Author: Ashvin Savani - Arckid
Adobe recently update the flash player version to 18.104.22.168 to fix some serious security issues found in last version of flash player 9.0.48.
So what are the changes in new version of flash player for flash developer perspective? Here are the issues that personally affect me and my team.
Stricter method to interpret crossdomain policy files:
Policy files formatting are now stricter. Here are the cases, which can cause rejection of your crossdomain policy files:
- Any extra content before or after the start and closing tag cross-domain-policy.
- Top level XML tag is not cross-domain-policy.
- Any text other than comments found inside any tag of the policy file.
Adobe published new schemas for various cases of crossdomain policies as following:
- Generic Schema: http://www.adobe.com/xml/schemas/PolicyFile.xsd
- Schema for FTP: http://www.adobe.com/xml/schemas/PolicyFileFtp.xsd
- Schema for HTTP: http://www.adobe.com/xml/schemas/PolicyFileHttp.xsd
- Schema for HTTPS: http://www.adobe.com/xml/schemas/PolicyFileHttps.xsd
- Schema for Socket communication: http://www.adobe.com/xml/schemas/PolicyFileSocket.xsd
Same domain redirection of policy files
- Redirection inside same domain is still allowed in new flash player version.
- If policy file located at domain/a/crossdomainpolicy.xml is set to redirect at domain/b/crossdomainpolicy.xml, in that case it would treated policy file for folder domain/b not domain/a.
- Policy file’s content-type must be either text/* or application/xml or application/xhtml+xml
- Flash player will ignore any HTTP policy file that is not sent with a Content-Type value.
- Intention of whitelist is to give some assurance that the file is intended to be a text file.
Stronger socket communication rules
- From this player version onwards, it’s required to define socket communication port number in the socket policy file.
- Meta-policies are defining which policy files are permitted to exist on a server.
- Meta-policies normally defines, which kind of flash player related services are hosted on this server and it’s sub folders.
- Scope for Meta-policies is for HTTP, HTTPS, FTP and Sockets.
- Currently, its not too important unless and until you are super administrator of lot many flash player services like Yahoo! and Google.
Policy file logging
- It requires debug version of flash player.
- To enable logging, you need to edit mm.cfg which is normally located inside your home folder depending on your operating system.
Default locations for mm.cfg are as following:
- Windows: C:\Documents and Settings\username
- Windows Vista: C:\Users\username
- Macintosh and Linux: /home/username
- Create mm.cfg if it does not exist.
It should have following settings:
- Line (i) will enable logging of policy files and line (ii) will continue appending logs instead of clearing log file if root-level SWF is used.
After doing this, if you load any SWF file in your debug version of flash player, it should create policyfiles.txt in following folders according the operating system:
- Windows: C:\Documents and Settings\username\Application Data\Macromedia\Flash Player\Logs
- Windows Vista: C:\Users\username\AppData\Roaming\Macromedia\Flash Player\Logs
- Macintosh: /Users/username/Library/Preferences/Macromedia/Flash Player/Logs
- Linux: /home/username/.macromedia/Flash_Player/Logs
- Main message which is added in this log file is “Root-level SWF loaded“. This indicates that policy file logging is working fine.
- Complete article on Adobe Devnet can be found here.
Restriction on unsupported function asfunction:
This was the main protocol to address potential cross-site scripting issues with some SWF files. As it was updated after Flash Player 8, it has nothing to do with Flash Player 7.
Downloading the update:
To download latest update please point your browser to here.