Most Popular
| Top Stories | Commented | Featured |
TechSpot Blog: Disable Windows automatic check for solutions after a program crashes featured
Weekend Open Forum: Google Chrome OS and the future of cloud computing featured
Tech Tip of the Week: Unearth Region-Specific Windows 7 Themes featured
Sony: PlayStation 3 to be 3D-capable via firmware update
Radeon HD 5970 supplies dry up quick, not a big surprise
Xbox Live bans prompt class action lawsuit
Mozilla reveals 2008 revenue, rumors say Firefox coming to PS3
TS Community
| User Gallery | Recent Discussion |
View from the window by Didou | the gamers room by maazter21 |
CIMG0335 by darkman3d | World Record? by Mirob |
IT Security
Rogue Flash ads overwrite clipboard
There is a new type of malicious advertising doing the rounds, one that targets users of Windows, Mac, and Linux systems running IE, Firefox, and Safari. The attack, which was made public via a number of discussion boards, exploits a feature in Flash to put a plain-text string of characters on a user’s clipboard.
While the feature alone appears to pose no security risk at all, hackers are using it in tandem with Flash-based banner ads on legitimate sites to persistently overwrite the clipboard with a malicious URL – effectively hijacking the clipboard until the browser window is closed. This of course can lead some people to unknowingly spam the link, which points to a fake anti-virus product for sale.
Adobe says it is investigating potential solutions to this issue and has promised to update customers as soon as more information is available.
While the feature alone appears to pose no security risk at all, hackers are using it in tandem with Flash-based banner ads on legitimate sites to persistently overwrite the clipboard with a malicious URL – effectively hijacking the clipboard until the browser window is closed. This of course can lead some people to unknowingly spam the link, which points to a fake anti-virus product for sale.
Adobe says it is investigating potential solutions to this issue and has promised to update customers as soon as more information is available.
TechSpot RSS



