On Wed, May 02, 2007 at 12:50:10PM +0100, Martin Guy wrote:
> I've added a couple of examples of exploits using net access to
> http://gnash.lulu.com/wiki/index.php/Security#Network_access

It seems all of those expoits are exploiting their security model.
By NOT implementing crossdomain.xml (or disabling whenever we'll implement)
we'll be the kind of all exploits for that.

In my opitnion the model is just bogus itself, so wouldn't go too deep
in trying to make it secure when it's security concept is just wrong.

--strk;


_______________________________________________
Gnash-dev mailing list
[email protected]
http://lists.gnu.org/mailman/listinfo/gnash-dev

Reply via email to