Policy file changes in Flash Player 9 and Flash Player 1. This article refers to Flash Player 9 Update 3 9,0,1. Flash Player 9 April 2. Security Update 9,0,1. Flash Player 1. 0. Flash Player 1. 1. For more information on the structure of cross domain policy files used to permit the sharing of data by client side applications across domains, refer to Cross domain policy file specification. For information on serving socket policy files from Linux and Windows hosts, you may find Setting up a socket policy file server very helpful. Note This article was updated in October 2. There are only three substantial changes to be aware of Flash Player 9,0,1. Phase 1. 5 Flash Player 1. Phase 2 of the new restrictions and the Phase 2 default URL meta policy has been changed from the maximally restrictive none to the less restrictive master only, permitting URL master policy files those at crossdomain. In 2. 00. 3, Flash Player 7 software introduced a channel of client server communication that was new to the web direct cross domain data loading, authorized by policy files. Before policy files, web content could only perform two way communication with its own server, such as runtime configuration or transactions without page reloads. Policy files allowed servers to open up their data selectively to client content from other domains, or generally to content from anywhere. Since the introduction of policy files, domain boundaries have been less of a barrier for authors of rich Internet applications. Like most new technologies, policy files werent perfect when they were first introduced. After four years, the Internet security community has found two undesirable situations described later in this article that can arise from the existence of policy files. The basic premise of policy files remains valid, and Flash developers can continue to rely on policy files just as they have since Flash 6. To address the new concerns, however, Adobe is specifying some stricter rules for the use of policy files. Additionally, there are a number of improvements that make policy files more useful and usable. We will try to explain the reasons for our changes clearly and simply. This article assumes some familiarity with policy files. For a detailed introduction to policy files, see the Flash Player Security chapter of Programming Action. Script 3. 0 on Adobe Live. Docs Cross domain policy file usage recommendations for Flash Player and the Cross domain policy file specification. For information about HTTP header sending permissions in policy files, which is not covered in this article, see the relevant section in Understanding Flash Player 9 April 2. Security Update compatibility. How websites need to respond. To conform to the stricter rules, websites that serve policy files will need to make some minor changes. These changes are mainly for the protection of those sites themselvesessentially a new set of security best practices concerning policy files. For most sites, we dont expect the changes to be difficultbut because of the large number of sites impacted, Adobe implemented the stricter requirements in Flash Player in three phases. In Phase 1, which began with Flash Player 9,0,1. Debug versions of Flash Player. In Phase 1. 5, which began with Flash Player 9,0,1. Phase 1 became errors in the specific case of socket operations. In Phase 2, which began with Flash Player 1. Phase 1 became errors and the transition to stricter rules was complete. We recommend that website administrators follow these steps Immediately Read the section on immediate strictness, then follow the workflow steps for diagnosing and fixing immediate issues. This step only applies to sites that serve Flash Player compatible content SWF files. This step accounts for the effects of Phase 1. Immediately Read the section on socket policy files, then follow the workflow steps for configuring socket policy files. This step applies primarily to sites that already provide policy files, but can also provide useful defensive measures to sites with no policy files or SWF files. This step accounts for the effects of Phase 1. As time permits Read the section on meta policies, then follow the workflow steps for choosing and configuring a meta policy. This step applies primarily to sites that already provide policy files, but can also provide useful defensive measures to sites with no policy files or SWF files. This step accounts for the effects of Phase 2. Two issues are addressed by the stricter policy file rules Policy file control. There is a possibility that a file on a server that does not appear to be a policy file may in fact be used as a policy file. For example, if a server permits uploads by users, but does not intend to open data for cross domain access, it is possible that a user could deliberately construct a policy file but disguise it as a different type of file, such as an ordinary text, XML, or HTML file, or even as a binary type, such as a PNG or JPEG image file. A user who successfully uploaded this disguised policy file could then write a SWF file that takes advantage of the disguised policy file to load data from outside the servers domain. Similarly, a site maintainer with limited privileges could add a policy file to the site against an administrators wishes, or even accidentally create a policy file they did not intend to. This issue is essentially one of controlling what policy files are permitted to exist on a server. Server administrators should be able both to set a server wide policy on policy files we call this a meta policy, and to easily search for all policy files on their server, allowing auditing of all cross domain permissions present on the server. The stricter policy file rules in Flash Player allow meta policy declarations by server administrators, and perform greater sanity checking on policy files to help ensure that they are properly formatted. DNS hardening. A class of cross site scripting attacks known as DNS rebinding can target Flash Player, as well as browsers, virtual machines, and other user agent programs. A DNS rebinding attack exploits a user agents same origin policy, in which content from a given Internet domain is permitted to load and communicate with other resources in its own domain without explicit permission. An attacker who controls their own domain, and runs their own DNS server, can dynamically reconfigure their DNS server so that a given domain name resolves first to an IP address under the attackers control which may be used to serve a malicious SWF file or other content, then later to a different IP address that the attacker does not control. If the user agent program does not detect the change in IP addresses, its same origin policy will permit the attackers content to access the second IP address without permission from the second host. Flash Player relies on browsers to provide HTTP networking, so any rebinding vulnerabilities that involve only HTTP must be solved in browsers. However, Flash Player also provides socket level networking via the Action. Script Socket and XMLSocket classes, and the strict policy file rules in Flash Player 9,0,1. DNS rebinding vulnerabilities as they pertain to sockets. Specifically, the strict rules always require permission from a socket policy file in order to make a socket connection, even when the socket server appears to be the same as a connecting SWF files domain of origin. In addition, beginning with version 9,0,1. List of File Extensions and Data Formats. Main Quick Reference. Updated January 1. Posted September 3. By Webopedia Staff. Webopedias list of Data File Formats and File Extensions makes it easy to look through thousands of extensions and file formats to find what you need. With literally thousands of data file formats employed by Windows and Window based apps, keeping track of all the file extensions used by software applications and programs can be a challenge. Webopedias List of Data File Formats and File Extensions. Fortunately, Webopedias Complete List of Data File Formats and File Extensions makes it quick and easy to sift through thousands of file extensions and data file formats to find exactly what you need. You can peruse the full list or search for data formats and file extensions based on the letter they start with from the table below. Data File Formats and File Extensions Complete List. Bit. Torrent Incomplete Download file. Bittorrent Partial Download file. Torrent Incomplete Download file. Printer data file for 2. Loco. Script. ib. Printer data file Loco. Script. sc. Printer data file Loco. Script. st. Standard mode printer definitions Loco. Script. Cryptext. Temporary file. 0. Pipe file DOS. 0. Pipe file DOS. db. Temporary file d. BASE IV. ed. Editor temporary file MS C. Group. Wise Database. Pipe file DOS. vm. Virtual manager temporary file Windows 3. Pervasive. SQL Database file. File Splitter Joiner Encrypted file. File Splitter Joiner Encrypted Archive file. Norton Disk Doctor Recovered file. Windows Live Mail Email file. Windows Live Mail Newsgroup Copy file. Malicious Software Removal Tool Temporary file. Temporary file 1st Reader. Old App. Expert project database Borland C 4. Project backup Borland C 4. Host. Monitor Test. List Backup file. Menu backup Norton Commander. Corel Word. Perfect Document Index file. Temporary file 1st Reader. Image Data Recovery file. Compressed harddisk data Double. Space. 0. 01. Norton Ghost Span file. Multiple Volume Compressed file. Fax many. 0. 75. Ventura Publisher. Ventura Publisher. Ventura Publisher. Ventura Publisher. Printer font with line. Draw extended character set Page. Maker. 0xe. F Secure Renamed Virus file. Inno Setup Binary file. Roffnrofftroffgroff source for manual page cawf. IBM Voice Type Script file. Iomega Backup file. Lotus 1 2 3 Spreadsheet file. Printer font with PI font set Page. Maker. 1pe. Turbo. Tax Form file. 1ph. Turbo. Tax file. 1st. Usually README. 1. ST text. 2. Setup Factory 6. Ripped Video Data file. Drawings Versa. Cad. Dimensional Data Array file. Libraries Versa. Cad. Drawings Versa. Cad. Libraries Versa. Cad. D VRML World. Fax Super FAX 2. Fax Mail 9. 6. 3. Intel 8. 03. 86 processor driver Windows 3. D Assembly file. 3dd. Arc. Globe Document file. DMark Benchmark file. Graphics 3. D Studio. Database for 3. D mind map concept map 3. D Topicscape. 3fx. Effect Corel. Chart. GPP2 file format. GPP Multimedia file. Data file Windows Video Grabber. NGRAIN Mobilizer. Turbo. Tax Form file. D Movie Maker Movie Project. Turbo. Tax 2. 00. Form file. 3t. 4Binary file converter to ASCII Util. Sony Mavica Data file. Datafile 4. Cast2. D View Ultrasound file. MP3 Database file. Swap File. 4th. Forth source code file Forth. CMP LMI Forth. Preconfigured drivers for System 5cr and System 5cr Plus. Music 8 channels The 6. Composer. 6cm. Music 6 Channel Module Triton Fast. Tracker. 7. 77. 7 Zip compressed file archive. Zip archiving format. A8. 6 assembler source code file. Adobe Photoshop Plugin file. Adobe Photoshop Plugin file. Adobe Photoshop Plugin file. Adobe Photoshop Plugin file. Music 8 Channel Module Triton Fast. Tracker. 8li. Photoshop Scripting Plug in. Printer font with Math 8 extended character set Page. Maker. 8pbs. Adobe Photoshop Macintosh file. Printer font with Roman 8 extended character set Page. Maker. a. Ada source code file. Library unix. a. ALZip Split Archive file. Graphics AIIM image file. A2. B Player Playlist. Amapi 3. D Modeling file. Unpackaged Authorware Mac. Intosh file. a. 3w. Unpackaged Authorware Windows file. Authorware 4. x Library. Unpackaged Authorware Mac. Intosh file. a. 4p. Authorware file packaged without runtime. Unpackaged Authorware Windows file. Unpackaged Authorware Windows file. Audible Audio file. Macromedia Authorware Binary. Advanced Audio Coding MPEG 2, MPEG 4. Authorware shocked file. Audible Audiobook file. Parsons Address Book. Datafile ABStat. Datafile ABStat. Palm Address Book file. Action. Script Byte Code File. ABC FLOWCHARTER 1. ABC2. K AudioVideo Controller Software. Am. Biz Bonus Calculator data file. Adventure Builder database. Adobe Binary Font. ABI CODER Encryption software. AOL extension AOL 6 Organizer. Automatic backup file Corel. DRAW. abm. Image. Pals Photo Album Document. Montage Photo Album file. Photo. Plus Album file. Adobe Photoshop brush file. Abstracts info fileData file AbscissaMPEG audio sound file. Abi. Word document. Word. Perfect Address Book file. AOL file located in AOL program directory. AC3 Audio File Format. Microsoft Agent Character file. Project Project Manager Workbench. Graphics ACMB. acc. Program DR DOS View. Max GEM resident. Sonic Foundry Acid music file. Ace Archiver Win. Ace compressed file. Microsoft Agent Character file. Adobe Photoshop Custom Filter. ACI Development Appraisal. Microsoft Office Auto Correction file. Document file Audit Command LanguageArbor. Text Command Language. Audio Compression Manager Driver. Photoshop command button. Windows system file. ACBM image file. Interplay compressed Sound file. ACORN Graphics format. MS Agent Character file. AIMP2 Media Player Skin file. Adobe Content Server Message file. Actor source code file. Foxdoc Action Diagrams Fox. Copy Bcd File Windows 7. ProPresentation Action. OS2 Audio Drivers. Photoshop Saved Curve. Screen saver data After. Dark. ada. Ada source code file. Ada Package Body. Bitmap graphics 1. Scanstudio. ade. Microsoft Access Project. Adapter Description file. Admin Config file. Amiga Disk File. Dog Creek QC Mask file. Graphics Auto. CAD. Mca adapter description library QEMM. After Dark Screen Saver Module. Windows Policy Template. Addict Compiled Dictionary. Administrative template files for protected mode in Internet Explorer 7. Advantage Data Server Database Memo file. Add in Lotus 1 2 3. Photoshop Duotone Options. Stata Program. adp. Fax. Works Modem setup file. Astound Dynamite file. MS Access Project. AOLserver Dynamic Page file. Address Book. Address Plus Database. After Dark Random Screen Saver Module. Opera Web Browser Bookmark file. Smart Address Address Book. Ada Package Specification. Datafile for cardfile application HP New. WaveFax Ad. Tech. Document Archetype Designer. GZ Packed Amiga Disk file. Per Advanced Embedded Hypertext. Adobe After Effects Project file. PGP Armored Extracted Public Encryption Key. After Effects Plugin file. Flowchart ABC Flow. Charter 2. 0. aff. Any. Form Form file. Truevision bitmap graphics. Font file for Allways Lotus 1 2 3. Type 1 font metric ASCII data for font installer ATM manyDatafile for cardfile application HP New. Wave. afs. Adobe Type Manager font set. Any. Form template file. Applixware graphics file. Aspen Graphics Pages. Aspen Graphics Windows. Vector graphics Adobe Illustrator. Audio interchange file format. Compressed file archive created by AIN. APL file transfer format file. Adobe AIR Installation Package file. Automatic Image Registration.