Ad rotator swf with possible x-site XML info

Hi: My friend does online advice and pointed out a flash ad from another listing (and definitely a different category) that she’d like in her listing. Maybe she’s shy about making contact and asking, Maybe I’m not, but she’s not taking calls ;). I would show you the ad, but it’s hosted at a site with kinky toys. :whip: :crazy: The listing is also of questionable content. Maybe I can attach a censored screen shot, though. The site where these people do their listings does not allow javascript (pics, mp3s, vids, etc. are hosted offsite whre the account holder puts them (like myspacers did with photobucket) and the embed code contains:

<param name="allowScriptAccess" value="always">

Would this not be x-site scripting if her HTML or actionscript called the external JS and not work ? Unless it’s JSON-P is that possible? A JSON-P file that the swf calls? Again, JS is not allowed in the listing. They type or paste their HTML in a text box.

See… somehow this swf in a flash player gets ad text and links to rotate. I doubt it is hard coded every time she adds a toy or video she wants to promote. Never know what one will learn to make a buck, though

XML list?

Been a while since I dabbled in AS and I don’t have time right now. I found this site: http://www.flashxml.net

I’ll post the embed code in case that helps.

<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000"
    codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=8,0,0,0"
    width="400" height="187" id="widget" align="top"><param name="allowScriptAccess"     value="always">
<param name="allowFullScreen" value="false">
<param name="FlashVars" value="userID=304">
<param name="movie" value="http://www.my.com/widgets/widget6.swf">
<param name="menu" value="false">
<param name="quality" value="high">
<param name="salign" value="t">
<param name="wmode" value="transparent">
<embed src="http://www.my.com/widgets/widget6.swf" flashvars="userID=304" menu="false" quality="high"
    salign="t" wmode="transparent" width="400" height="187" name="widget" align="top"
     type="application/x-shockwave-flash"></embed></object>

So her widget is at her online store. The domain registry info is private - suspect they hawk e-commerce software targeted at niches and provided the swf widget

flashvars="userID=304"

What is that? Maybe the widget’s ad text is entered in an app provided by the host and the XML comes from their database? The host (the folks hiding the domain info / holding the name hostage ) is

Reverse Whois:
"Customer of Lunarpages" owns about11 other domains
... blah ...
Registrant:
 Customer of Lunarpages
 Free Domain for Life!!!!
 100 E. La Habra Blvd.
 La Habra, CA 90631
 US

http://www.lunarpages.com

no indication of that at lunarpages, but who knows?

If you think this is doable, I’ll contact them for details and see if the have a similar widget. Or maybe one of you knows where I can get one. The widget, that is - STOP THINKING THAT WAY! 8)

Or something I haven’t thought of.

TIA and Regards
Mike