Adobe SWF Investigator : New From Adobe!

grandpaflo

Member
Jan 18, 2011
139
2
81
March 6, 2012

### BREAKING NEWS ! ### ADOBE PRESENTS: ###

Adobe SWF Investigator

Perform quick, comprehensive, analysis of SWF applications

- http://labs.adobe.com/technologies/swfinvestigator/

Download and Discuss:
- http://labs.adobe.com/downloads/swfinvestigator.html
Discuss SWF Investigator:
- http://forums.adobe.com/community/labs/swfinvestigator/

Adobe® SWF Investigator is the only comprehensive, cross-platform, GUI-based set of tools, which enables quality engineers, developers and security researchers to quickly analyze SWF files to improve the quality and security of their applications. With SWF Investigator, you can perform both static and dynamic analysis of SWF applications with just one toolset. SWF Investigator lets you quickly inspect every aspect of a SWF file from viewing the individual bits all the way through to dynamically interacting with a running SWF.

*** SWF Investigator Features ***

From a static perspective, you can disassemble ActionScript 2 (AS2) and ActionScript 3 (AS3) SWFs, view SWF tags and make binary changes to SWF files. SWF Investigator also lets you view associated information, including local shared objects (LSOs) and per site settings.

From a dynamic perspective, you can call functions within the SWF, load the SWF in various contexts, communicate via local connections and send messages to Action Message Format (AMF) endpoints in order to test more effectively.

SWF Investigator contains an extensible fuzzer for SWF applications and AMF services, so you can search for common Web application attacks. This toolset also provides a variety of utilities including encoders and decoders for SWF data, as well as a basic compiler for testing small pieces of ActionScript code.

Additional Benefits

SWF Investigator is the only application of its kind that's built on Adobe AIR – a versatile runtime that supports ActionScript, the language used to create SWF applications. This allows for native interaction between the SWF Investigator and the SWF application. Using ActionScript also makes the source code of the tool more intuitive for SWF developers.

SWF Investigator has the ability to auto-update, so you don't need to worry about whether or not you have the most current version.

Since it's an open source AIR application, SWF Investigator can be modified to fit your environment, and it is cross-platform.

Read the Introducing Adobe SWF Investigator article for additional information:
- http://www.adobe.com/devnet/security/articles/inroducing-adobe-swf-investigator.html

*** Getting Started ***

Follow these steps to get started with SWF Investigator:

Read Introducing Adobe SWF Investigator in the Adobe Developer Connection:
- http://www.adobe.com/devnet/security/articles/inroducing-adobe-swf-investigator.html

Download the SWF Investigator preview:
- http://labs.adobe.com/downloads/swfinvestigator.html

Ask questions or share your feedback in the SWF Investigator forum:
- http://forums.adobe.com/community/labs/swfinvestigator/

Please note that your submission of comments, ideas, feature requests and techniques on this and other Adobe maintained forums, as well as Adobe's right to use such materials, is governed by the Adobe.com Terms of Use: - http://www.adobe.com/go/labs_term_of_use


*** Community ***

Below you'll find references and links to help you participate in the SWF Investigator community.

* Online Forum *

Ask questions and discuss ideas with other SWF Investigator users in the Labs forum.

Visit the SWF Investigator discussion forum:
- http://forums.adobe.com/community/labs/swfinvestigator/

Please note that your submission of comments, ideas, feature requests and techniques on this and other Adobe maintained forums, as well as Adobe's right to use such materials, is governed by the Adobe.com Terms of Use:
- http://www.adobe.com/go/labs_term_of_use

*** Adobe Developer Connection ***

Learn more about security topics in the Adobe Developer Connection.

Visit the Security Developer Center:
- http://www.adobe.com/devnet/security.html

Read the Introducing Adobe SWF Investigator article:
- http://www.adobe.com/devnet/security/articles/inroducing-adobe-swf-investigator.html

*** Resources ***

If you want to learn more about releases on Labs as well as other Adobe technologies, visiting a user group or connecting with an Adobe Community Professional is a great place to start.

Find a user group:
- http://www.adobe.com/cfusion/usergroups/

Find an Adobe Community Professional:
- http://www.adobe.com/communities/professionals/

*** Product Details ***

FAQ:
- http://labs.adobe.com/technologies/swfinvestigator/#FAQ

System Requirements:
- http://labs.adobe.com/technologies/swfinvestigator/#sysreqs

Release Notes:
- http://labs.adobe.com/technologies/swfinvestigator/#release_notes

=================================================


*** FAQ ***

What is SWF Investigator?
- Adobe SWF Investigator is a comprehensive, cross-platform, GUI-based set of tools, which enables quality engineers, developers and security researchers to quickly analyze SWF files to help ensure the quality and security of their applications.

What is the target audience for SWF Investigator?
- SWF Investigator was developed for quality engineers, developers and security researchers.

Can end-users/consumers use SWF Investigator?
- SWF Investigator is not a tool for end-users/consumers. The tool was developed specifically for quality engineers, developers and security researchers looking for a first-line tool to help them examine SWF files in an effort to improve the quality and security of their SWF applications.

Is SWF Investigator a proprietary or an open source tool?
- Yes. SWF Investigator is an open-source tool.

Which platforms are supported by SWF Investigator?
- SWF Investigator supports both Windows and Macintosh platforms.

See the system requirements:
- http://labs.adobe.com/technologies/swfinvestigator/#sysreqs

Does SWF Investigator eliminate the need for additional or separate tools currently being leveraged to improve the quality and security of SWF applications?
- No. SWF Investigator is a comprehensive, cross-platform, GUI-based set of tools, which enables quality engineers, developers and security researchers to quickly analyze SWF files to help ensure the quality and security of their applications. Depending on the results, a quality engineer, developer or security researcher may decide to use additional tools for further, more detailed analysis.

=================================================
*** System Requirements ***

Mac OS


-- Intel Core™ Duo 1.83GHz or faster processor
-- Mac OS X v10.6 or above
-- 512MB of RAM (1GB recommended)


Windows

-- Minimum: Intel® Pentium® III 1GHz or faster processor Recommended: Pentium 4 2GHz or faster
-- Microsoft® Windows® XP Home, Professional, or Tablet PC Edition with Service Pack 2 or 3 (including 64 bit editions), Windows Server® 2003, Windows Vista® Home Premium, Business, Ultimate, or Enterprise (including 64-bit editions) with Service Pack 1, or Windows 7 (including 64 bit editions)
-- 512MB of RAM (1GB recommended)


Linux (not mentioned on site, added by Anonymous)
-- Minimum: Try with WINE? Or, "screwed again!"
=================================================


** Release Notes **

The SWF Investigator beta is designed for evaluation purposes only. We do not recommended that this release be used on production systems or for any mission-critical work.

=================================================


*** Adobe Labs: ***

Home:
- http://labs.adobe.com/

Technologies:
- http://labs.adobe.com/technologies/

Wiki:
- http://labs.adobe.com/wiki/

Download:
- http://labs.adobe.com/downloads/

Community:
- http://labs.adobe.com/community/

Showcase:
- http://labs.adobe.com/showcase/

RSS Feeds:
- http://labs.adobe.com/rss_feeds/

Search:
- http://www.adobe.com/cfusion/labs/search.cfm

About:
- http://labs.adobe.com/about/

Copyright © 2012 Adobe Systems Incorporated. All rights reserved.
=================================================


Adobe provides tool for analysing Flash files
6 March 2012, 17:44


"Adobe SWF Investigator lets users take a look at the inner workings of Flash files. Whether a security expert wants to look into a Flash exploit or a developer wants to debug their own project, the tool collection can be used, among other things, to decompile SWF files in order to then examine the ActionScript source code.

It includes an XSS fuzzer to check files for cross-site scripting vulnerabilities (XSS) and a HEX editor to modify those files. SWF Investigator, built in Adobe Air, was developed by Peleus Uhley, a member of Adobe's security team.

SWF Investigator is available to download for Windows and Mac OS X.

- http://labs.adobe.com/downloads/swfinvestigator.html

The source code can also be downloaded:

- http://sourceforge.net/adobe/swfinvestigator/wiki/Home/

and is available under the Mozilla Public Licence 1.1 .":

- http://sourceforge.net/adobe/swfinvestigator/code/11/tree/trunk/MPL.txt

- http://labs.adobe.com/technologies/swfinvestigator/

SWF Inspector's main tool is a decompiler for ActionScript:
- http://www.h-online.com/security/ne...ing-Flash-files-1464864.html?view=zoom;zoom=1

- http://www.h-online.com/security/ne...s-tool-for-analysing-Flash-files-1464864.html

- http://h-online.com/-1464864

Copyright © 2012 Heise Media UK Ltd.
=================================================
The New Zealand Copyright Act 1994 specifies certain circumstances where all or a substantial part of a copyright work may be used without the copyright owner's permission. A "fair dealing" with copyright material does not infringe copyright if it is for the following purposes: research or private study; criticism or review; or reporting current events.
 

JEDIYoda

Lifer
Jul 13, 2005
33,981
3,318
126
March 6, 2012

### BREAKING NEWS ! ### ADOBE PRESENTS: ###

Adobe SWF Investigator

Perform quick, comprehensive, analysis of SWF applications

- http://labs.adobe.com/technologies/swfinvestigator/

Download and Discuss:
- http://labs.adobe.com/downloads/swfinvestigator.html
Discuss SWF Investigator:
- http://forums.adobe.com/community/labs/swfinvestigator/

Adobe® SWF Investigator is the only comprehensive, cross-platform, GUI-based set of tools, which enables quality engineers, developers and security researchers to quickly analyze SWF files to improve the quality and security of their applications. With SWF Investigator, you can perform both static and dynamic analysis of SWF applications with just one toolset. SWF Investigator lets you quickly inspect every aspect of a SWF file from viewing the individual bits all the way through to dynamically interacting with a running SWF.

*** SWF Investigator Features ***

From a static perspective, you can disassemble ActionScript 2 (AS2) and ActionScript 3 (AS3) SWFs, view SWF tags and make binary changes to SWF files. SWF Investigator also lets you view associated information, including local shared objects (LSOs) and per site settings.

From a dynamic perspective, you can call functions within the SWF, load the SWF in various contexts, communicate via local connections and send messages to Action Message Format (AMF) endpoints in order to test more effectively.

SWF Investigator contains an extensible fuzzer for SWF applications and AMF services, so you can search for common Web application attacks. This toolset also provides a variety of utilities including encoders and decoders for SWF data, as well as a basic compiler for testing small pieces of ActionScript code.

Additional Benefits

SWF Investigator is the only application of its kind that's built on Adobe AIR – a versatile runtime that supports ActionScript, the language used to create SWF applications. This allows for native interaction between the SWF Investigator and the SWF application. Using ActionScript also makes the source code of the tool more intuitive for SWF developers.

SWF Investigator has the ability to auto-update, so you don't need to worry about whether or not you have the most current version.

Since it's an open source AIR application, SWF Investigator can be modified to fit your environment, and it is cross-platform.

Read the Introducing Adobe SWF Investigator article for additional information:
- http://www.adobe.com/devnet/security/articles/inroducing-adobe-swf-investigator.html

*** Getting Started ***

Follow these steps to get started with SWF Investigator:

Read Introducing Adobe SWF Investigator in the Adobe Developer Connection:
- http://www.adobe.com/devnet/security/articles/inroducing-adobe-swf-investigator.html

Download the SWF Investigator preview:
- http://labs.adobe.com/downloads/swfinvestigator.html

Ask questions or share your feedback in the SWF Investigator forum:
- http://forums.adobe.com/community/labs/swfinvestigator/

Please note that your submission of comments, ideas, feature requests and techniques on this and other Adobe maintained forums, as well as Adobe's right to use such materials, is governed by the Adobe.com Terms of Use: - http://www.adobe.com/go/labs_term_of_use


*** Community ***

Below you'll find references and links to help you participate in the SWF Investigator community.

* Online Forum *

Ask questions and discuss ideas with other SWF Investigator users in the Labs forum.

Visit the SWF Investigator discussion forum:
- http://forums.adobe.com/community/labs/swfinvestigator/

Please note that your submission of comments, ideas, feature requests and techniques on this and other Adobe maintained forums, as well as Adobe's right to use such materials, is governed by the Adobe.com Terms of Use:
- http://www.adobe.com/go/labs_term_of_use

*** Adobe Developer Connection ***

Learn more about security topics in the Adobe Developer Connection.

Visit the Security Developer Center:
- http://www.adobe.com/devnet/security.html

Read the Introducing Adobe SWF Investigator article:
- http://www.adobe.com/devnet/security/articles/inroducing-adobe-swf-investigator.html

*** Resources ***

If you want to learn more about releases on Labs as well as other Adobe technologies, visiting a user group or connecting with an Adobe Community Professional is a great place to start.

Find a user group:
- http://www.adobe.com/cfusion/usergroups/

Find an Adobe Community Professional:
- http://www.adobe.com/communities/professionals/

*** Product Details ***

FAQ:
- http://labs.adobe.com/technologies/swfinvestigator/#FAQ

System Requirements:
- http://labs.adobe.com/technologies/swfinvestigator/#sysreqs

Release Notes:
- http://labs.adobe.com/technologies/swfinvestigator/#release_notes

=================================================


*** FAQ ***

What is SWF Investigator?
- Adobe SWF Investigator is a comprehensive, cross-platform, GUI-based set of tools, which enables quality engineers, developers and security researchers to quickly analyze SWF files to help ensure the quality and security of their applications.

What is the target audience for SWF Investigator?
- SWF Investigator was developed for quality engineers, developers and security researchers.

Can end-users/consumers use SWF Investigator?
- SWF Investigator is not a tool for end-users/consumers. The tool was developed specifically for quality engineers, developers and security researchers looking for a first-line tool to help them examine SWF files in an effort to improve the quality and security of their SWF applications.

Is SWF Investigator a proprietary or an open source tool?
- Yes. SWF Investigator is an open-source tool.

Which platforms are supported by SWF Investigator?
- SWF Investigator supports both Windows and Macintosh platforms.

See the system requirements:
- http://labs.adobe.com/technologies/swfinvestigator/#sysreqs

Does SWF Investigator eliminate the need for additional or separate tools currently being leveraged to improve the quality and security of SWF applications?
- No. SWF Investigator is a comprehensive, cross-platform, GUI-based set of tools, which enables quality engineers, developers and security researchers to quickly analyze SWF files to help ensure the quality and security of their applications. Depending on the results, a quality engineer, developer or security researcher may decide to use additional tools for further, more detailed analysis.

=================================================
*** System Requirements ***

Mac OS


-- Intel Core™ Duo 1.83GHz or faster processor
-- Mac OS X v10.6 or above
-- 512MB of RAM (1GB recommended)


Windows

-- Minimum: Intel® Pentium® III 1GHz or faster processor Recommended: Pentium 4 2GHz or faster
-- Microsoft® Windows® XP Home, Professional, or Tablet PC Edition with Service Pack 2 or 3 (including 64 bit editions), Windows Server® 2003, Windows Vista® Home Premium, Business, Ultimate, or Enterprise (including 64-bit editions) with Service Pack 1, or Windows 7 (including 64 bit editions)
-- 512MB of RAM (1GB recommended)


Linux (not mentioned on site, added by Anonymous)
-- Minimum: Try with WINE? Or, "screwed again!"
=================================================


** Release Notes **

The SWF Investigator beta is designed for evaluation purposes only. We do not recommended that this release be used on production systems or for any mission-critical work.

=================================================


*** Adobe Labs: ***

Home:
- http://labs.adobe.com/

Technologies:
- http://labs.adobe.com/technologies/

Wiki:
- http://labs.adobe.com/wiki/

Download:
- http://labs.adobe.com/downloads/

Community:
- http://labs.adobe.com/community/

Showcase:
- http://labs.adobe.com/showcase/

RSS Feeds:
- http://labs.adobe.com/rss_feeds/

Search:
- http://www.adobe.com/cfusion/labs/search.cfm

About:
- http://labs.adobe.com/about/

Copyright © 2012 Adobe Systems Incorporated. All rights reserved.
=================================================


Adobe provides tool for analysing Flash files
6 March 2012, 17:44


"Adobe SWF Investigator lets users take a look at the inner workings of Flash files. Whether a security expert wants to look into a Flash exploit or a developer wants to debug their own project, the tool collection can be used, among other things, to decompile SWF files in order to then examine the ActionScript source code.

It includes an XSS fuzzer to check files for cross-site scripting vulnerabilities (XSS) and a HEX editor to modify those files. SWF Investigator, built in Adobe Air, was developed by Peleus Uhley, a member of Adobe's security team.

SWF Investigator is available to download for Windows and Mac OS X.

- http://labs.adobe.com/downloads/swfinvestigator.html

The source code can also be downloaded:

- http://sourceforge.net/adobe/swfinvestigator/wiki/Home/

and is available under the Mozilla Public Licence 1.1 .":

- http://sourceforge.net/adobe/swfinvestigator/code/11/tree/trunk/MPL.txt

- http://labs.adobe.com/technologies/swfinvestigator/

SWF Inspector's main tool is a decompiler for ActionScript:
- http://www.h-online.com/security/ne...ing-Flash-files-1464864.html?view=zoom;zoom=1

- http://www.h-online.com/security/ne...s-tool-for-analysing-Flash-files-1464864.html

- http://h-online.com/-1464864

Copyright © 2012 Heise Media UK Ltd.
=================================================
The New Zealand Copyright Act 1994 specifies certain circumstances where all or a substantial part of a copyright work may be used without the copyright owner's permission. A "fair dealing" with copyright material does not infringe copyright if it is for the following purposes: research or private study; criticism or review; or reporting current events.

ummm..ok....so....