Another security.allowDomain() question

I have a Flex application cause me a lot of grief because of the infamous * Security Sandbox Violation *.

After having spent a few days in the doc/reference and help online, I hope someone here can give me an idea.

OK, the swf files hosted on "DomainA', used of"DomainB"of a page.

Calling JavaScript from DomainB to DomainA ending by:

Security Sandbox Violation

SecurityDomain ' http://domainB/1685555-02-01-01.m3u 'tried to access incompatible context' http://domainA/main.swf '

Excerpt from Main.mxml, where the word is a character generic allowDomain:
< mx:Application... preinitialize = "application1_preinitializeHandler (event)" >
< mx:Script >
<! [CDATA]
...
protected function application1_preinitializeHandler(event:FlexEvent):void {}
Security.allowDomain("*");
...
}
...

Now, from what I've seen, this should allow any field to access the SWF via javascript... but it's not.

I have 2 things out of the ordinary, and perhaps the problem lies here:

-DomainA and domanB are respectively 5 and 6 parts names (www.julien.devbox.okdown.com and static.julien.devbox.domain.co.uk)

-The Main.swf uses 2 libraries, built separately, and there is no reference to security.allowDomain(), but really no doubt that this is necessary.

Please, any ideas would be very welcome.

Best regards

Julien

There must be code in a SWF file that calls the allowDomain to allow code in

This SWF to call.  So, if you are using modules or apps or RSL, if

code in the SWF files are a reminder, you must have the code in the SWF files

calling allowDomain.  AllowDomain call from the code of the main application only

help for the code in the main SWF file.

There is a function on IFlexModuleFactory calling allowDomain on all

the known modules and RSL.

Tags: Flex

Similar Questions

  • If you have firewall and windows defender, do you really need another security software?

    If you have firewall and windows defender, do you really need another security software?

    I have no other security software

    Norton internet security becomes awkward

    Peter

    Hello

    Yes you still need an antivirus program and you are right that Norton tends to cause problems.

    Norton Removal Tool
    http://Service1.Symantec.com/support/tsgeninfo.nsf/docid/2005033108162039

    You want to remove Norton and old and even uninstalled antivirus can leave remnants then download and run
    the Norton Removal Tool. Also, I would get Avast and Prevx and you should be in good shape.

    Download the 3 to get back to after removing the McAfee antivirus.

    Download - SAVE - go to where you put them - right click - RUN AS ADMIN - REBOOT after each.

    --------------------------------------------------------

    Here is what I use:

    Avast and Prevx proved extremely reliable and compatible with everything I threw at them.

    Avast Home free - stop any shields is not necessary except away from Standard, Web and network is working.

    Prevx - Home - free

    Windows Firewall

    Windows Defender

    Protected IE - mode

    IE 8 - SmartScreen filter WE (IE 7 phishing filter)

    I also IE always start with asset if filter InPrivate IE 8.
    (Sometimes you have to temporarily turn off with the little icon to the left of the + bottom right of IE)

    Avast - stop home - free - all shields you do no need except leave Standard, Web and network running.
    (Double-click the blue icon - details look OK. - upper left Shields - those that you do not cancel).
    http://www.avast.com/eng/avast_4_home.html
    Prevx - Home - small, fast, exceptional CLOUD free protection, working with other security programs. It comes
    a scan only, VERY EFFICIENT, if it finds something to come back here or use Google to see how to remove.
    http://www.prevx.com/

    PCmag - Prevx - Editor's choice
    http://www.PCMag.com/Article2/0, 2817,2346862,00.asp

    Also get Malwarebytes - free - use as scanner only. If you ever suspect malware, and that would be unusual with
    Avast and Prevx running except a low occasional (not much), updated cookie and then run it as
    a scanner. I have a lot of scanners and they never find anything of note that I started to use this configuration.

    http://www.Malwarebytes.org/

    I hope this helps.

    Rob - bicycle - Mark Twain said it is good.

  • Shows the code from other sites to the top of my page. - Security Possible question

    I'm working on a Web page behind a firewall. I use firebug for firefox script debugger and the IE for IE script debugger. If I go to another site (cnn or reddit), then back to my test page, that there is an error in the code for drop down menu jquery that I wrote, rather than the advice that there is an error in jquery - 1.8.3.js, I get a notice that there is an error in the code on the previous page. For example http://www.redditstatic.com/reddit-init.en.IY9Adp1eOs.js will appear in the error console when I'm on my own test server.
    Given that the code on my page tries to run code from someone else, it seems to me that this could be a major security problem. It is perhaps difficult to understand. I have screen shots I try to load.
    Thank you
    Brita
    PS when I debug in IE. I show only the expected jQuery error.

    I rarely use Firebug, so I have not seen myself. Or simply ignored. I hope someone else here or on the list of Firebug/forum can address this problem.

  • How reset my security if questions I do not remember the answers

    I do not remember all

    You have to ask Apple to reset your security questions. To do this, click here and choose a method; If this page does not list one for your country or if you are unable to call, complete and submit this form.

    (137396)

  • Secure area questions

    Hi BC community, I have a few questions Secure area that I need help:

    (1) is it possible to put an expiration of secure area date 30 days from the Date a shipment of form Secure area (via the secure payment area), without having to do it manually via the ADMIN of BC?

    (2) I have a customer who has 3 areas of Secure.  Each Secure area must have a basic text content shown.  The content is specific to this protected area.  Question - I know how to hide/show info Secure area based on the BC-0 {whoisloggedin} and {whoisloggedin} settings - 1, but is there a way to add an ID of the < div > tag to show only the content relevant to a specific area Secure ID?

    Thank you

    Aaron

    Hello

    You can put this in a form:

    Date - October 1, 2013

    There is currently no way to expose it that your request directly, BC in the live version of it has no area ID in the sense of what you use to. But you can look at to try to use:the Developer Reference

    (Javascript/css solution)

  • security internet-question (possible pirates)

    Today I noticed my funny acting internet all of a sudden. When I opened a new page/tab that appears instead of my home pages regulars of google or bing.  I don't know who is this company or why it occurs, it seems to interfere with my internet - I'll be online and suddenly the internet starts acting funny and will not work.

    It is a login screen.

    Can someone tell me why this screen?  What is a hacker?  Who is doing this and why?  Any ideas anyone

    You can use 'force quit' in the dropdown under the Apple

    choose Safari (or other applications, for various reasons) so it

    stops. Then restart Safari, hold down the SHIFT key to the bottom of the browser both

    does not have any previous web saved pages.

    {The browser will remember and reload the same page, unless you choose

    to stop the charging; It is a method of software in the Mac. Another way

    would be to deny access to the internet; stop the Airport (an icon of antenna around)

    (Date et heure dans la fenêtre supérieure droite) or if the internet connection by cable, unplug Ethernet.}

    Without be defined on the start page, you should be able to go in Safari preferences

    and delete the history of the browser including cookies; Check the setting of the home page

    to see that he said that, too. This is part of a situation of Adware that can

    be serious, especially you above or below should react to the presence of evidence.

    After you change the preferences of Safari so do not load the bad page (s), a reboot of the

    Safari would be OK. My browsers don't load anything when I run one.

    • Safari open without restoring the tabs and windows - tip...

    www.chriswrites.com/Open--without-restoring-tabs-and-windows-quick-tip/safari

    "When you want to Open Safari without restoring tabs just hold down the SHIFT key .

  • Norton says thunderbird is dangerous to download and used to let me do it. Another security program said it has a Trojan horse and won't let me download it.

    I used Thunderbird for at least 10 years and it downloaded many times on different computers. After a computer crash, I'm trying to download it, but 2 programs of security would not let me do. I just downloaded Firefox without problem. I see that others have had this problem, but have so far not found a solution.

    You download from here:

  • Transfer iTunes to another PC - multiple questions content

    Hello

    I bought a new laptop (Windows 10) and want to transfer my iTunes to the PC (Vista), via hard drive (and leave duplicates on hard drive for back to the top).

    I've got 20,000 songs and hundreds of playlists.

    On the first attempt, I'm done with no playlists and 9 000 pieces.

    On the second attempt (by replacing the new library with the PC), I found myself with playlists up to 2014 and only 9,000 tunes

    On the third, 17 000 songs and lists full reading - but only until 2014.

    I can only assume that I am not transfer to itls up-to-date? I tried to export the library and playlist to make sure they are u-t-j but I am not sure it is the right method.

    Any ideas? Can't the Chuck on the old PC until I am sure than that.

    Thank you

    Matthew

    Migrate a library iTunes from one computer to another

    These are two approaches that work normally to move an existing library to a new computer.

    Method 1

    1. Save the library with this trick of the user.
    2. Remove the old computer if you no longer wish to access content protected on it.
    3. Restore the backup to your new computer by using the same tool used to back it up.
    4. Keep your current backup in the future.

    Method 2

    Connect the two computers on the same network. Share your old computer < user music > folder and copy the folder of library full iTunes in the < user music > on the new folder. Yet once, remove the old computer so is no longer necessary.

    These two methods should give the new computer, a clone of the library work which was on the former. What about iTunes is it is still the 'home' for your devices library you should not have problems with iTunes will erase and reload.

    I recommend method 1 because it establishes a current backup for your library.

    Note If you have iOS devices and that you have not reached your contacts and calendar all in all items, then you need to create a dummy entry in your new profile and iTunes expected to merge existing data from the device.

    If your media folder has been separated in the main folder of iTunes, you may need to do some preparatory work to make it easier to move. See make a library of portable split.

    If you are in the unfortunate position where you're able to access your original library or a backup and then see recover your iTunes from your iPod or an iOS device to get tips on how to configure your devices with a new library with the maximum preservation of data.

    TT2

  • Will be getting a gtx 770 - Secure Boot question/s

    I understand that secure boot must be disabled, but that I also need to enable legacy support?

    http://support.HP.com/us-en/document/c03975089

    Windows 8.1 - UEFI - friend 80.07 05/09/2013

    Hello:

    If you want to add a video card no HP, you must change both settings according to the instructions on the link below.

    http://support.HP.com/us-en/document/c03653200

  • Pavillion dv6 Wireless Security Configuration Question: router beats Notebook?

    I have a HP Pavilion dv6 Notebook running Windows 7 that I connect to a new router.

    The router offers a high security setting: WPA - PSK (TKIP) and WPA - PSK (AES).  My laptop does not show this as being available.

    It shows that of the two, but not both combined.

    Does anyone know if my laptop can provide this level of security setting so I can match my router?

    My cell phone as a card Intel Centrino Wireless N-1000.

    Thank you!

    Dear Dragon-fur,

    Thank you very much for your kind response and assistance.

    I used the AES as WPA - PSK (AES) parameter.

    However, it seems that a better level of security is available, at least on my router, which combines the AES parameter with the TKIP {WPA - PSK (TKIP)} parameter.  It shows like the WPA - PSK (AES) + WPA - PSK (TKIP).  My notebook, however, does not give this combo setting option.

    I'm misunderstanding you?

    Thank you very much!

    Chai613

  • Security IIS question - Blackberry Java program

    I'm really at a cross roads here, I have a Windows 2003 Standard Server, I need to make sure the user access the installation package for the phone is a member of our active directory, now the file is secured in IIS anonymous access disabled, authenticated access is set to 'Digetst of authentication for Windows domain servers' with the correct realm. The user can go to a site web page with internet explorer on a test computer and prompted for a login name, they put into their network and network password user name and authenticate OK and I know who they are. BUT on BlackBerry phones, any type of phone this is the case, when you are prompted, they put in the SAME EXACT INFORMATION and obtain unauthorized user, it's as if the phone cannot send or receive something. The IIS server has a valid SSL certificate until 2016 and a verisign certificate valid. Content expiration is dsabled. MIME types are correct for the deployment because program if I activate anonymous, anyone can install the program very well (which is not what I want, I'm not anonymous activated), I do not use any substance asp.net but this tab is set to the version 2.0.50272, which should have no effect on this problem. The directory is configured with read / access to the log and index this resource, it has its own pool of applications set to Scripts only, which is also very good.

    Why is it impossible with any configuration of browser on blackberries to authenticate?

    Well, let's say that you have described your problem now.

    I thought that you would say kerberos/ntlm authentication (which is similar, I read on the technet site).

    as far as I know the windows digest authentication is not supported on the blackberry browser, but do not hesitate to get this confirmed by your RIM support.

    Maybe you could go to with https basic authentication?

  • Secure API question

    Hello

    in my application, I use the API signed... I want to deploy the application on the device... while deploying, I need to sign these APIs... I signed these APIs

    When I try to start the application on the device, it is said: application startup error: attempt to access a secure API

    I've done all that is necessary to do to signed API

    no particular reason for this?

    Thanks in advacne.

    Clean.bat helped.

    Thank you

  • securing blazeDS question

    Hello

    I'm working on an application using Grails + Flex. But after scanning by Rational to, the report shows that the application has some security issues like cross-site scripting, phishing through frames and link injection.

    I realized that how does the AppScan is to manipulate the values of different fields of CommandMessage, RemotingMessage, messageId, clientId, Iddm, destination and so forth and look at the answer. For example, AppScan could insert ' alert (22193) < script > < /script > "messageId and if the response contains" alert (22193) < script > < /script > ', then he will report it to you as a problem of cross-site script.

    I wonder if there is a solution to this, such as validation of these fields before sending to MessageBroker or simply returning error message in the response. Grateful if someone can help.

    Kind regards

    Haibin

    Hi Haibin. IDS such as MessageId and Iddm can be defined by the customer. These are only the channels that are used to identify the client message, etc.. BlazeDS will normally produce UUID for the latter, but in some cases, developers can use ID they create themselves instead. The only condition to a point of view of BlazeDS is that the ID to be unique within the application. Because the IDS are simply treated as strings, I think it's a false positive reports of the tool being able to inject some scripts code in the field as a problem. It would be only a matter if the response has been made on the client and the script blocks are executed as is the case with HTML. This does not happen with the AUTHORITY and AMFX as what is sent across the wire is just data.

    That said, it is probably possible to do validation on ID such as MessageID and Iddm if you wanted to. I would like to look at the BlazeDS documentation on processors of queue custom writing and writing custom adapters of e-mail. A custom queue processor where you then have access to each message in the queue outbound for each customer or a custom messaging adapter where you have access to all messages sent to a destination that uses the adapter of writing would probably be the best place to do this kind of check.

    We do no checking of the ID format (we only care if the ID is a valid string) to move to a more recent version of BlazeDS will not help you.

    Hope that helps.

    -Alex

  • Another button in question nested movie clip

    Hello world

    Sorry to ask this type of question once again. I have searched for last 24 hours for a solution and lose the will to live. I am very new to AS 3.0 (and do not have much programming experience), so I guess that's a big part of the problem.

    Here's the situation: I have a clip on the main timeline (image 1), whose instance is called "Main_mc". In Main_mc, I had a few buttons, each defined in this way in the script:

    function goINFO (e:MouseEvent): void {}

    gotoAndStop ("INFO");

    }

    INFO_btn.addEventListener (MouseEvent.CLICK, goINFO);

    Everything worked very well. So I decided to put these buttons in a new clip ("Links_mc" on frame 1 of the 'Main_mc') so that I could add animation. Also, I moved the code above in the Planning Links_mc bar. Now, the buttons do not work. After some research, I understand that with the current code, marked executives must be in the same scenario as the buttons. I tried a number of things, none worked. These, for example:

    function goINFO (e:MouseEvent): void {}

    Main_mc.gotoAndStop ("info");

    }

    function goINFO (e:MouseEvent): void {}

    MovieClip (parent). Main_mc.gotoAndStop ("info");

    }

    All the advice I can get would be greatly appreciated!

    See you soon,.

    Robin

    Try:

    function goINFO (e:MouseEvent): void {}

    MovieClip (parent) .gotoAndStop ("INFO");

    }

    This requires a link inside the hand sits

    There are a few options for how you might code.  The code could stay in the main_mc and you could target the headphones to the buttons in the mc of the link.  Do not have the code to follow the buttons.

  • another escape the question of the room.

    I'm working on the presence of objects around the room, as well as in the inventory. When the player clicks on an object in the room, I want only one instance of the object to disappear and the instance of the object in the inventory to appear.  For the moment, I try to make the objects in my inventory disappears.  Here is the code I use:

    var squarelocated:String;

    squarelocated = "hidden";

    square2_mc. DisplayObject.visible = false;

    var ovallocated:String;

    ovallocated = 'hidden ';

    oval2_mc. DisplayObject.visible = false;

    var circlelocated:String;

    circlelocated = 'hidden ';

    circle2_mc. DisplayObject.visible = false;

    But I get the following output error messages:
    TypeError: Error #1010: a term is undefined and has no properties.
    to escapegametutorialnew_fla::MainTimeline/frame1()
    TypeError: Error #1010: a term is undefined and has no properties.
    to escapegametutorialnew_fla::MainTimeline/frame1()
    at flash.display::MovieClip/gotoAndPlay()
    to escapegametutorialnew_fla::MainTimeline/startMovie4()
    Thanks in advance!  And sorry for the questions, I'm working on a tutorial that is based on Actionscript 2.

    I don't think you want to DisplayObject in the middle of each line you have.  If square2_mc is the instance that should be invisible, you must specify square2_mc.visible = false.

    Also, instead of a string value for the located variables, you can consider using a Boolean type, so that they can be evaluated as true or false.  And you should only use the visible property to do it as well, which would mean you don't need those.  But I say this while being blind to the design.

Maybe you are looking for