<?xml version="1.0" encoding="utf-8"?>
<feed xml:lang="en-us" xmlns="http://www.w3.org/2005/Atom"><title>Simon Willison's Weblog: swf</title><link href="http://simonwillison.net/" rel="alternate"/><link href="http://simonwillison.net/tags/swf.atom" rel="self"/><id>http://simonwillison.net/</id><updated>2009-11-26T12:52:16+00:00</updated><author><name>Simon Willison</name></author><entry><title>flXHR</title><link href="https://simonwillison.net/2009/Nov/26/flxhr/" rel="alternate"/><published>2009-11-26T12:52:16+00:00</published><updated>2009-11-26T12:52:16+00:00</updated><id>https://simonwillison.net/2009/Nov/26/flxhr/</id><summary type="html">
    
&lt;p&gt;&lt;strong&gt;&lt;a href="http://flxhr.flensed.com/"&gt;flXHR&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
I was looking for something like this recently, glad to see it exists. flXHR is a drop-in replacement for regular XMLHttpRequest which uses an invisible Flash shim to allow cross-domain calls to be made, taking advantage of the Flash crossdomain.xml security model.


    &lt;p&gt;Tags: &lt;a href="https://simonwillison.net/tags/ajax"&gt;ajax&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/crossdomain"&gt;crossdomain&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/flash"&gt;flash&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/flxhr"&gt;flxhr&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/javascript"&gt;javascript&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/swf"&gt;swf&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/xhr"&gt;xhr&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/xmlhttprequest"&gt;xmlhttprequest&lt;/a&gt;&lt;/p&gt;



</summary><category term="ajax"/><category term="crossdomain"/><category term="flash"/><category term="flxhr"/><category term="javascript"/><category term="swf"/><category term="xhr"/><category term="xmlhttprequest"/></entry><entry><title>Facebook and MySpace security: backdoor wide open, millions of accounts exploitable</title><link href="https://simonwillison.net/2009/Nov/5/crossdomain/" rel="alternate"/><published>2009-11-05T09:47:49+00:00</published><updated>2009-11-05T09:47:49+00:00</updated><id>https://simonwillison.net/2009/Nov/5/crossdomain/</id><summary type="html">
    
&lt;p&gt;&lt;strong&gt;&lt;a href="http://www.yvoschaap.com/index.php/weblog/facebook_myspace_accounts_hijacked/"&gt;Facebook and MySpace security: backdoor wide open, millions of accounts exploitable&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
Amazingly, both services had wide open holes in their crossdomain.xml files. Facebook were serving allow-access-from-domain=“*” in the crossdomain.xml file on one of their subdomains (a subdomain that still had access to the user’s profile information) while MySpace were opting in farm.sproutbuilder.com, a service which allowed anyone to upload arbitrary SWF files.

    &lt;p&gt;&lt;small&gt;&lt;/small&gt;Via &lt;a href="http://www.techcrunch.com/2009/11/05/massive-facebook-and-myspace-flash-vulnerability-exposes-user-data/"&gt;TechCrunch&lt;/a&gt;&lt;/small&gt;&lt;/p&gt;


    &lt;p&gt;Tags: &lt;a href="https://simonwillison.net/tags/crossdomainxml"&gt;crossdomainxml&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/facebook"&gt;facebook&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/flash"&gt;flash&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/myspace"&gt;myspace&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/security"&gt;security&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/swf"&gt;swf&lt;/a&gt;&lt;/p&gt;



</summary><category term="crossdomainxml"/><category term="facebook"/><category term="flash"/><category term="myspace"/><category term="security"/><category term="swf"/></entry><entry><title>Adobe and Industry Leaders Establish Open Screen Project</title><link href="https://simonwillison.net/2008/May/1/adobe/" rel="alternate"/><published>2008-05-01T09:43:04+00:00</published><updated>2008-05-01T09:43:04+00:00</updated><id>https://simonwillison.net/2008/May/1/adobe/</id><summary type="html">
    
&lt;p&gt;&lt;strong&gt;&lt;a href="http://www.adobe.com/aboutadobe/pressroom/pressreleases/200804/050108AdobeOSP.html"&gt;Adobe and Industry Leaders Establish Open Screen Project&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
Talk about burying the lede... the real story is that Adobe are going to drop the license restriction that prevents other people from implementing SWF players. They’re also publishing the AMF and Flash Cast protocols and removing licensing fees for Flash Player on devices.

    &lt;p&gt;&lt;small&gt;&lt;/small&gt;Via &lt;a href="http://reddit.com/r/programming/info/6hrb0/comments/"&gt;programming.reddit.com&lt;/a&gt;&lt;/small&gt;&lt;/p&gt;


    &lt;p&gt;Tags: &lt;a href="https://simonwillison.net/tags/adobe"&gt;adobe&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/amf"&gt;amf&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/flash"&gt;flash&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/flashcast"&gt;flashcast&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/swf"&gt;swf&lt;/a&gt;&lt;/p&gt;



</summary><category term="adobe"/><category term="amf"/><category term="flash"/><category term="flashcast"/><category term="swf"/></entry><entry><title>How the myspace SWF hack worked</title><link href="https://simonwillison.net/2006/Jul/17/myspace/" rel="alternate"/><published>2006-07-17T18:04:53+00:00</published><updated>2006-07-17T18:04:53+00:00</updated><id>https://simonwillison.net/2006/Jul/17/myspace/</id><summary type="html">
    
&lt;p&gt;&lt;strong&gt;&lt;a href="http://kinematictheory.phpnet.us/"&gt;How the myspace SWF hack worked&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
If Flash is a vector for XSS, is this the end of Flash badges?


    &lt;p&gt;Tags: &lt;a href="https://simonwillison.net/tags/flash"&gt;flash&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/myspace"&gt;myspace&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/swf"&gt;swf&lt;/a&gt;, &lt;a href="https://simonwillison.net/tags/xss"&gt;xss&lt;/a&gt;&lt;/p&gt;



</summary><category term="flash"/><category term="myspace"/><category term="swf"/><category term="xss"/></entry></feed>