Socket Connection Timing Can Reveal Information About Network Configuration (Exploit)
Due to a design flaw in ActionScript 3 socket handling, compiled Flash movies are able to scan for open TCP ports on any host reachable from the host running the SWF, bypassing the Flash Player Security Sandbox Model and without the need to rebind DNS.
Read more here:
Socket Connection Timing Can Reveal Information About Network Configuration (Exploit)
Leave a Reply