{"id":7173,"date":"2020-05-13T22:56:50","date_gmt":"2020-05-13T22:56:50","guid":{"rendered":"http:\/\/www.hexacorn.com\/blog\/?p=7173"},"modified":"2020-05-13T22:57:16","modified_gmt":"2020-05-13T22:57:16","slug":"flash-player-background-updates-from-an-internal-server-via-mms-cfg","status":"publish","type":"post","link":"https:\/\/www.hexacorn.com\/blog\/2020\/05\/13\/flash-player-background-updates-from-an-internal-server-via-mms-cfg\/","title":{"rendered":"Flash Player &#038; Background updates from an internal server via mms.cfg"},"content":{"rendered":"\n<p>This is just a note to reference what I <a href=\"https:\/\/twitter.com\/Hexacorn\/status\/1260697471115722758\">posted<\/a> on Twitter earlier today.<\/p>\n\n\n\n<p>According to <a href=\"https:\/\/www.adobe.com\/devnet\/flashplayer\/articles\/flash_player_admin_guide.html\">Flash Player Admin Guide<\/a> (&#8216;Background updates from an internal server&#8217; section), you can create a mms.cfg file with the following content:<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">AutoUpdateDisable=0 <br>SilentAutoUpdateEnable=1 <br>SilentAutoUpdateServerDomain=&lt;your serv&gt; <\/pre>\n\n\n\n<p>Once installed, Flash will be updating from the server provided in the config. It could be a lolbin\/persistence\/covert channel opportunity. I have not tested it. Also, note that Flash is dying, so this is probably not that important.<\/p>\n\n\n\n<p>In any case though, if you spot mmc.cfg file you may want to inspect it. Procmon tells me that these are possible locations:<\/p>\n\n\n\n<ul><li>C:\\Windows\\System32\\mms.cfg<\/li><li>C:\\Windows\\SysWOW64\\mms.cfg<\/li><li>C:\\Windows\\SysWOW64\\Macromed\\Flash\\mms.cfg<\/li><\/ul>\n","protected":false},"excerpt":{"rendered":"<p>This is just a note to reference what I posted on Twitter earlier today. According to Flash Player Admin Guide (&#8216;Background updates from an internal server&#8217; section), you can create a mms.cfg file with the following content: AutoUpdateDisable=0 SilentAutoUpdateEnable=1 SilentAutoUpdateServerDomain=&lt;your &hellip; <a href=\"https:\/\/www.hexacorn.com\/blog\/2020\/05\/13\/flash-player-background-updates-from-an-internal-server-via-mms-cfg\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[35,19,56,64,58],"tags":[],"_links":{"self":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/7173"}],"collection":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/comments?post=7173"}],"version-history":[{"count":2,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/7173\/revisions"}],"predecessor-version":[{"id":7175,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/7173\/revisions\/7175"}],"wp:attachment":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/media?parent=7173"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/categories?post=7173"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/tags?post=7173"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}