Re: Flash Media Servers as Open Proxies

2009-12-03 Thread Marshall Eubanks
On Dec 3, 2009, at 1:09 PM, Ray Sanders wrote: Marshall, Did you find out via published article, or your own research? Either way I'd like (if you don't mind) more information on this so I can investigate what impact there may be on our systems. Via a DMCA take-down letter for a Cricket

Re: Flash Media Servers as Open Proxies

2009-12-03 Thread Ray Sanders
Marshall, Did you find out via published article, or your own research? Either way I'd like (if you don't mind) more information on this so I can investigate what impact there may be on our systems. Thanks! Marshall Eubanks wrote: I recently found out that the Adobe Flash Media Server (FMS

Re: Flash Media Servers as Open Proxies

2009-12-03 Thread Charles Wyble
H.. This is most interesting. Have you spoken with Adobe about the issue? I don't have an immediate handle on how they have reacted to security issues in the past. Sane defaults would be nice. :( You might want to ping Akami as they have substantial operational experience with flash medi

Flash Media Servers as Open Proxies

2009-12-03 Thread Marshall Eubanks
I recently found out that the Adobe Flash Media Server (FMS) can operate "out of the box" as an open proxy, enabling other people to steal server resources and bandwidth. Furthermore, I also found that there is an ecosystem of pirates taking advantage of this "feature" to illegally stream spo