Please create an account to participate in the Slashdot moderation system

 



Forgot your password?
typodupeerror
×
HP Security

HP's Free Adobe Flash Vulnerability Scanner 82

Catalyst writes "SWFScan is a free Flash security tool (download here), released by HP Software, which decompiles all versions of Flash and scans them for over 60 security vulnerabilities. The scan detects things like XSS, SQL inside of the Flash app, hard-coded authentication credentials, weak encryption, insecure function calls, cross-domain privilege escalation, and violations of Adobe's security recommendations. There is also this video explaining a real, and amusing, attack against a Flash app. These issues are fairly widespread, with over 35% of SWF applications violating Adobe security advice."
This discussion has been archived. No new comments can be posted.

HP's Free Adobe Flash Vulnerability Scanner

Comments Filter:
  • What good is it? (Score:5, Interesting)

    by frovingslosh ( 582462 ) on Tuesday March 24, 2009 @03:17PM (#27316243)
    Unless they make it into a Firefox plug-in that checks the flash code before running it, just what good is this?
  • Youtube (Score:5, Interesting)

    by JJman ( 916535 ) on Tuesday March 24, 2009 @04:11PM (#27317119)
    So naturally my first thought was, I wonder how well youtube does.
    And lo: it's got 7 vulnerabilities.

    It's interesting how this behemoth of a flash provider is still not secure.
    *reaches for tinfoil hat*
  • Re:Youtube (Score:3, Interesting)

    by phase_9 ( 909592 ) on Tuesday March 24, 2009 @05:01PM (#27318349) Homepage
    I ran this app on my own Flash App (http://moshimonsters.com/) and it produced a plethora of "Vulnerabilities" - and really dangerous ones too like "Interesting Variable Name" (a variable named "masterList") and "Possible userdata information" (a constant named "LOGGED_IN")... To be honest this seems like a lot of FUD being generated by HP - I mean just go look at the dailyWTF and you'll see programmers butting SQL statements in javascript! Still, I must give credit where it's due and thank HP for providing one of the most thorough SWF decompilers I have seen for free.

And it should be the law: If you use the word `paradigm' without knowing what the dictionary says it means, you go to jail. No exceptions. -- David Jones

Working...