Posts tagged fix
Flash Vulnerability Found, Adobe Says No Fix Forthcoming
Nov 12th
The basic policy for Actionscript is very close to the Javascript same-origin policy: A Flash object can only access content from the domain it originated from. There are exceptions, which I’ll get into another time, but they actually aren’t particularly important. This flash behavior is known and documented, but is not particularly well-understood, even within the Web Application Security community. The important difference, of course, is that flash objects are not web pages. A flash object does not need to be injected into a web page to execute- simply loading the content is enough. Let’s consider the implications of this policy for a moment: If I can get a Flash object onto your server, I can execute scripts in the context of your domain.
http://www.foregroundsecurity.com/MyBlog/flash-origin-policy-issues.html
Tweaks to speed up Internet Explorer 8
Nov 5th
Several users have reported significantly slower performance under Internet Explorer 8, particularly when the browser is first launched or when navigating to new pages. Delays of up to 30 seconds or more have been reported.
The problem, in most cases, is the presence of IE restricted sites and enhanced security configuration zones, which are generally created automatically by spyware removal software, such as Spybot and IESpyAd.
http://windowsfixup.com/2009/03/speeding-up-internet-explorer-8/