Web Hack List

Collected research

Poking new holes with Flash Crossdomain Policy Files

Hardened-PHP Project - PHP Security - Poking new holes with Flash Crossdomain Policy Files

Flash's loadPolicyFile accepts any URL, follows in-domain redirects, and needs no well-formed XML, so a crossdomain policy can be smuggled into any response an attacker influences — an uploaded avatar, a GIF carrying policy tags, a PHP include or file-retrieval bug. Cross-domain reads and writes then work against sites that never opted in. Esser argues alternate policy locations should go.

Record

Document
Hardened-PHP Project - PHP Security - Poking new holes with Flash Crossdomain Policy Files
Researcher
Stefan Esser
Published by
hardened-php.net
Date
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Stefan Esser, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .