« Microsoft releases !exploitable crash evaluation tool | Main | More companies seek third-party Web app code review, survey finds »

SWFScan - Free Flash Security Tool

"HP SWFScan is a free security tool to developers find and fix security vulnerabilities in applications developed with the Adobe Flash Platform. The tool is the first of its kind to decompile applications developed with the Flash platform and perform static analysis to understand their behaviors. This helps developers without security backgrounds identify vulnerabilities hidden within the application which cannot be detected with dynamic analysis methods.

Simply, point HP SWFScan at the SWF file for any Flash application and it will:

    *  Decompile the ActionScript 2 or ActionScript 3 bytecode back to the original source code.
    * Audit the code for over 60 vulnerabilities including exposure of confidential data, Cross-Site Scripting (XSS) and cross-domain privilege escalation.
    * Validate the Flash application adherence with Adobe's security best practices.

HP SWFScan is not the first free Flash tool. Excellent decompilers such as Flare or OWASP's SWFIntruder security tool have existed for a few years now. Unfortunately, the capabilities of free tools have not kept up with new Flash innovations such as the introduction of Flash 9 and 10, ActionScript 3, and Adobe's Flex framework. HP's SWFScan is the first and only free tool to decompile both ActionScript 2 and ActionScript 3 and analyze them for security vulnerabilities.

In addition, HP SWFScan offers several other features to help developers, code auditor/reviewers, and pen-testers examine the contents of Flash applications, including:

    * Highlighting the line of source code that contains the vulnerability to help better understand the context of the issue.
    * Providing summaries, details, and remediation advice for each vulnerability in accordance with Adobe's recommendation for secure Flash development.
    * Generating a vulnerability report to share and solve the detected issues.
    * Exporting the decompiled source code for use with other external tools.
    * Revealing all the URLs and web services the Flash Application contacts.
    * Flagging class names, function names, or variable names that may be of interest such as loadedUserXml or crypt()"


Feed You can follow this conversation by subscribing to the comment feed for this post.

All Comments are Moderated and will be delayed!

Free is always good, thanks!
Amber Kimball

Advanced version of Actionscript view tool