Flash’s crossdomain.xml Dangers (WebProNews)
Flash’s crossdomain.xml Dangers (WebProNews)
PHP security guru Chris Shiflett has a great post about the dangers of Cross Domain Flash. If you have implemented a crossdomain.xml file you will want to read his post. If you have a crossdomain.xml file on your domain, and you allow access from ALL domains, then you are essentially opening that domain up to Cross Site Request Forgery attacks. Chris found that flickr had a