Showing posts with label Video Plug-in. Show all posts
Showing posts with label Video Plug-in. Show all posts

Wednesday, 22 July 2015

Recent Silverlight Leak Targeted By Cyber Criminals


It is not only vulnerabilities in Adobe Flash Player cyber criminals to infect computers with malware, users also need to watch Microsoft Silverlight, according to a security researcher. A vulnerability in the video plug-in that Microsoft in May by Security Bulletin MS15-044 patched is now being actively attacked by exploit kits, according to researcher ' JuK 'of the blog Malware Do not Need Coffee.

Once users with a vulnerable version a hacked or malicious website or visit an infected ad get to see the computer can become infected with malware. However, the question is how effective is attacking outdated Silverlight versions. Both Internet Explorer and Google Chrome Block obsolete video plug-in fact. In addition, Microsoft announced that Silverlight in the new Edge browser in Windows 10 will not support .

On the other hand, there are still users who do not install Windows Updates and therefore at risk of being attacked. Anti-virus company Trend Micro stated that Internet users last year, most via Adobe Flash Player, Internet Explorer and Silverlight were attacked and this year there have been several attacks discovered that unpatched Silverlight versions were targeted.

Saturday, 18 July 2015

Adobe Flash Player Arming Against New Attacks


Adobe has security measures in collaboration with Google added to Flash Player that should arm the video plug-in against new attacks. In recent months, several different zero-day vulnerabilities found in Flash Player that allows Internet users were attacked.

In this case there was no update available before the attacks took place. In addition, there were dozens of other vulnerabilities discovered in the software that could give an attacker access to computers. A number of these leaks, after the appearance of the update also be used for users of attacks. In this case it was users who did not install the update. A large proportion of the vulnerabilities in Adobe fixes Flash Player detected by Google. The reason is that Google Chrome has an embedded Flash Player. Vulnerabilities in Flash Player can consequently affect Chrome users. In addition, Google has a separate team of hackers that focuses on researching and safer popular software, such as Flash Player.

In addition to reporting new vulnerabilities Google therefore contributes to security. Measures to make it more difficult for attackers to attack vulnerabilities. Along with these measures now from Adobe Adobe Flash Player version 18.0.0.209 implemented. Thus, for example, the memory locations of Flash Player made ​​more random. Because these locations were previously predictable, an attacker could easily use it here. "We think we have put a great step forward when it comes to the security of Flash, but we're not done yet," said Chris Evans of Google.

He stressed that will find a way for every defensive measure attackers to bypass it. "It's a cat-and-mouse game." Evans stressed that the new security measures are effective in 64-bit versions of Flash Player. Users also are advised to upgrade to a 64-bit version of both their browser and Flash Player.

Thursday, 16 July 2015

Manufacturer Stops Installing Flash Player On Computers



The American computer manufacturer System76 has stopped the default install Adobe Flash Player on new computers. It includes both desktops and laptops now come without the video plug-in. System76 delivers desktops, laptops and servers, which all run on Ubuntu.

In 2007, the manufacturer of a license to install Adobe Flash Player advance new systems. Something the company did until now standard. Starting today, there came a change in systems and be delivered without Flash Player. According to the manufacturer's decision is based on two reasons. First, Flash Player no longer required to have a "full web experience", whereas previously it was often the case. In addition, the safety of users of the other reason.

In recent weeks, several zero-day vulnerabilities discovered in the video plug-in, which were then used by cyber criminals to infect computers silently by malware. Besides the decision to henceforth avoid Flash Player System76 also advises to remove the browser plug-in already purchased systems. "Even if you think you need Flash, you might have to experiment further by not using a time. You will be surprised how little your Internet experience is changing," the company said.

In case customers but not without Flash Player is advised to Google Chrome, which uses a proprietary Flash Player located in a sandbox. Still, this offers no guarantee, as one of the Flash Player vulnerabilities that an attacker had discovered had to break out here the Italian Hacking Team, and then take on the underlying system. Therefore, it is according to the manufacturer still more sensible to avoid flash at all.