Rios said the method is particularly effective since if the request fails, the data will still be transmitted to the attacker's server without the victim knowing.Rios wrote that there are two lessons to be learned: First, running untrusted SWF code is dangerous and that protocol handler blacklists are bad.