mark: A photo of Mark kneeling on top of the Taal Volcano in the Philippines. It was a long hike. (Default)
Mark Smith ([staff profile] mark) wrote in [site community profile] dw_maintenance2009-09-23 09:18 am

LJ web security exploit

If you use LiveJournal, you're probably aware of an exploit involving cross site Flash that was propagated over there for a little while last night (LJ news post). They've since taken steps to mitigate the issue, and are working on a permanent fix as we speak.

Some people have contacted me about Dreamwidth; this is something I should have posted about last night. We investigated both the source code of the exploit (Flash is easy to decompile) as well as the attack vector (how the exploit code works) and determined that Dreamwidth is not currently vulnerable to this attack.

I apologize for not posting about this last night. We investigated and made the determination that Dreamwidth was safe, but didn't mention it anywhere.
keris: Keris with guitar (Default)

[personal profile] keris 2009-09-26 10:07 am (UTC)(link)
Ah, thanks, that's a better explanation than I got from LJ. LJ's description sounded as though it was affecting real embedded videos. But even better that it doesn't afftect DW at all...