RE: Re: Flash Obfuscation
"Brian Shura" <[email protected]>
| Newsgroups | gmane.comp.security.websecurity,gmane.comp.security.web-applications |
|---|---|
| Message-ID | <01f801cae8bc$6d519800$47f4c800$@net> |
Did your pentester tell you specifically what sensitive information was contained in the Flash content (such as security-critical logic that should be handled server-side, secret keys included in the ActionScript code that can be used to compromise the application, etc.), or did they just recommend that you to obfuscate the Flash content as a security best practice? If they gave you some specifics, then you may be better off changing the design of your application to address those issues with sensitive logic and/or information in your Flash code rather than pursuing the obfuscation route. I think it's possible to have a securely-designed application that makes heavy use of Flash without the need for obfuscating the Flash code. Thanks, Brian -----Original Message----- From: 0x4150 [mailto:[email protected]] Sent: Friday, April 30, 2010 2:00 PM To: Brad Causey Cc: Paul Melson; [email protected]; [email protected] Subject: [WEB SECURITY] Re: Flash Obfuscation My company had a pen test of the application and the tester reported that we should obfuscate the flash content. I would like to make it as difficult as possible for an attacker to reverse and understand the application logic. The application deals with sensitive data so I want to protect it (as much as possible). I was told there were ~3 products on the market which can obfuscate flash, but none seemed reputable. On Fri, Apr 30, 2010 at 6:58 AM, Brad Causey <[email protected]> wrote: > What's your goal? Maybe thatll help us help you. > > On 4/30/10, Paul Melson <[email protected]> wrote: >> On Thu, Apr 29, 2010 at 2:05 AM, 0x4150 <[email protected]> wrote: >>> Has anyone done obfuscation of a flash application? If so, what >>> tool(s) would you recommend? >> >> I wouldn't recommend any of them as a way to actually secure anything >> as the end result must still be a SWF file that Flash Player can parse >> correctly, and therefore they can be decompiled or debugged in order >> to reverse the code. >> >> The only example of obfuscated ActionScript that I've seen to date has >> been a malware dropper. In that case it was about 20 minutes by hand >> to reverse. About 1 minute for Wepawet to do the same. >> >> PaulM >> >> >> >> This list is sponsored by Cenzic >> -------------------------------------- >> Let Us Hack You. Before Hackers Do! >> It's Finally Here - The Cenzic Website HealthCheck. FREE. >> Request Yours Now! >> http://www.cenzic.com/2009HClaunch_Securityfocus >> -------------------------------------- >> >> > > -- > Sent from my mobile device > > -Brad Causey > CISSP, MCSE, C|EH, CIFI, CGSP > > http://www.owasp.org > -- > "Si vis pacem, para bellum" > -- > ---------------------------------------------------------------------------- Join us on IRC: irc.freenode.net #webappsec Have a question? Search The Web Security Mailing List Archives: http://www.webappsec.org/lists/websecurity/archive/ Subscribe via RSS: http://www.webappsec.org/rss/websecurity.rss [RSS Feed] Join WASC on LinkedIn http://www.linkedin.com/e/gis/83336/4B20E4374DBA ---------------------------------------------------------------------------- Join us on IRC: irc.freenode.net #webappsec Have a question? Search The Web Security Mailing List Archives: http://www.webappsec.org/lists/websecurity/archive/ Subscribe via RSS: http://www.webappsec.org/rss/websecurity.rss [RSS Feed] Join WASC on LinkedIn http://www.linkedin.com/e/gis/83336/4B20E4374DBA