For the complete experience, please enable JavaScript in your browser. Thank you!

  • Creative Cloud
  • Photoshop
  • Illustrator
  • InDesign
  • Premiere Pro
  • After Effects
  • Lightroom
  • See all
  • See plans for: businesses photographers students
  • Document Cloud
  • Acrobat DC
  • Sign
  • Stock
  • Elements
  • Marketing Cloud
  • Analytics
  • Audience Manager
  • Campaign
  • Experience Manager
  • Media Optimizer
  • Target
  • See all
  • Adobe for enterprise
  • Acrobat Reader DC
  • Adobe Flash Player
  • Adobe AIR
  • Adobe Shockwave Player
  • All products
  • Creative Cloud
  • Individuals
  • Photographers
  • Students and Teachers
  • Business
  • Schools and Universities
  • Creative Cloud
  • Marketing Cloud
  • Document Cloud
  • Stock
  • Elements
  • All products
  • Get Support
    Find answers quickly. Contact us if you need to.
    Start now >
  • Learn the apps
    Get started or learn new ways to work.
    Learn now >
  • Ask the community
    Post questions and get answers from experts.
    Start now >
Adobe is changing the world through digital experiences. Our creative, marketing and document solutions empower everyone — from emerging artists to global brands — to bring digital creations to life and deliver them to the right person at the right moment for the best results.
    • About Us
    • Newsroom
    • Careers At Adobe
    • Privacy
    • Security
    • Corporate Responsibility
    • Customer Showcase
    • Investor Relations
    • Events
    • Contact Us
Preorder Estimated Availability Date. Your credit card will not be charged until the product is shipped. Estimated availability date is subject to change. Preorder Estimated Availability Date. Your credit card will not be charged until the product is ready to download. Estimated availability date is subject to change.
Qty:
vat included
Subtotal
Promotions
Estimated shipping
Tax
Calculated at checkout
Total
Review and Checkout
Adobe Developer Connection / Security /

Introducing Adobe SWF Investigator

by Peleus Uhley

Peleus Uhley
  • Adobe

Created

5 March 2012

Page tools

Share on Facebook
Share on Twitter
Share on LinkedIn
Bookmark
Print
securitySWFtesting
Was this helpful?
Yes   No

By clicking Submit, you accept the Adobe Terms of Use.

 
Thanks for your feedback.

Requirements

User level

All

Today I am launching a beta of a tool on Adobe Labs called, Adobe SWF Investigator. This Adobe AIR-based application is a suite of tools that may be useful to SWF developers, quality engineers, and security researchers. The tool allows you to examine every aspect of SWF from both a static and dynamic analysis perspective. The tool is also being released as an open-source application on Open@Adobe so it can be extended or customized for your particular needs.

As a security researcher for the Flash runtime team, I have to look at SWF applications on many different levels. This application started as a way for me to experiment with the AIR runtime and view Local Shared Objects (LSOs). Over time, I continued adding new features to the tool as I encountered new challenges. While I didn't start out with the intention of releasing the tool publicly, it seems to have become useful enough now to merit sharing with a larger audience.

This tool is similar in concept to any multi-purpose tool. It is a collection of simple tools to allow you to quickly address common problems. SWF Investigator's disassembler isn't meant to replace all the features of a high-end, commercial decompiler. However, if you just need a quick overview of the SWF, then this tool has all the features necessary to give you the basic information and perform some quick tests.

Adobe SWF Investigator includes the capability to view the SWF tags, disassemble the ActionScript, and provide a binary view of the SWF. You can also view information related to SWFs such as LSOs and settings files. From a dynamic perspective, you can load files from the local file system into the security context of your domain and with the parameters of your choosing. You can then interact with the SWF as it is running. From a security perspective, the tool includes functionality to test for cross-site scripting vulnerabilities and perform simple fuzzing on AMF services. There are also a few supporting utilities such as a basic ActionScript 3.0 compiler and a simple web server.

Authoring the tool in ActionScript has several advantages. One advantage is that I can achieve more natural interactions with SWF content by using the Flash runtime engine than I would with a Java application. Another advantage is that, as an open-source ActionScript-based application, the tool will be easier for SWF developers to understand and extend. My hope is that developers will quickly want to build on the tool's foundation to meet their more advanced needs. One of the major goals for this project is to provide an easily extensible framework for SWF testing that could be easily modified to meet specific needs by the ActionScript developer community.

This tool is mostly targeted at developers with enough SWF application experience to understand the numerous ActionScript development technical references within the application. However, tool tips were included for many fields as well as a help guide. Having access to the source should also help in understanding any ambiguities. While the overall project is large, it is in essence just a collection of many small components. I will soon post videos that demo the application's functionality.

Since the tool is open-source, please feel free to contribute your ideas and feedback in the forums. You can find the binary on Adobe Labs and the source on the Open@Adobe web site. The source and binaries are provided as-is to the ActionScript development community, but we do welcome any feedback and suggestions you have.

Creative Commons License
This work is licensed under a Creative Commons Attribution-Noncommercial-Share Alike 3.0 Unported License

More Like This

  • The Flash Player sandbox bridge
Choose your region United States (Change)   Products   Downloads   Learn & Support   Company
Choose your region Close

Americas

Europe, Middle East and Africa

Asia Pacific

  • Brasil
  • Canada - English
  • Canada - Français
  • Latinoamérica
  • México
  • United States
  • Africa - English
  • Österreich - Deutsch
  • Belgium - English
  • Belgique - Français
  • België - Nederlands
  • България
  • Hrvatska
  • Cyprus - English
  • Česká republika
  • Danmark
  • Eesti
  • Suomi
  • France
  • Deutschland
  • Greece - English
  • Magyarország
  • Ireland
  • Israel - English
  • ישראל - עברית
  • Italia
  • Latvija
  • Lietuva
  • Luxembourg - Deutsch
  • Luxembourg - English
  • Luxembourg - Français
  • Malta - English
  • الشرق الأوسط وشمال أفريقيا - اللغة العربية
  • Middle East and North Africa - English
  • Moyen-Orient et Afrique du Nord - Français
  • Nederland
  • Norge
  • Polska
  • Portugal
  • România
  • Россия
  • Srbija
  • Slovensko
  • Slovenija
  • España
  • Sverige
  • Schweiz - Deutsch
  • Suisse - Français
  • Svizzera - Italiano
  • Türkiye
  • Україна
  • United Kingdom
  • Australia
  • 中国
  • 中國香港特別行政區
  • Hong Kong S.A.R. of China
  • India - English
  • 日本
  • 한국
  • New Zealand
  • Southeast Asia (Includes Indonesia, Malaysia, Philippines, Singapore, Thailand, and Vietnam) - English
  • 台灣

Commonwealth of Independent States

  • Includes Armenia, Azerbaijan, Belarus, Georgia, Moldova, Kazakhstan, Kyrgyzstan, Tajikistan, Turkmenistan, Ukraine, Uzbekistan

Copyright © 2017 Adobe Systems Incorporated. All rights reserved.

Terms of Use | Privacy | Cookies

AdChoices