<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" 
      xmlns:thr="http://purl.org/syndication/thread/1.0">
  <link rel="alternate" type="text/html" href="http://www.insideria.com/2009/03/swfscan---first-look.html" />
  <link rel="self" type="application/atom+xml" href="http://www.insideria.com/atom.xml" />
  <id>tag:www.insideria.com,2009://34/tag:www.insideria.com,2009://34.35701-</id>
  <updated>2009-11-16T15:09:41Z</updated>
  <title>Comments for SWFScan - First Look (http://www.insideria.com/2009/03/swfscan---first-look.html)</title>
  <generator uri="http://www.sixapart.com/movabletype/">Movable Type 4.21-en</generator>
  <entry>
    <id>tag:www.insideria.com,2009://34.35701</id>
    <link rel="alternate" type="text/html" href="http://www.insideria.com/2009/03/swfscan---first-look.html" />
    <link rel="service.edit" type="application/atom+xml" href="http://blogs.oreilly.com/cgi-bin/mt/mt-atom.cgi/weblog/blog_id=34/entry_id=35701" title="SWFScan - First Look" />
    <published>2009-03-24T22:09:32Z</published>
    <updated>2009-03-25T13:09:50Z</updated>
    <title>SWFScan - First Look</title>
    <summary>I&apos;ve seen several blog posts recently announcing SWFScan, a free tool from HP for decompiling and inspecting swf files for security vulnerabilities.  In this post, we&apos;ll take a quick glance at what the tool can do for you.</summary>
    <author>
      <name>Andrew Trice</name>
      
    </author>
    
    <category term="Blogs" />
    
    <content type="html" xml:lang="en" xml:base="http://www.insideria.com/">
      <![CDATA[<p>I've seen several blog posts recently announcing <a target="_blank" href="https://h30406.www3.hp.com/campaigns/2009/wwcampaign/1-5TUVE/index.php?key=swf&jumpid=go/swfscan">SWFScan</a>, a free tool from HP for decompiling and inspecting swf files for security vulnerabilities.  In this post, we'll take a quick glance at what the tool can do for you.</p>

<p>From the HP site:<br />
<blockquote>HP SWFScan, a free tool developed by HP Web Security Research Group, will automatically find security vulnerabilities in applications built on the Flash platform.</blockquote></p>

<p>My initial experience is that this is a very easy to use AS2 and AS3 swf decompiler.  You just point it at a file or URL, and it will decompile it.  It will also analyze the swf to detect any embedded URLS, and more importantly any potential security threats (Database connection strings, passwords, debug messaging, cross site scripting vulnerabilities, etc..).  This could be useful if you are auditing your own applications, or if you are inheriting a legacy application and want to find any weaknesses in it.</p>

<p>Just to test it out, I pointed it at acrobat.com, and below is an example of what I found.   Had there been any vulnerabilities on that site, then they would show up in the vulnerabilities frame on the lower right.</p>

<p><a href="http://www.insideria.com/upload/2009/03/swfscan.png" class="highslide" onclick="return hs.expand(this)"><img src="http://www.insideria.com/upload/2009/03/swfscan.png" alt="swfscan.png" title="Click to enlarge" width="520"/></a></p>

<p><br />
You have the ability to export source for the application, generate vulnerability reports, and there are lots of options for code inspection.  It is a free download from HP, so you go try it out for yourself, and ensure that your own applications are safe and secure.</p>

<p>Related Links:<br />
<a target="_blank" href="https://h30406.www3.hp.com/campaigns/2009/wwcampaign/1-5TUVE/index.php?key=swf&jumpid=go/swfscan">SWFScan Download Page</a></p>

<p>___________________________________<br />
<strong>Andrew Trice</strong><br />
Principal Architect<br />
<a href="http://www.cynergysystems.com" target="_blank">Cynergy Systems<br />
http://www.cynergysystems.com</a></p>]]>
      
    </content>
  </entry>

  <entry>
    <id>tag:www.insideria.com,2009://34.35701-comment:2055890</id>
    <thr:in-reply-to ref="tag:www.insideria.com,2009://34.35701" type="text/html" href="http://www.insideria.com/2009/03/swfscan---first-look.html"/>
    <link rel="alternate" type="text/html" href="http://www.insideria.com/2009/03/swfscan---first-look.html#comment-2055890" />
    <title>Comment from Chris on 2009-03-24</title>
    <author>
        <name>Chris</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p></p>

<p>..But not available for Mac...</p>]]>
    </content>
    <published>2009-03-25T00:30:06Z</published>
  </entry>

  <entry>
    <id>tag:www.insideria.com,2009://34.35701-comment:2055891</id>
    <thr:in-reply-to ref="tag:www.insideria.com,2009://34.35701" type="text/html" href="http://www.insideria.com/2009/03/swfscan---first-look.html"/>
    <link rel="alternate" type="text/html" href="http://www.insideria.com/2009/03/swfscan---first-look.html#comment-2055891" />
    <title>Comment from Andrew Trice on 2009-03-24</title>
    <author>
        <name>Andrew Trice</name>
        <uri>http://www.tricedesigns.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.tricedesigns.com">
        <![CDATA[<p>Yeah, looks like it is Windows only - forgot to mention that.</p>]]>
    </content>
    <published>2009-03-25T00:38:03Z</published>
  </entry>

  <entry>
    <id>tag:www.insideria.com,2009://34.35701-comment:2055969</id>
    <thr:in-reply-to ref="tag:www.insideria.com,2009://34.35701" type="text/html" href="http://www.insideria.com/2009/03/swfscan---first-look.html"/>
    <link rel="alternate" type="text/html" href="http://www.insideria.com/2009/03/swfscan---first-look.html#comment-2055969" />
    <title>Comment from Vipin on 2009-03-25</title>
    <author>
        <name>Vipin</name>
        <uri>http://flashchemist.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://flashchemist.com">
        <![CDATA[<p>So, all code is open..and tool which do it so easily?</p>]]>
    </content>
    <published>2009-03-25T21:53:34Z</published>
  </entry>

  <entry>
    <id>tag:www.insideria.com,2009://34.35701-comment:2055976</id>
    <thr:in-reply-to ref="tag:www.insideria.com,2009://34.35701" type="text/html" href="http://www.insideria.com/2009/03/swfscan---first-look.html"/>
    <link rel="alternate" type="text/html" href="http://www.insideria.com/2009/03/swfscan---first-look.html#comment-2055976" />
    <title>Comment from JMC on 2009-03-25</title>
    <author>
        <name>JMC</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>Couldn't help but think it was a tool that could make exploiting .swfs a lot quicker and easier too...</p>]]>
    </content>
    <published>2009-03-26T00:34:52Z</published>
  </entry>

  <entry>
    <id>tag:www.insideria.com,2009://34.35701-comment:2056070</id>
    <thr:in-reply-to ref="tag:www.insideria.com,2009://34.35701" type="text/html" href="http://www.insideria.com/2009/03/swfscan---first-look.html"/>
    <link rel="alternate" type="text/html" href="http://www.insideria.com/2009/03/swfscan---first-look.html#comment-2056070" />
    <title>Comment from Mike Slinn on 2009-03-26</title>
    <author>
        <name>Mike Slinn</name>
        <uri>http://mslinn.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://mslinn.com">
        <![CDATA[<p>When I point it at acrobat.com I get "Malformed SWF header".  I tried various incantations of the URL.  What URL did you use?</p>]]>
    </content>
    <published>2009-03-27T04:51:33Z</published>
  </entry>

  <entry>
    <id>tag:www.insideria.com,2009://34.35701-comment:2056354</id>
    <thr:in-reply-to ref="tag:www.insideria.com,2009://34.35701" type="text/html" href="http://www.insideria.com/2009/03/swfscan---first-look.html"/>
    <link rel="alternate" type="text/html" href="http://www.insideria.com/2009/03/swfscan---first-look.html#comment-2056354" />
    <title>Comment from Andrew Trice on 2009-03-27</title>
    <author>
        <name>Andrew Trice</name>
        <uri>http://www.tricedesigns.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.tricedesigns.com">
        <![CDATA[<p>You have to use the direct URL to the swf file: <a href="https://www.acrobat.com/adc.swf"><a href="https://www.acrobat.com/adc.swf">https://www.acrobat.com/adc.swf</a></a></p>

<p>Also, after it loads, you have to hit the "analyze" button to get the potential vulnerabilities to show up.</p>]]>
    </content>
    <published>2009-03-27T12:34:34Z</published>
  </entry>

  <entry>
    <id>tag:www.insideria.com,2009://34.35701-comment:2056768</id>
    <thr:in-reply-to ref="tag:www.insideria.com,2009://34.35701" type="text/html" href="http://www.insideria.com/2009/03/swfscan---first-look.html"/>
    <link rel="alternate" type="text/html" href="http://www.insideria.com/2009/03/swfscan---first-look.html#comment-2056768" />
    <title>Comment from Vinoth on 2009-03-29</title>
    <author>
        <name>Vinoth</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>Most of the features of this tool is similar to Actionscript viewer</p>]]>
    </content>
    <published>2009-03-30T06:12:47Z</published>
  </entry>

  <entry>
    <id>tag:www.insideria.com,2009://34.35701-comment:2067376</id>
    <thr:in-reply-to ref="tag:www.insideria.com,2009://34.35701" type="text/html" href="http://www.insideria.com/2009/03/swfscan---first-look.html"/>
    <link rel="alternate" type="text/html" href="http://www.insideria.com/2009/03/swfscan---first-look.html#comment-2067376" />
    <title>Comment from Andrew on 2009-06-29</title>
    <author>
        <name>Andrew</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>In case anyone is using secureSWF to obfuscate their AS code -- the code is still obfuscated when decompiled with HP's SWFscan. I tried it out with one of my own swf's to confirm.</p>]]>
    </content>
    <published>2009-06-29T07:11:21Z</published>
  </entry>

</feed
