www.insideria.com,2008://34.33484" type="text/html" href="http://www.insideria.com/2008/09/adobe-flash-clipboard-hack.html"/>
    <link rel="alternate" type="text/html" href="http://www.insideria.com/2008/09/adobe-flash-clipboard-hack.html#comment-2068891" />
    <title>Comment from ankara aslanlar nakliyat on 2009-07-23</title>
    <author>
        <name>ankara aslanlar nakliyat</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>Clickjacking has been fixed now already. People using it for the old copy clipboard function ankara aslanlar nakliyat (which Flash 10 broke) should look for other solutions. I saw a good example here:</p>]]>
    </content>
    <published>2009-07-23T19:22:07Z</published>
  </entry>

</feed
