XSS Exploits: Cross Site Scripting Exploits and Defense

Flash, QuickTime, PDF, Oh My

There are many of different technologies that we use on a daily basis in order to access the true potentials of the Web. Spend a few minutes online and you will start to see just how many different formats, applications, and media types your browser/computer has to be able to understand to enable the full power of the Internet.

We watch videos in YouTube by using the Flash player and Adobe's Flash Video format. We preview MP3 and movie trailers with QuickTime and Microsoft Windows player. We share our pictures on Flickr and we do business with Portable Document Format (PDF) documents. All of these technologies are used almost simultaneously today by the average user. If one of them happens to be vulnerable to an attack, all of them become vulnerable. Like a domino chain, the entire system collapses. As a result, when discussing Web application security, all of these Web-delivered technologies also have to be considered, otherwise you will be ignoring a large number of potentially insecure protocols, file formats, and applications.

In this section, we are going to learn about various vulnerabilities and issues related to Web technologies such as Flash, QuickTime, and PDF, and see how they can be easily abused by attackers to gain access to your personal data.

Playing with Flash Fire

Flash content is currently one of the most commonly used/abused media-enhancing components added to Web sites. In fact, it is such an important part of the Internet experience...

UNLIMITED FREE
ACCESS
TO THE WORLD'S BEST IDEAS

SUBMIT
Already a GlobalSpec user? Log in.

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.

Customize Your GlobalSpec Experience

Category: Graphic Design Services
Finish!
Privacy Policy

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.