Dear Adobe Flash, why won't you DIE, DIE, DIE?

happygeek 2 Tallied Votes 544 Views Share

Earlier this month, security outfit FireEye’s 'FireEye as a Service' researchers out in Singapore discovered and reported on a phishing campaign that was found to be exploiting a zero-day in Adobe Flash Player vulnerability (CVE-2015-3113). That campaign has been well and truly active for a while now, with attacking emails including links to compromised sites serving up benign content if you are lucky and a malicious version of the Adobe Flash Player complete with the exploit code if you are not.

Adobe has now with the following recommendations:

Users of the Adobe Flash Player Desktop Runtime for Windows and Macintosh should update to Adobe Flash Player 18.0.0.194.

Users of the Adobe Flash Player Extended Support Release should update to Adobe Flash Player 13.0.0.296.

Users of Adobe Flash Player for Linux should update to Adobe Flash Player 11.2.202.468.

Adobe Flash Player installed with Google Chrome and Adobe Flash Player installed with Internet Explorer on Windows 8.x will automatically update to version 18.0.0.194.

Here are the affected software versions:

Adobe Flash Player 18.0.0.161 and earlier versions for Windows and Macintosh

Adobe Flash Player Extended Support Release version 13.0.0.292 and earlier 13.x versions for Windows and Macintosh

Adobe Flash Player 11.2.202.466 and earlier 11.x versions for Linux

Craig Young, Security Researcher at Tripwire, reckons that "Flash, along with ActiveX and Java are remnants of the 1990s 'Web 2.0’ technology boom. The nature of these technologies allows attackers to run code directly on remote computers and revolutionized the attack surface of the Internet." I agree with him, and my response is that Flash should die, so KILL IT. Anyway, Craig continues "There has been a constant barrage of vulnerabilities in all ‘Web 2.0’ technology as well as a constant stream of ‘update’ messages to users. This has given way to a newer and very successful form of attack wherein the attacker spoofs an update message tricking users into downloading malware. These tricks can be particularly effective, as illustrated by the 2012 Flashback malware which exploited Java on roughly 600,000 Apple computers in the 6 weeks it took for Apple to respond with patches." Yep, so KILL FLASH. It's useless, you don't need it and you won't miss it. KILL IT.

Mark James, Security Specialist at IT Security firm ESET, also explains why Adobe Flash is targeted so often and what users should do to protect themselves. "Since Flash is such a widely used plugin, it stands to reason that it will be one of the most targeted apps for vulnerability." Agreed Mark, so let's start a campaign to reduce that popularity by encouraging users to KILL IT or HAVE IT KILLED. Sorry, back to Mark. "If you want to affect as many people as possible then you need an application that a lot of users use and flash is one of them. This is an excellent example of why you should be very aware of updates for software not only operating systems. Checking to see if any updates are available and installing them immediately is the only way to help protect yourself in the minefield of the software world that we use today. There is an excellent link that everyone should save and use as often as they can to check to see the latest version of flash and more importantly see if their version is the same or needs updating. I request that you please be very careful of following links to update sites as these could sometimes be used to direct you to other malicious sites. I would personally recommend that you manually type the link to be absolutely sure if you have any concerns at all." Or better still, go to the uninstall software section of your OS and KILL THE BLOODY THING STONE DEAD. WHY ARE YOU STILL USING THIS DINOSAUR?

Yes, some sites and services still demand Flash for their videos. Usually, it has to be said, to serve you adverts you don't want of course. Anyhow, if you do want something there is a work around that doesn't involve Flash most of the time as far as I can see. That work around is called HTML5. Most sites with Flash will also serve up HTML5 so as not to alienate their iOS using visitors. A little googling pretty quickly turns up tricks to spoof your browser, via the User Agent, into becoming an iOS device for this purpose. You should then be able to switch it into iPad, or whatever, mode for those sites that insist on using Flash and still get the content in HTML5 form.

I'm with Brian Krebs who, just the other week, how he has "spent the better part of the last month running a little experiment to see how much I would miss Adobe‘s buggy and insecure Flash Player software if I removed it from my systems altogether. Turns out, not so much."

C'mon folks, be honest now, do you really need Flash, do you really you it and would you really miss it? Let's all do the decent thing and shoot this sick beyond belief monstrosity in the head...

Dani AI

Generated

As argued in 2015, Flash was a huge attack surface — the good news is that the industry eventually answered. Adobe formally retired Flash Player (end of support: December 31, 2020). (adobe.com) Adobe also shipped the update that prevents Flash content from running after January 12, 2021, and browser vendors followed documented removal roadmaps. ()

Practical next steps for anyone landing on this old thread: remove any remaining Flash runtime and treat old installs as untrusted. Adobe publishes platform-specific uninstallers for Windows and macOS; run those, then verify with your browser that no Flash plugin remains. () Microsoft additionally released updates that remove built‑in Flash from supported Windows images. (support.microsoft.com)

If legacy Flash content must be preserved or used (games, internal training, old media), use purpose-built preservation/emulation tools rather than the original Player. Projects such as Ruffle (a sandboxed open‑source emulator) and the Flashpoint archive provide safe ways to run or archive SWF content without exposing the live web to an unpatched plugin. (ruffle.rs) For businesses that absolutely cannot migrate, Adobe pointed enterprises to commercial options via its distribution partner (HARMAN) for transition assistance. (community.adobe.com)

Finally: was right to hint at the broader trend — browsers long ago began phasing out plugin architectures (NPAPI/ActiveX/etc.), so Flash was not unique. If you manage sites still using Flash, plan a migration to HTML5/WebAssembly or convert content with emulation tools; if you must run Flash, keep it isolated (VM or air‑gapped environment), patched at the OS level, and never enable it for general web browsing.

Member Avatar for Member #120589
Member #120589

Flash, along with ActiveX and Java

Heh heh, are you suggesting that Java runtimes be dropped too? Silverlight? Things are warming up.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.