Go Back   CodingForums.com > :: Client side development > Flash & ActionScript

Before you post, read our: Rules & Posting Guidelines

Reply
 
Thread Tools Rate Thread
Enjoy an ad free experience by logging in. Not a member yet? Register.
Old 03-16-2008, 11:09 AM   PM User | #1
BatCountry
New Coder

 
BatCountry's Avatar
 
Join Date: Jul 2007
Location: McMaynerberry, Texas
Posts: 57
Thanks: 5
Thanked 0 Times in 0 Posts
BatCountry can only hope to improve
Is it just me or does Flash seem to bypass CrossDomain.xml? - UNRESOLVED

OK well something weird is a foot, I just re-installed Windows and I'm trying to test a crossdomain.xml which sets what sites/domains/ip can access flvs or flash files. For some reason, I seem to be able to bypass crossdomain.xml and access flvs on another server regardless of whether the crossdomain.xml allows it or not. I've tried it in Firefox, IE and Opera - all seem to bypass it.

Is it just me or does Flash v9.0 (I have CS 3 installed) bypass crossdomain restrictions? Also can anyone give me a test site so that I can see if it's a problem on my end, or just a coincidence?

Hopefully you understand what I'm saying..I'm going out of mind trying to understand this.
-------------------
Here's an example:
http://fresco.awardspace.com/index.html

Using youtube as an example which has a set restrictive crossdomain.xml that includes only sites hosted on youtube to access flvs directly.

Last edited by BatCountry; 03-17-2008 at 01:37 AM.. Reason: example given
BatCountry is offline   Reply With Quote
Old 03-17-2008, 01:36 AM   PM User | #2
BatCountry
New Coder

 
BatCountry's Avatar
 
Join Date: Jul 2007
Location: McMaynerberry, Texas
Posts: 57
Thanks: 5
Thanked 0 Times in 0 Posts
BatCountry can only hope to improve
Unhappy Surely someone can help?

anyone?
BatCountry is offline   Reply With Quote
Old 03-17-2008, 12:38 PM   PM User | #3
StupidRalph
Senior Coder

 
Join Date: Mar 2003
Location: Atlanta
Posts: 1,037
Thanks: 14
Thanked 30 Times in 28 Posts
StupidRalph is on a distinguished road
Sorry I haven't used flash across different domains yet. Have you tried using the similar System.security.allowDomain() and see if that allows you to bypass it too?


Edit: Ignore what I said. I just realized that you said its allowing all domains correct? What version of flash player or you publshing for? I think it has to be 6 and higher.
__________________
Most of my questions/posts are fairly straightforward and simple. I post long verbose messages in an attempt to be thorough.
StupidRalph is offline   Reply With Quote
Old 03-17-2008, 12:40 PM   PM User | #4
StupidRalph
Senior Coder

 
Join Date: Mar 2003
Location: Atlanta
Posts: 1,037
Thanks: 14
Thanked 30 Times in 28 Posts
StupidRalph is on a distinguished road
The Youtube video never loaded on my end.
__________________
Most of my questions/posts are fairly straightforward and simple. I post long verbose messages in an attempt to be thorough.
StupidRalph is offline   Reply With Quote
Old 03-17-2008, 06:29 PM   PM User | #5
BatCountry
New Coder

 
BatCountry's Avatar
 
Join Date: Jul 2007
Location: McMaynerberry, Texas
Posts: 57
Thanks: 5
Thanked 0 Times in 0 Posts
BatCountry can only hope to improve
sorry the video on youtube apparently doesn't work anymore, so the reason you didn't see wasn't because of the crossdomain but because the flv path was wrong.

I've since a video elsewhere, and fixed the example - I put a crossdomain.xml to only allow *.google.com to access the file.

Please try it now..and to everyone: please confirm if you can see the video or not.
BatCountry is offline   Reply With Quote
Old 03-18-2008, 04:57 AM   PM User | #6
StupidRalph
Senior Coder

 
Join Date: Mar 2003
Location: Atlanta
Posts: 1,037
Thanks: 14
Thanked 30 Times in 28 Posts
StupidRalph is on a distinguished road
Yes the video loads. But something (concept wise) isn't right. I mean I thought, that you can load movies BUT those movies wouldn't be able to access your variables or actionscript. I was under the impression that the crossdomain.xml was to allow the developer to load variables or an XML file or something across different domains.
__________________
Most of my questions/posts are fairly straightforward and simple. I post long verbose messages in an attempt to be thorough.
StupidRalph is offline   Reply With Quote
Old 03-18-2008, 05:35 AM   PM User | #7
BatCountry
New Coder

 
BatCountry's Avatar
 
Join Date: Jul 2007
Location: McMaynerberry, Texas
Posts: 57
Thanks: 5
Thanked 0 Times in 0 Posts
BatCountry can only hope to improve
according to Adobe crossdomain.xml is used for security restrictions, so to prevent sites from accessing actionscript,flvs, and yes variables probably as well..but it's clearly not working. On the remote server I set it only for *.google.com.

BTW what browser are you using? Firefox seems to ignore crossdomain.xml but IE usually adheres to it - but recently my IE is allowing everything - so I was just wondering if anyone can try it out in IE or any other non-Firefox browser.
BatCountry is offline   Reply With Quote
Old 03-19-2008, 12:15 PM   PM User | #8
StupidRalph
Senior Coder

 
Join Date: Mar 2003
Location: Atlanta
Posts: 1,037
Thanks: 14
Thanked 30 Times in 28 Posts
StupidRalph is on a distinguished road
Yes, I'm sorry to have not informed you earlier. But I tried it using IE 6.0 as well as Firefox 2.0.12 I believe.

I know your crossdomain.xml has a wildcard on subdomains and I'm just randomly guessing but do you suppose since youtube is under the google's umbrella that its allowing youtube?

Actually, nevermind as they are two totally different domains. I just checked and noticed there is no http://youtube.google.com
__________________
Most of my questions/posts are fairly straightforward and simple. I post long verbose messages in an attempt to be thorough.
StupidRalph is offline   Reply With Quote
Old 03-20-2008, 07:52 AM   PM User | #9
BatCountry
New Coder

 
BatCountry's Avatar
 
Join Date: Jul 2007
Location: McMaynerberry, Texas
Posts: 57
Thanks: 5
Thanked 0 Times in 0 Posts
BatCountry can only hope to improve
it's so weird, I can't figure out why this works? Crossdomain.xml is supposed to stop this, and I could swear it had in the past.
BatCountry is offline   Reply With Quote
Reply

Bookmarks

Jump To Top of Thread


Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 11:44 PM.


Advertisement
Log in to turn off these ads.