News and guides about converting video to flash (FLV/SWF).

Jul 22, 2009

Adobe investigating zero-day bug in Flash

Researchers on Wednesday said they have uncovered attacks in the wild in which malicious Acrobat PDF files are exploiting a vulnerability in Flash and dropping a Trojan onto computers.
The situation could affect tons of users since Flash exists in all popular browsers, is available in PDF files, and is largely operating system-independent.
Any software that uses Flash could be vulnerable to the attack, according to Symantec. Adobe Reader is vulnerable because its Flash interpreter is vulnerable, said Paul Royal, principal researcher at Purewire, a Web security services provider.
In a post on its Web site, Adobe said it "is aware of reports of a potential vulnerability in Adobe Reader and Acrobat 9.1.2 and Adobe Flash Player 9 and 10. We are currently investigating this potential issue and will have an update once we get more information."
"The authors of the exploit have managed to take a bug and turn it into a reliable exploit using a heap spray technique," Patrick Fitzgerald writes on a Symantec Security blog post.
"Typically an attacker would entice a user to visit a malicious Web site or send a malicious PDF via e-mail," he writes. "Once the unsuspecting user visits the Web site or opens the PDF this exploit will allow further malware to be dropped onto the victim's machine. The malicious PDF files are detected as Trojan.Pidief.G and the dropped files as Trojan Horse."
It appears the exploit was first developed about two weeks ago, Royal said. The bug itself has been around since December 2008.
The hole is exploitable on Windows XP and Vista users are protected if User Account Control (UAC) is enabled, Symantec said.
US-CERT offered information about workarounds on its Web site:
• Disable Flash in Adobe Reader 9 on Windows platforms by renaming the following files: "%ProgramFiles%\Adobe\Reader 9.0\Reader\authplay.dll" and "%ProgramFiles%\Adobe\Reader 9.0\Reader\rt3d.dll".
• Disable Flash Player or selectively enable Flash content as described in the "Securing Your Web Browser" document.

Jul 21, 2009

Adobe offers up more Flash technology to open source Move follows Microsoft’s Linux effort by a day; Canonical also makes open source move

Adobe Systems will offer more of its Flash rich media application platform up to open source Tuesday, a move viewed by analysts as reactive to the fierce competition Adobe faces in the rich Internet application space from the Microsoft Silverlight platform.
Also in the open source realm Tuesday, Canonical, commercial sponsor of the Ubuntu Linux distribution, will offer code for the Launchpad software development and collaboration platform in an open source format.
Adobe will make available via open source the company's OSMF (Open Source Media Framework) and Text Layout Framework. Formerly part of the "Strobe" project, OSMF allows for software-based media players to be built based on the Flash platform. Individuals could, for example, add new functionality around the Flash Player.
Text Layout Framework allows users to "to do all the things you want to do with text to make it really cool" on the Flash platform, said McAllister. Sophisticated typography capabilities can be added to Web applications.
The two offerings follow previous Adobe efforts to open source parts of the platform. Previous Flash technologies released via open source have included Flex and its compilers, and the Tamarin virtual machine. Specifications also have been released for streaming formats (convert video to Flash)
"People quite often think that the Flash platform is a closed platform, Adobe-only," McAllister said. "What we're doing is continuing this commitment to making the unique features of the Flash platform open."
Although Adobe insisted its latest open source efforts were not done as any sort of response to Microsoft's Silverlight, analysts nonetheless saw a Microsoft angle.
"It's yet another example of the serve and volley going [on] in the RIA space," said Jeffrey Hammond, principal analyst for application development at Forrester. "Adobe and Microsoft are pushing each other hard, and as a result, the state of the art for RIAs is advancing at an amazing rate."
"Adobe is in a race with Microsoft for RIAs, and open source is a powerful way for Adobe to level the playing field considering Microsoft's huge mindshare and adoption among developers," said Melissa Webster, program vice president for content and digital media technologies at IDC.
The core Flash Player and Flex Builder IDE remain unavailable to open source. " McAllister said. "There's code inside the Flash Player that we don't own," such as codec technology, he said. Flex Builder, meanwhile, is built atop the open source Eclipse IDE.
Still, developers have more open source options with Adobe than with Silverlight, said Webster. She also cited Adobe's Open Screen Project as an example of openness.
"Yes, the Flash Player remains Adobe-proprietary, however with the Open Screen Project, developers can write their own servers to stream media to the Flash Player," Webster said.
Adobe's OSMF and Text Layout Framework better enable companies to take advantage of capabilities of Flash 10 without having to understand all the "nuts and bolts of low-level ActionScript calls and functions," said Hammond. ActionScript is the programming language for the Flash platform.
Adobe is working with Akamai to coordinate OSMF with Akamai's Open Video Player initiative. The companies will provide a framework enabling partners such as developers and content owners to build new services with high-end features.
Canonical's Launchpad, meanwhile, lets developers host and share code for free using the Bazaar version control system. Developers now can contribute directly to Launchpad themselves.
"Launchpad is designed to accelerate collaboration between open source projects," said Canonical founder Mark Shuttleworth, in a statement released by the company.
"Making Launchpad itself open source fulfills a long term intention to give the users of Launchpad the ability to improve the service they use every day," Shuttleworth said.
While open source projects are hosted for free on Launchpad, closed source projects can use the service for a fee.

Jul 20, 2009

Adobe Offering Insecure Reader Software

Despite making a commitment earlier this year to scrutinize its code for bugs more closely, Adobe is offering insecure software on its Web site.
Adobe's Web site makes Adobe Reader 9.10 available to users. Yet in May the company released Reader 9.11 to address at least one critical vulnerability. And in June the company released Reader 9.12 to fix nine critical vulnerabilities.
Secunia, a computer security company based in Denmark, said its Personal Software Inspector (PSI) tool will help users identify Adobe's out-of-date software.
Mikkel Winther, PSI partner manager, said in an e-mailed statement, that PC users need to be diligent about patching. "They need to patch all their vulnerable programs and they need to do so as fast as possible after the patch has been issued from the vendor," he said. "Failing to do so is playing Russian Roulette with your IT security."
In an e-mailed statement, an Adobe spokesperson said, "Adobe Reader 9.1 for Windows is the most recent full installer of the product. Adobe Reader 9.1.1 and 9.1.2 for Windows are patches that require Adobe Reader 9.1 to be present. This is the reason users are offered Adobe Reader 9.1 via the 'Get Adobe Reader' page on Adobe.com. Once Adobe Reader 9.1 is installed, the Adobe Updater will subsequently offer the Adobe Reader 9.1.1 and 9.1.2 patches. Or, alternately, the end user can manually apply the patches via the Product updates section of our Web site."
The problem with this approach is that there's a window of vulnerability between the time that the user downloads the software and the time that the software gets patched by Adobe's update tool.
Adobe didn't immediately respond to a follow-up question about how long that window of vulnerability might last.
That period of vulnerability might be extended if the user declines to accept, or defers, an update because he or she does not want to be interrupted at the moment the updater requests authorization.
Were a user without Reader installed to click on a malicious PDF file on a Web site, the user's computer would be at risk because it would download a vulnerable version of Reader to open the unsafe PDF.
Update: Adobe says the the window of vulnerability is small because its updater tries to update Reader immediately and every seven days thereafter, automatically. However, the company acknowledges that the scenario suggested by Secunia -- clicking on a malicious PDF without Reader installed -- could lead to a compromised system.
An Adobe spokesperson explained, "The updater runs on a separate thread the main Reader process, so a user double-clicking on a PDF file would usually open the file (and trigger a possible attack) before the update manager could prompt the user to apply an update. The updater does not block the main Reader process from executing."
The company says it continues to look at ways to "to further narrow the window of exposure." And of course you can not use it to convert video to Flash.

Adobe Offering Insecure Reader Software

Despite making a commitment earlier this year to scrutinize its code for bugs more closely, Adobe is offering insecure software on its Web site.
Adobe's Web site makes Adobe Reader 9.10 available to users. Yet in May the company released Reader 9.11 to address at least one critical vulnerability. And in June the company released Reader 9.12 to fix nine critical vulnerabilities.
Secunia, a computer security company based in Denmark, said its Personal Software Inspector (PSI) tool will help users identify Adobe's out-of-date software.
Mikkel Winther, PSI partner manager, said in an e-mailed statement, that PC users need to be diligent about patching. "They need to patch all their vulnerable programs and they need to do so as fast as possible after the patch has been issued from the vendor," he said. "Failing to do so is playing Russian Roulette with your IT security."
In an e-mailed statement, an Adobe spokesperson said, "Adobe Reader 9.1 for Windows is the most recent full installer of the product. Adobe Reader 9.1.1 and 9.1.2 for Windows are patches that require Adobe Reader 9.1 to be present. This is the reason users are offered Adobe Reader 9.1 via the 'Get Adobe Reader' page on Adobe.com. Once Adobe Reader 9.1 is installed, the Adobe Updater will subsequently offer the Adobe Reader 9.1.1 and 9.1.2 patches. Or, alternately, the end user can manually apply the patches via the Product updates section of our Web site."
The problem with this approach is that there's a window of vulnerability between the time that the user downloads the software and the time that the software gets patched by Adobe's update tool.
Adobe didn't immediately respond to a follow-up question about how long that window of vulnerability might last.
That period of vulnerability might be extended if the user declines to accept, or defers, an update because he or she does not want to be interrupted at the moment the updater requests authorization.
Were a user without Reader installed to click on a malicious PDF file on a Web site, the user's computer would be at risk because it would download a vulnerable version of Reader to open the unsafe PDF.
Update: Adobe says the the window of vulnerability is small because its updater tries to update Reader immediately and every seven days thereafter, automatically. However, the company acknowledges that the scenario suggested by Secunia -- clicking on a malicious PDF without Reader installed -- could lead to a compromised system.
An Adobe spokesperson explained, "The updater runs on a separate thread the main Reader process, so a user double-clicking on a PDF file would usually open the file (and trigger a possible attack) before the update manager could prompt the user to apply an update. The updater does not block the main Reader process from executing."
The company says it continues to look at ways to "to further narrow the window of exposure." And of course you can not use it to convert video to Flash.

Jul 16, 2009

Suspects Open Fire On Police, 5 Officers Injured

An early morning shoot out Thursday in Jersey City, New Jersey has left two suspects dead and five officers injured - in what may have been the result of a police department investigation into an armed robbery last week, officials said.

The injured officers have been identified as Frank Molina Jr., 35, Michael Camacho, 25, Marc DiNardo, 37, Marc Lavelle, 43, and Dennis Mitchell, whose age has not been identified.
According to Jersey City police, at around 5:15 a.m. an armed black man and woman, wearing long robes and black hoodies, shot at officers at 24 Reed Street in Jersey City. One resident told PIX News that she heard "intense gunfire" as officers returned fire.

In fact, one of the suspects, who have tentatively been identified as 32-year-old Hassan A. Shakur and 23-year-old Amanda Anderson, shedded an outer garment to access a pump shotgun, which is, according to Jersey City Police Chief Thomas Comey, a combat weapon.
PIX News learned that at around 6:45 a.m. the suspects, were 'neutralized.' Jersey City police confirmed Shakur and Anderson were shot and killed by officers. They were apparently cornered in a building, on the corner of Reed Street and Bergen Avenue, which was first searched and evacuated.

Earlier, the pair were able to escape police and an intense manhunt for them included all New Jersey police units. Later, Port Authority police units, K-9 Units, New Jersey State troopers and Emergency Services Unit snipers were called to the scene of the shooting to assist local police in the search that included area rooftops.

Residents told PIX News they saw snipers on rooftops and officers jumping from rooftop to rooftop possibly in pursuit of the suspects,. In addition, cops said that the building where the suspects were subdued is known for drug sales activity and believe the gunfire began with a drug deal gone wrong.

"It was a guy selling drugs and he probably sold some bad drugs and the guy came back to retaliate," said a local resident who witnessed the shooting. "So when they seen the cops coming that's when they shot at the cops. That's probably how they cop got shot. Then they ran into the alleyway so they must have went into the window from the back and go in through the window on the first floor."

According to residents, violence has plagued the area and surrounding communities for many years, leaving some unfazed by the bloodshed that happens on a regular basis. Although they say it happens all the time, some neighbors who spoke to PIX News described Thursday's shootings as "intense" and at times "frightening."

At a press conference Thursday afternoon, Jersey City Police Chief Thomas Comey expressed outrage at how gun violence has become almost accepted in the area and lashed out at loopholes in the law that continue to allow such deadly weapons to be on the street and in the hands of criminals.

"Somebody's gotta wake up and smell the coffee, and say enough is enough," Comey said about taking illegal guns off the streets of the community. "Stop being afraid of the NRA, and start being afraid of our own rights."

Molina a 15-year veteran of the force, who was shot in the back, remains in the Jersey City Medical Center for observation. Camacho, a five-year-veteran, who was shot in the neck, remains in critical condition, as does DiNardo, a 10-year veteran, who was shot in the face. Lavelle, a 20-year veteran, who was shot in the leg, was treated and released, as was Mitchell, a seven-year veteran of the Port Authority police force, who was shot in the arm.

Witnesses say one officer was bleeding from his face and PIX videographer John Fine assisted the male officer into an ambulance. The officer told PIX News that he was, "okay despite the way he looks." He may have been one of the officers who was grazed with a bullet.

Authorities believe Shakur and Anderson may have been involved with a June shooting caught on surveillance tape, but are currently waiting for fingerprint results before making a solid identification.

President Barack Obama, who was visiting Holmdel, New Jersey today, attending a fundraiser at the P&C Art Center for a fundraiser event held by Gov. Jon Corzine, spoke to reporters and emphasized the dangers officers through on a daily basis.

"Our thoughts and prayers go out to all the families of those hurt," Obama said. The shooting "shows the sacrifice our law enforcement officers and their families go through every day." And convert video to Flash.

Jul 15, 2009

Adobe Releases First Beta of ColdFusion 9

Adobe Systems this week released the public beta of the next version of its ColdFusion Web development platform. The new version, dubbed ColdFusion 9, will come with an optional integrated development environment (IDE).
By adding the new IDE, dubbed ColdFusion Builder, Adobe is adding capabilities for more sophisticated developers that ColdFusion has lacked. Among other features, Adobe said it will offer a more customized and extensible development environment for coding data-driven applications, offer server management and debugging.
Originally developed by Allair in the mid 1990s and retained by Adobe when it acquired Macromedia, Adobe said there 800,000 ColdFusion developers. But it faces steep competition including Ruby on Rails, Java Server Pages and Microsoft's ASP.NET and others.
"There are a variety of options that were not there a few years ago," said Gartner analyst Eric Knipp. But he added, the new upgrade is substantial and will likely appeal to the more advanced ColdFusion developers. "A lot of the features that are in ColdFusion 9 are features that the advanced ColdFusion developer community has been clamoring for, for a long time."
Notably is the ability to access any part the language from the ColdFusion scripting language, CF Script, and its support for object relational mapping (ORM) to databases via integration with Hibernate, he said.
ColdFusion 9 will integrate with Adobe's forthcoming Flash Builder 4 framework, released to beta last month "For the first time we are really able to offer a full server side to client side development work flow, with all of our tools and our technology," said Adam Lehman, Adobe's ColdFusion product manager.
"Cold Fusion Builder is an Eclipse based plug-in similar to the Flash Builder, so you basically are installing one inside each other. If I am developing server side code and I want to kick over to write some client access code, and I am in the Flex [Flash] world, all of a sudden I am in the same IDE. We've done a lot to maintain a lot of the fidelity between the two"
The Hibernate support will make it easier developers to provide bi-directional synchronization to databases by providing support for Hibernate-based object relational mapping (ORM). Through the integration, Lehman said developers will be able to access all of the Hibernate internals.
"Today developers spend a lot of time taking that tabular data and basically converting SQL into CFCs ColdFusion Components when they are writing SQL code for inserts and updates and then moving that into this object model," Lehman said. "Because we are basically removing SQL that means we are truly building database independent applications."
While the ORM support should be welcome by ColdFusion developers, Gartner's Knipp said that capability that is now expected. "I don’t know it’s something that's going to win people over to the language, it might keep them from leaving," he said.
Also new in ColdFusion 9 is Server Manager, a Flex-based AIR application that will allow for the administration of ColdFusion Servers. Developers can run the manager on the desktop and control settings and receive alerts, Lehman said. "You can deploy a data source or update our JVM arguments or even deploy a hot fix," he said.
On the integration side, while ColdFusion 8 introduced support for native .NET code and Exchange, ColdFusion 9 adds native support for Microsoft SharePoint services. Developers can build Web Parts in SharePoint via the ColdFusion Markup Language (CFML), including support for single sign on.
"Everything ColdFusion has access to can now be exposed to SharePoint Server, but we also have a way to talk to the SharePoint back-end services, so if you are building an application that needs to interact with a document repository or some of the content management features, you can do that with native CFML, you don’t have to learn any .NET APIs or anything like that," Lehman said.
The new release will also allow developers and users to create, read and update Excel spreadsheets, generate PDFs from Word and PowerPoint, and create Flash presentations from PowerPoint,
For Java developers, ColdFusion 9 will integrate with key portlet servers via support for JSR-168, JSR 268 and Web Services for Remote Portlets (WSRP).
The new release will also include Adobe's Blaze DS, which will support high speed Flash remoting.
Lehman is not saying when ColdFusion is going to be released but he indicated the company is hoping to ship by the end of the year. Pricing was not disclosed.
Use it to convert video to Flash .

Jul 14, 2009

Software That Makes Twitter So Much Tweeter

Most people who aren’t familiar with Twitter are eager to list the reasons why they don’t use this social-networking service. It’s for narcissists. It’s for teenagers. It’s for people who have nothing better to do. It’s a forum for oversharing. While all of these things may be true in some cases, I find Twitter’s 140-character messaging network to be an incredibly useful tool in my everyday life.
I use Twitter as my personalized news feed by following people who “tweet” (write updates) about things that interest me. In one glance I can read White House correspondent Mark Knoller’s tweets about President Obama’s activities, a recipe tweeted by Martha Stewart and WSJ.com tweets with links to news stories.
But Twitter works best with a little help from its friends, namely those programs that are designed to make it more customized and useful with minimal work on the user’s behalf. Here’s a rundown of just some of these helpers. I’m focusing only on ones that run on your computer, either in Web browsers or as stand-alone programs. There is also a plethora of Twitter applications that work on mobile devices like the iPhone and BlackBerry, too many to go into here. A few Twitter programs let you lurk and read tweets without a Twitter account, but in most cases these programs require a Twitter user name and password so they can better organize tweets of the people whom you follow.
To get a Twitter account in the first place, you will need to sign up with a user name and password at Twitter.com and start following people—or subscribing to read someone’s updates. These may be friends or people you simply find interesting, like journalists whose work you read (my Twitter user name is kabster728). You can see whom one person follows, and then opt also to follow those same people and the people those people follow and so on. Though it’s possible to lock your account so it’s private, very few people do so because Twitter encourages open communication throughout the Web.
That said, you can always choose to block someone from following you or stop following someone’s Twitter feed. You can comment on a tweet by sending the person who wrote it an “at reply,” named because the reply starts with the “@” sign followed by the user name of the person to whom you are replying. You can also send direct messages to another Twitter user as long as he or she is following you.
All-Purpose Programs
TweetDeck and Seesmic are two programs that do a good job of filtering others’ tweets and aiding the process of writing tweets. Both use Adobe Air, a tool that lets the program work in the background while continuously refreshing its content. This increases productivity because the programs can be set to display pop-up notifications whenever certain tweets appear.
TweetDeck (a free download at TweetDeck.com) organizes tweets into columns that you designate, such as a column of all tweets that mention your name, your company’s name or the word “Wimbledon.” It eases the process of writing tweets by building in ways to shorten Web links, post photos or translate a tweet into one of 35 languages. TweetDeck also integrates with Facebook so that one TweetDeck column displays your Facebook friends’ latest status updates.
The most recent version of TweetDeck enables synchronization of accounts with an email and password. This means that you can download TweetDeck on several computers, log into your account and see the same columns and settings on all platforms. The new version also includes fun extras like search within each column and the option to show how many followers a user has by displaying that number below his or her tweets.
Seesmic (a free download at seesmic.com) is another all-purpose Twitter program. It works much like TweetDeck, but has a few differences. Seesmic also integrates with Facebook, but does so in a more robust way, showing when Facebook friends share photos or Web links and letting you comment on or “like” someone’s status; TweetDeck only shows Facebook status updates.
Seesmic lets you drag photos into a small window for sharing via Twitter. But its overall look isn’t as visually appealing as TweetDeck’s and it lacks some of TweetDeck’s extra features.
Twhirl (twhirl.org) also runs on Adobe Air, working in the background as you use your computer for other activities. Like the aforementioned programs, it also enables easier tweeting with built-in tools for photo uploading and URL shrinking. Unlike TweetDeck and Seesmic, which focus on Twitter and Facebook, Twhirl enables logging into four types of accounts: Twitter, FriendFeed, Laconi.ca and Identica. But Twhirl shows only one category at a time, like a screen of replies, rather than showing all of these categories at a glance like TweetDeck and Seesmic.
Browser Power
Some Twitter programs run in browsers, not as stand-alone programs. This saves you from downloading a program on multiple computers because you can simply log into your account on any computer using its Web browser. But these programs won’t use the helpful pop-up notifications of Adobe Air; instead, you will need to look in your browser to see new information—like opening Twitter.com.
One such browser-based program is HootSuite (HootSuite.com), which uses an owl as its mascot. HootSuite’s unique features include its ability to set tweets to send at a later time or date, giving your followers the illusion that you are tweeting when you’re actually not, and a built-in statistic-tracker to measure how many people opened a link you posted using its ow.ly URL shortener. Like Twhirl, HootSuite shows only certain categories at a time rather than one overall glance at many categories of tweets.
Twitter.com is getting better, though it’s still weak compared with these other programs. I’ve used add-ons in my Firefox browser to enhance Twitter, and one called Power Twitter is like steroids for Twitter.com, adding photo uploading and link shortening right into the Web site. It also makes friends’ tweets richer by displaying details about any Web links that they share.
No Sign-Up Necessary
If you’re just curious about Twitter and want to see what people are talking about without signing up, try sites that are open to everyone. Twitterfall.com, for example, displays tweets about trending Twitter topics and custom search results in a waterfall-like visual with new tweets spilling over the top every half second. TwitterVision.com cleverly displays tweets around the world on a global map as they are posted, showing where the tweets are from, geographically.
Twitter isn’t limited to Twitter.com, and I wouldn’t likely use it as much were it not for programs like the ones I’ve mentioned and others. So give them a try and find out what makes Twitter useful for you.

Now we can see that everything can not leave Flash. Flash became more and more important, maybe some years later there will be not normal video format. You have to convert video to Flash.

From: news.google.com