Web Hack List

Other nomination

Poking new holes with Flash Crossdomain Policy Files

Flash's loadPolicyFile accepts any URL, follows in-domain redirects, and needs no well-formed XML, so a crossdomain policy can be smuggled into any response an attacker influences — an uploaded avatar, a GIF carrying policy tags, a PHP include or file-retrieval bug. Cross-domain reads and writes then work against sites that never opted in. Esser argues alternate policy locations should go.

Record

Researcher
Stefan Esser
Date

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Stefan Esser, first published at the original source. Preserved copies are kept so the citation survives its host.