We’re probably taking a somewhat different approach in the next version.

 

Matt

 


From: JesterXL [mailto:[EMAIL PROTECTED]
Sent: Saturday, April 02, 2005 3:35 PM
To: Flexcoders
Subject: [flexcoders] FlashVars a security risk?

 

NO, I haven't found a use case yet, but to me, it seems that putting any url
var translates to a FlashVars automatically written for me.  Cool.

...however, I started thinking dirty, and did stuff like _root=cow, etc.,
trying to break it.  While it's nice because now I can just reference
application level variables this way, it also feels very unsecure.  Is there
a way in the future, vars set with private cannot be touched via FlashVars
in this way?

--JesterXL




Yahoo! Groups Links

Reply via email to