Security

Flash Security at the end of Flash era

Flash era is rapidly wrapping up and it is important to ensure the security of Flash applications we leave behind us.

Danger of crossdomain.xml

crossdomain.xml specifies the following:

  • If https://other-domain.com/evil.swf can read data from your domain https://mycorp.com/user-mail
  • If other crossdomain