SecurityTubeBeta
Watch ... Learn ... Contribute
securitytube home
programming videos
tools videos
basics videos
fun
divider
upload video on SecurityTube

Bypassing Flash Logins using Flasm

 
 

Flasm is a free command line assembler/disassembler of Flash ActionScript bytecode. It lets you make changes to any SWF. Flasm fully supports SWFs produced by Macromedia Flash 8 and earlier Flash versions. You can download Flasm from their website.

In this video, we see a demo of how to disassemble a Flash file using Flasm. In this specific example, the developer has made the mistake of embedding credentials in the flash swf and doing local authentication. What most developers don't realize is that flash binaries can be easily disassembled, and any strings embedded in them can be easily seen.




 

We hate these ADs as much as you do! Help us stay FREE and CLEAN by making a Generous Donation!

 
Related Videos from: Exploit Demos (15)
divider
You are Viewing this Video Now!
1456 views
2713 views
2756 views

Author
Vivek-Ramachandran

Vivek Ramachandran is a security evangelist and has been working in computer security related fields for the past 7 years. In 2007, Vivek spoke at world renowned conferences Defcon (WEP Cloaking Exposed) and Toorcon (The Caffe Latte Attack). The discovery of the Caffe Latte Attack was covered by CBS5 news, BBC online, Network World etc news agencies.In 2006, Vivek was announced as one of winners of the Microsoft Security Shootout contest held in India among 65,000 participants. He has also been a recipient of a Team Achievement at Cisco Systems for his work on 802.1x and Port Security modules on the Catalyst 6500 switches. Currently he spends all of his time maintaining Security- Freak.Net , SecurityTube.Net and is the co-founder of Axonize. Vivek, is a Bachelor in Electronics and Communications Engineering from the prestigious Indian Institute of Technology, Guwahati.You can contact him at vivek[at]securitytube.net

 
©2007 Freak Labs