Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Web-App-Sec
[Top] [All Lists]

Re: Crawl And interpret Flash files redux

Subject: Re: Crawl And interpret Flash files redux
Date: Mon, 20 Feb 2006 11:02:08 +0100
Arian,
could be useful to use flasm ...  http://flasm.sourceforge.net

arian.evans wrote:
Does anyone know of a good flash parsing/extraction
utilities for manual swf analysis?

I too am having a real problem finding something that
actually does this effectively. (besides, you know,
the eyeball/hand/mouse widget set)

-ae

-----Original Message-----
From: arian.evans [mailto:arian.evans@anachronic.com] 
Sent: Wednesday, February 15, 2006 8:26 AM
To: lists@dawes.za.net; webappsec@securityfocus.com
Subject: RE: Crawl And interpret Flash files

 
-----Original Message-----
From: Rogan Dawes [mailto:discard@dawes.za.net] 
Sent: Wednesday, February 15, 2006 6:21 AM

tester@mytrashmail.com wrote:
Hi, 

I'm looking for a way to auto Crawl And interpret Flash 
files i'm writing a crawler that should support this 

AFAIK, Metis has/had a flash parser in its spider library.

Rogan
Thanks, I was curious how this was done.

fwiw// I've been testing all the commercial scanners again
and since most of them list "flash" as a bullet point, I made
a couple of SWF files to represent varying complexity of
vector-based navigation (from completely flat w/links to
several layers of rendering).

I can't find a single webappsec tool that automatically
extracts the links and navigates SWFs properly, if at all.

This could *entirely* be the result of my having improperly
designed SWFs, since I won't claim to know what I am doing
with the format.

I will be releasing everything to the public for scrutiny,

-ae





--------------------------------------------------------------
-----------
This List Sponsored by: SpiDynamics

ALERT: "How A Hacker Launches A Web Application Attack!" 
Step-by-Step - SPI Dynamics White Paper
Learn how to defend against Web Application Attacks with real-world 
examples of recent hacking methods such as: SQL Injection, Cross Site 
Scripting and Parameter Manipulation

https://download.spidynamics.com/1/ad/web.asp?Campaign_ID=7013
00000003gRl
--------------------------------------------------------------
------------


-------------------------------------------------------------------------
This List Sponsored by: SpiDynamics

ALERT: "How A Hacker Launches A Web Application Attack!" 
Step-by-Step - SPI Dynamics White Paper
Learn how to defend against Web Application Attacks with real-world 
examples of recent hacking methods such as: SQL Injection, Cross Site 
Scripting and Parameter Manipulation

https://download.spidynamics.com/1/ad/web.asp?Campaign_ID=701300000003gRl
--------------------------------------------------------------------------




-------------------------------------------------------------------------
This List Sponsored by: SpiDynamics

ALERT: "How A Hacker Launches A Web Application Attack!" 
Step-by-Step - SPI Dynamics White Paper
Learn how to defend against Web Application Attacks with real-world 
examples of recent hacking methods such as: SQL Injection, Cross Site 
Scripting and Parameter Manipulation

https://download.spidynamics.com/1/ad/web.asp?Campaign_ID=701300000003gRl
--------------------------------------------------------------------------

<Prev in Thread] Current Thread [Next in Thread>