Top Menu

ajax scripts script web 2.0 dhtml javascript

Main Menu

Menu

Scripts

 
Category: Ajax Tips And Tutorials /  The Dangers Of Cross-Domain Ajax With Flash

Domain Ajax with Flash

Chris Shiflett takes another look at some of the dangers that can come up with cross-site Ajax via a Flash object embedded in the page.


Share this ajax content

Domain Ajax with Flash

In this blog entry, Chris Shiflett takes another look at some of the dangers that can come up with cross-site Ajax via a Flash object embedded in the page. He mentions a previous discussion where Chris points out the filename-specific nature (crossdomain.xml) of this example.

Julien (author of the example) replied in the affirmative that this was the case and Chris, amazed that this was the case, gives an example of how it could be exploited (including a test performed on Flickr). He continues on, talking about pulling in others more experienced with Flash to make sure this problem was true. They find it is and even went to far as to create a simulation of the Myspace worm to show its potential for abuse.

Chris also recommends:

If you have a public API and want to allow cross-domain Ajax requests with Flash, be sure to use a separate domain. If the user interface and API operate in the same domain, there’s almost no limit to what an attacker can do.

 

website: http://shiflett.org/archive/263

demo: this example.

Hit: 1027.



 
Rating
  • Currently 3.01/5
  • 1
  • 2
  • 3
  • 4
  • 5

Rating: 3.0 (total votes for this content: 634)

 
Write Review

Footer

| Stats