Quoting: “Luckily — by a hair’s breadth with browser AJAX requests — a scintillation godliness hosted on discipline X is not able to liable a send in on discipline Y. If this would be accomplishable, discipline X [would be] proficient to access abundance on discipline Y, and when the operator is logged in on discipline Y make amends for and pile wiping out any palpable materials. In different cases this could limit a Flash application’s capabilities.. To dissolve into such issues, Adobe (Flash’s developers) introduced a ‘crossdomain.xml’ send in which could allocate different domains to access another discipline, chief to cross-domain access around different or all domains. Both sites were notified, and they con implemented fixes.
Read more of this feature at Slashdot. While certainly Facebook locked the facing door from any non-Facebook discipline access via Flash, a fundamental subdomain swap allowed any scintillation godliness (domain=”*”) to access its discipline materials.” He create a like refractory in MySpace’s crossdomain.xml.
Original pile around Soulskill
Share and Enjoy:
These icons component to sexually transmitted bookmarking sites where readers can ration and disinter immature network pages.
Facebook and MySpace Backdoors Found, Fixed · TechBlogger
Marraskuu 6th, 2009 · Ei kommentteja
Uncategorized
Create a free edublog to get your own comment avatar (and more!)