September 19th, 2008
Adobe moves to nuke ‘clipboard hijack’ attacks
Adobe has announced plans to modify the next version of its Flash Player to use an “allow/deny” system to mitigate clipboard hijack attacks.
The change will be fitted into the final version of Flash Player 10 to demand user interaction when a Shockwave (.swf) file attempts to set data on a user’s clipboard. It follows news that malicious hackers are using booby-trapped Flash banner ads to hijack clipboards for use in rogue security software attacks.
(See Aviv Raff’s proof-of-concept demo to show how easy it is to use Flash with ActionScript code to persistently load a malicious URL into a target clipboard).
Here’s the skinny on the Flash Player 10 changes:
[ SEE: Can Adobe mitigate ‘clipboard hijack’ issue? ]
System.setClipboard() method may be successfully called only through ActionScript that originates from user interaction. This includes actions such as clicking the mouse or using the keyboard. This user interaction requirement also applies to the new ActionScript 3.0 Clipboard.generalClipboard.setData() and Clipboard.generalClipboard.setDataHandler() methods.System.setClipboard() method. This change affects SWF files of all versions played in Flash Player 10 beta and later. This change affects all non-application content in Adobe AIR—however, AIR application content itself is unaffected.System.setClipboard() method outside of an event triggered by user interaction will need to be updated. Setting the Clipboard will now have to be invoked through a button, keyboard shortcut, or some other event initiated by the user.[ SEE: Adobe Flash ads launching clipboard hijack attack ]
Adobe already uses an allow/deny mechanism when a SWF file attempts to access a user’s camera or microphone using the Camera.get() or Microphone.get() methods.

 * Photo credit: EdTarwinski’s Flickr photostream (Creative Commons 2.0)
For daily updates on Ryan's activities, follow him on Twitter.

![[image]](http://mowser.com/img?url=http%3A%2F%2Fi.zdnet.com%2Fimages%2F200803%2FtreeItem.gif)
![[image]](http://mowser.com/img?url=http%3A%2F%2Fi.zdnet.com%2Fimages%2F200803%2FtreeSkipItem.gif)
![[image]](http://mowser.com/img?url=http%3A%2F%2Fi.zdnet.com%2Fimages%2F200803%2FtreeLastItem.gif)
![[image]](http://mowser.com/img?url=http%3A%2F%2Fwww.zdnet.com%2Fi%2Fzdnn%2Fspacer.gif)




![[image]](http://mowser.com/img?url=http%3A%2F%2Fi.i.com.com%2Fcnwk.1d%2FAds%2F9713%2F12%2F120xx90_CBSSportsStore_Products.jpg)

![[image]](http://mowser.com/img?url=http%3A%2F%2Fi.i.com.com%2Fcnwk.1d%2FAds%2Fcommon%2Fcleargif.gif)
![[image]](http://mowser.com/img?url=http%3A%2F%2Fi.i.com.com%2Fcnwk.1d%2FAds%2F1671%2F12%2FIntel_PC08_IPIP.jpg)





![[image]](http://mowser.com/img?url=http%3A%2F%2Fi.i.com.com%2Fcnwk.1d%2FAds%2F7074%2F29%2Fhotspot%2Fpic1.jpg)
![[image]](http://mowser.com/img?url=http%3A%2F%2Fi.i.com.com%2Fcnwk.1d%2FAds%2F7074%2F29%2Fhotspot%2Fpic2.jpg)
![[image]](http://mowser.com/img?url=http%3A%2F%2Fi.i.com.com%2Fcnwk.1d%2FAds%2F7074%2F29%2Fhotspot%2Fpic3.jpg)
![[image]](http://mowser.com/img?url=http%3A%2F%2Fi.i.com.com%2Fcnwk.1d%2FAds%2F7074%2F29%2Fhotspot%2Fpic4.jpg)

