Mark Smith (
mark) wrote in
dw_maintenance2009-09-23 09:18 am
![[staff profile]](https://www.dreamwidth.org/img/silk/identity/user_staff.png)
![[site community profile]](https://www.dreamwidth.org/img/comm_staff.png)
LJ web security exploit
If you use LiveJournal, you're probably aware of an exploit involving cross site Flash that was propagated over there for a little while last night (LJ news post). They've since taken steps to mitigate the issue, and are working on a permanent fix as we speak.
Some people have contacted me about Dreamwidth; this is something I should have posted about last night. We investigated both the source code of the exploit (Flash is easy to decompile) as well as the attack vector (how the exploit code works) and determined that Dreamwidth is not currently vulnerable to this attack.
I apologize for not posting about this last night. We investigated and made the determination that Dreamwidth was safe, but didn't mention it anywhere.
Some people have contacted me about Dreamwidth; this is something I should have posted about last night. We investigated both the source code of the exploit (Flash is easy to decompile) as well as the attack vector (how the exploit code works) and determined that Dreamwidth is not currently vulnerable to this attack.
I apologize for not posting about this last night. We investigated and made the determination that Dreamwidth was safe, but didn't mention it anywhere.
no subject
no subject
Thanks for all you do.
no subject
no subject
no subject
no subject
I love feeling like this "isn't just a blog" to the Dreamwidth staffers. (I get that feeling all the time on LJ!)
no subject
no subject
no subject
no subject
no subject
Seriously, I'm scared.
It's good to know that we're safe over here, but though I read the news post over on LJ now, I'm confused - can you tell what kind of "videos and other media" it is that got affected, or is that still uncertain? I'm not an expert at this, so I'm simply curious and want to know what I have to look out for and pay attention to.
<3 you guys for watching over us!
no subject
no subject
Thanks for explaining! :)
no subject
no subject
no subject
no subject
no subject
no subject
Which, I guess, means that it's a configuration difference. We decided we didn't need this functionality yet, and did not enable it.