Exposing Flash Application Vulnerabilities with SWFScan - The HP Security Laboratory Blog -
Exposing Flash Application Vulnerabilities with SWFScan

After months of hard work and late caffeine-fueled nights, HP’s Web Security Research Group is proud to release HP SWFScan.

HP SWFScan is a free Windows-based security tool to help developers find and fix security vulnerabilities in applications developed with the Adobe Flash Platform. The tool is the first of its kind to decompile applications developed with the Flash platform and perform static analysis to understand their behaviors. This helps developers without security backgrounds identify vulnerabilities hidden within the application which cannot be detected with dynamic analysis methods.

Simply, point HP SWFScan at the SWF file for any Flash application and it will:

  • Decompile the ActionScript 2 or ActionScript 3 bytecode back to the original source code.
  • Audit the code for over 60 vulnerabilities including exposure of confidential data, Cross-Site Scripting (XSS) and cross-domain privilege escalation.
  • Validate the Flash application adherence with Adobe's security best practices.

HP SWFScan is not the first free Flash tool. Excellent decompilers such as Flare or OWASP’s SWFIntruder security tool have existed for a few years now. Unfortunately, the capabilities of free tools have not kept up with new Flash innovations such as the introduction of Flash 9 and 10, ActionScript 3, and Adobe’s Flex framework. HP’s SWFScan is the first and only free tool to decompile both ActionScript 2 and ActionScript 3 and analyze them for security vulnerabilities.

In addition, HP SWFScan offers several other features to help developers, code auditor/reviewers, and pen-testers examine the contents of Flash applications, including:

  • Highlighting the line of source code that contains the vulnerability to help better understand the context of the issue.
  • Providing summaries, details and remediation advice for each vulnerability in accordance with Adobe’s recommendation for secure Flash development.
  • Generating a vulnerability report to share and solve the detected issues.
  • Exporting the decompiled source code for use with other external tools.
  • Revealing all the URLs and web services the Flash Application contacts.
  • Flagging class names, function names, or variable names that may be of interest such as loadedUserXml or crypt()

While developing HP SWFScan, we downloaded and audited over 4000 Flash applications. We encountered numerous insecure applications and collected some interesting statistics:

  • Of 250 Flash applications we tested that had a login form 15% had user names or passwords hard-coded inside the application code.
  • 16% of SWF applications targeting Flash Player 8 and earlier contained XSS vulnerabilities.
  • 35% of all SWF applications violated Adobe's security best practices.
  • 77% of SWF applications targeting Flash Player 9 and 10 contained developer debugging information and source code file references.


(You can learn more about how we got these figures in our SWFScan FAQ)

A few things to note: HP SWFScan only looks at the portion a Flash applications that runs inside the browser. This is the SWF file that contains the Flash code Adobe's Flash player executes. It does not look at the components that run on the server. To conduct a complete security assessment of your applications, HP provides a suite of software and services for testing applications throughout the application lifecycle.

Download HP SWFScan

Need Support or have a question about SWFScan? Visit our SWFScan Forum.

Video explanation of a Flash Attack: (AKA, Billy wins a Cheeseburger)


Posted 03-20-2009 10:12 PM by billyhoffman
Filed under: , , ,

Comments

SecuraByte Episode 06: HP SWFScan | SecuraBit wrote SecuraByte Episode 06: HP SWFScan | SecuraBit
on 03-23-2009 11:33 AM

Pingback from  SecuraByte Episode 06:  HP SWFScan | SecuraBit

swfscan - Sicherheitscheck f??r Flash wrote swfscan - Sicherheitscheck f??r Flash
on 03-23-2009 7:39 PM

Pingback from  swfscan - Sicherheitscheck f??r Flash

HP ver??ffentlicht kostenloses Sicherheitswerkzeug f??r Flash-Entwickler | xobo.cc - Silvio Guder wrote HP ver??ffentlicht kostenloses Sicherheitswerkzeug f??r Flash-Entwickler | xobo.cc - Silvio Guder
on 03-23-2009 11:30 PM

Pingback from  HP ver??ffentlicht kostenloses Sicherheitswerkzeug f??r Flash-Entwickler | xobo.cc - Silvio Guder

.:: Securnetwork.net Blog - Massimo Rabbi ::. » SWFScan: security tool gratuito da HP per gli sviluppatori Flash wrote .:: Securnetwork.net Blog - Massimo Rabbi ::. » SWFScan: security tool gratuito da HP per gli sviluppatori Flash
on 03-24-2009 12:06 AM

Pingback from  .:: Securnetwork.net Blog - Massimo Rabbi ::.  » SWFScan: security tool gratuito da HP per gli sviluppatori Flash

HP ver??ffentlicht kostenloses Sicherheitswerkzeug f??r Flash-Entwickler | Blog von root_alpha wrote HP ver??ffentlicht kostenloses Sicherheitswerkzeug f??r Flash-Entwickler | Blog von root_alpha
on 03-24-2009 9:37 AM

Pingback from  HP ver??ffentlicht kostenloses Sicherheitswerkzeug f??r Flash-Entwickler | Blog von root_alpha

SWF Security Testing Tool von HP | Rich-Media Blog wrote SWF Security Testing Tool von HP | Rich-Media Blog
on 03-24-2009 9:56 AM

Pingback from  SWF Security Testing Tool von HP | Rich-Media Blog

SNOWBALL LABS | Previously ad2 labs wrote SNOWBALL LABS | Previously ad2 labs
on 03-25-2009 12:42 AM

Pingback from  SNOWBALL LABS | Previously ad2 labs

??????????????????Adobe Flash??????????????? « ??????IT???????????????IT????????????????????????????????????????????????????????? wrote ??????????????????Adobe Flash??????????????? « ??????IT???????????????IT?????????????????????????????????????????????????????????
on 03-25-2009 11:30 AM

Pingback from  ??????????????????Adobe Flash??????????????? «  ??????IT???????????????IT?????????????????????????????????????????????????????????

iWeb Blog » iWeb Tech News Highlights: fast polling, first Linux Botnet, Flash vulnerabilities wrote iWeb Blog » iWeb Tech News Highlights: fast polling, first Linux Botnet, Flash vulnerabilities
on 03-25-2009 12:13 PM

Pingback from  iWeb Blog » iWeb Tech News Highlights: fast polling, first Linux Botnet, Flash vulnerabilities

iWeb Blog » Nouvelles Techno iWeb: serveurs de messagerie, botnet Linux, et vuln??rabilit??s Flash wrote iWeb Blog » Nouvelles Techno iWeb: serveurs de messagerie, botnet Linux, et vuln??rabilit??s Flash
on 03-25-2009 12:18 PM

Pingback from  iWeb Blog » Nouvelles Techno iWeb: serveurs de messagerie, botnet Linux, et vuln??rabilit??s Flash

web-media-flash-exposure | markLtuttle wrote web-media-flash-exposure | markLtuttle
on 03-25-2009 2:19 PM

Pingback from  web-media-flash-exposure | markLtuttle

Adobe Flash Vulnerability Scanner « Sharp Mind wrote Adobe Flash Vulnerability Scanner « Sharp Mind
on 03-25-2009 3:35 PM

Pingback from  Adobe Flash Vulnerability Scanner  « Sharp Mind

What’s Been on my Mind at aleatory wrote What’s Been on my Mind at aleatory
on 03-25-2009 4:59 PM

Pingback from  What’s Been on my Mind at  aleatory

?????????HP???????????????????????? | ???????????? wrote ?????????HP???????????????????????? | ????????????
on 03-26-2009 2:48 PM

Pingback from  ?????????HP???????????????????????? | ????????????

Catch Security Vulnerabilities Using SwfScan wrote Catch Security Vulnerabilities Using SwfScan
on 03-26-2009 3:00 PM

Pingback from  Catch Security Vulnerabilities Using SwfScan

Catch Security Vulnerabilities Using SwfScan | Padub wrote Catch Security Vulnerabilities Using SwfScan | Padub
on 03-26-2009 10:21 PM

Pingback from  Catch Security Vulnerabilities Using SwfScan | Padub

HP SWFScan-adobe flash?????????????????????????????? | ?????? wrote HP SWFScan-adobe flash?????????????????????????????? | ??????
on 03-27-2009 2:57 AM

Pingback from  HP SWFScan-adobe flash?????????????????????????????? | ??????

Free Baby Clipart wrote Free Baby Clipart
on 03-28-2009 6:59 AM

Pingback from  Free Baby Clipart

Exposing Flash Application Vulnerabilities with SWFScan | technichristian.net wrote Exposing Flash Application Vulnerabilities with SWFScan | technichristian.net
on 03-29-2009 4:35 PM

Pingback from  Exposing Flash Application Vulnerabilities with SWFScan | technichristian.net

localToGlobal » Blog Archive » news review -> 13th week of 2009 wrote localToGlobal » Blog Archive » news review -> 13th week of 2009
on 03-29-2009 7:31 PM

Pingback from  localToGlobal  » Blog Archive   » news review -> 13th week of 2009

NS?????? » ?????????HP???????????????????????? wrote NS?????? » ?????????HP????????????????????????
on 04-01-2009 10:20 AM

Pingback from  NS?????? » ?????????HP????????????????????????

Seguindo os padr??es de seguran??a da Adobe | Andr?? Carib?? wrote Seguindo os padr??es de seguran??a da Adobe | Andr?? Carib??
on 04-02-2009 1:48 PM

Pingback from  Seguindo os padr??es de seguran??a da Adobe | Andr?? Carib??

Wampiryczny blog wrote Exposing Flash Application Vulnerabilities with SWFScan
on 04-03-2009 6:36 AM

Warto przeczytać: Exposing Flash Application Vulnerabilities with SWFScan. A tak to narzędzie można wykorzystać: Code in a Flash.

HP’s SWFScan does not find simple XSS in Flash Apps | SecureThoughts.com wrote HP’s SWFScan does not find simple XSS in Flash Apps | SecureThoughts.com
on 04-21-2009 6:48 AM

Pingback from  HP’s SWFScan does not find simple XSS in Flash Apps | SecureThoughts.com

Topics about Flash » Exposing Flash Application Vulnerabilities with SWFScan - The HP… wrote Topics about Flash » Exposing Flash Application Vulnerabilities with SWFScan - The HP…
on 04-27-2009 11:39 AM

Pingback from  Topics about Flash  » Exposing Flash Application Vulnerabilities with SWFScan - The HP…

Info Sec News, May 5, 2009 « InfoSec Philippines wrote Info Sec News, May 5, 2009 « InfoSec Philippines
on 05-05-2009 4:04 AM

Pingback from  Info Sec News, May 5, 2009 « InfoSec Philippines

O “HP SWFScan”: uma ferramenta da HP para auditar ficheiros Flash « Q u i n t u s wrote O “HP SWFScan”: uma ferramenta da HP para auditar ficheiros Flash « Q u i n t u s
on 05-15-2009 5:07 AM

Pingback from  O “HP SWFScan”: uma ferramenta da HP para auditar ficheiros Flash « Q u i n t u s

Add a Comment

(required)  
(optional)
(required)  
Remember Me?

Type the numbers and letters above: