Tool for analyzing and testing security of Flash applications

SWFIntruder is the first tool specifically developed for analyzing and testing security of Flash applications at runtime. It helps to find flaws in Flash applications using the methodology originally described by Stefano Di Paola in Testing Flash Applications and in Finding Vulnerabilities in Flash Applications.

SWFIntruder was developed using ActionScript, Html and JavaScript resulting in a tool taking advantage of the best features of those technologies in order to get the best capabilities for analysis and interaction with the testing Flash movies.

Features include:

  • Basic predefined attack patterns
  • Highly customizable attacks
  • Highly customizable undefined variables
  • Semi automated Xss check
  • User configurable internal parameters
  • Log Window for debugging and tracking
  • History of latest 5 tested SWF files
  • ActionScript Objects runtime explorer in tree view
  • Persistent Configuration and Layout



Share this