Adobe
Products
Acrobat
Creative Cloud
Creative Suite
Digital Marketing Suite
Digital Publishing Suite
Elements
Photoshop
Touch Apps
Student and Teacher Editions
More products
Solutions
Digital marketing
Digital media
Education
Financial services
Government
Web Experience Management
More solutions
Learning Help Downloads Company
Buy
Home use for personal and home office
Education for students, educators, and staff
Business for small and medium businesses
Licensing programs for businesses, schools, and government
Special offers
Search
 
Info Sign in
Welcome,
My cart
My orders My Adobe
My Adobe
My orders
My information
My preferences
My products and services
Sign out
Why sign in? Sign in to manage your account and access trial downloads, product extensions, community areas, and more.
Adobe
Products Sections Buy   Search  
Solutions Company
Help Learning
Sign in Sign out My orders My Adobe
Preorder Estimated Availability Date. Your credit card will not be charged until the product is shipped. Estimated availability date is subject to change. Preorder Estimated Availability Date. Your credit card will not be charged until the product is ready to download. Estimated availability date is subject to change.
Qty:
Purchase requires verification of academic eligibility
Subtotal
Review and Checkout
Adobe Developer Connection / Security /

Introducing Adobe SWF Investigator

by Peleus Uhley

Peleus Uhley
  • Adobe

Created

5 March 2012

Page tools

Share on Facebook
Share on Twitter
Share on LinkedIn
Bookmark
Print
security SWF testing

Requirements

User level

All

Today I am launching a beta of a tool on Adobe Labs called, Adobe SWF Investigator. This Adobe AIR-based application is a suite of tools that may be useful to SWF developers, quality engineers, and security researchers. The tool allows you to examine every aspect of SWF from both a static and dynamic analysis perspective. The tool is also being released as an open-source application on Open@Adobe so it can be extended or customized for your particular needs.

As a security researcher for the Flash runtime team, I have to look at SWF applications on many different levels. This application started as a way for me to experiment with the AIR runtime and view Local Shared Objects (LSOs). Over time, I continued adding new features to the tool as I encountered new challenges. While I didn't start out with the intention of releasing the tool publicly, it seems to have become useful enough now to merit sharing with a larger audience.

This tool is similar in concept to any multi-purpose tool. It is a collection of simple tools to allow you to quickly address common problems. SWF Investigator's disassembler isn't meant to replace all the features of a high-end, commercial decompiler. However, if you just need a quick overview of the SWF, then this tool has all the features necessary to give you the basic information and perform some quick tests.

Adobe SWF Investigator includes the capability to view the SWF tags, disassemble the ActionScript, and provide a binary view of the SWF. You can also view information related to SWFs such as LSOs and settings files. From a dynamic perspective, you can load files from the local file system into the security context of your domain and with the parameters of your choosing. You can then interact with the SWF as it is running. From a security perspective, the tool includes functionality to test for cross-site scripting vulnerabilities and perform simple fuzzing on AMF services. There are also a few supporting utilities such as a basic ActionScript 3.0 compiler and a simple web server.

Authoring the tool in ActionScript has several advantages. One advantage is that I can achieve more natural interactions with SWF content by using the Flash runtime engine than I would with a Java application. Another advantage is that, as an open-source ActionScript-based application, the tool will be easier for SWF developers to understand and extend. My hope is that developers will quickly want to build on the tool's foundation to meet their more advanced needs. One of the major goals for this project is to provide an easily extensible framework for SWF testing that could be easily modified to meet specific needs by the ActionScript developer community.

This tool is mostly targeted at developers with enough SWF application experience to understand the numerous ActionScript development technical references within the application. However, tool tips were included for many fields as well as a help guide. Having access to the source should also help in understanding any ambiguities. While the overall project is large, it is in essence just a collection of many small components. I will soon post videos that demo the application's functionality.

Since the tool is open-source, please feel free to contribute your ideas and feedback in the forums. You can find the binary on Adobe Labs and the source on the Open@Adobe web site. The source and binaries are provided as-is to the ActionScript development community, but we do welcome any feedback and suggestions you have.

Creative Commons License
This work is licensed under a Creative Commons Attribution-Noncommercial-Share Alike 3.0 Unported License

 

Products

  • Acrobat
  • Creative Cloud
  • Creative Suite
  • Digital Marketing Suite
  • Digital Publishing Suite
  • Elements
  • Mobile Apps
  • Photoshop
  • Touch Apps
  • Student and Teacher Editions

Solutions

  • Digital marketing
  • Digital media
  • Web Experience Management

Industries

  • Education
  • Financial services
  • Government

Help

  • Product help centers
  • Orders and returns
  • Downloading and installing
  • My Adobe

Learning

  • Adobe Developer Connection
  • Adobe TV
  • Training and certification
  • Forums
  • Design Center

Ways to buy

  • For personal and home office
  • For students, educators, and staff
  • For small and medium businesses
  • For businesses, schools, and government
  • Special offers

Downloads

  • Adobe Reader
  • Adobe Flash Player
  • Adobe AIR
  • Adobe Shockwave Player

Company

  • News room
  • Partner programs
  • Corporate social responsibility
  • Career opportunities
  • Investor Relations
  • Events
  • Legal
  • Security
  • Contact Adobe
Choose your region United States (Change)
Choose your region Close

North America

Europe, Middle East and Africa

Asia Pacific

  • Canada - English
  • Canada - Français
  • Latinoamérica
  • México
  • United States

South America

  • Brasil
  • Africa - English
  • Österreich - Deutsch
  • Belgium - English
  • Belgique - Français
  • België - Nederlands
  • България
  • Hrvatska
  • Česká republika
  • Danmark
  • Eastern Europe - English
  • Eesti
  • Suomi
  • France
  • Deutschland
  • Magyarország
  • Ireland
  • Israel - English
  • ישראל - עברית
  • Italia
  • Latvija
  • Lietuva
  • Luxembourg - Deutsch
  • Luxembourg - English
  • Luxembourg - Français
  • الشرق الأوسط وشمال أفريقيا - اللغة العربية
  • Middle East and North Africa - English
  • Moyen-Orient et Afrique du Nord - Français
  • Nederland
  • Norge
  • Polska
  • Portugal
  • România
  • Россия
  • Srbija
  • Slovensko
  • Slovenija
  • España
  • Sverige
  • Schweiz - Deutsch
  • Suisse - Français
  • Svizzera - Italiano
  • Türkiye
  • Україна
  • United Kingdom
  • Australia
  • 中国
  • 中國香港特別行政區
  • Hong Kong S.A.R. of China
  • India - English
  • 日本
  • 한국
  • New Zealand
  • 台灣

Southeast Asia

  • Includes Indonesia, Malaysia, Philippines, Singapore, Thailand, and Vietnam - English

Copyright © 2012 Adobe Systems Incorporated. All rights reserved.

Terms of Use | Privacy Policy and Cookies (Updated)

Ad Choices

Reviewed by TRUSTe: site privacy statement