RE: Re: Flash Obfuscation

"Brian Shura" <[email protected]>
Newsgroups gmane.comp.security.websecurity,gmane.comp.security.web-applications
Message-ID <01f801cae8bc$6d519800$47f4c800$@net>
Did your pentester tell you specifically what sensitive information was contained in the Flash content (such as security-critical logic that should be handled server-side, secret keys included in the ActionScript code that can be used to compromise the application, etc.), or did they just recommend that you to obfuscate the Flash content as a security best practice?  If they gave you some specifics, then you may be better off changing the design of your application to address those issues with sensitive logic and/or information in your Flash code rather than pursuing the obfuscation route.  I think it's possible to have a securely-designed application that makes heavy use of Flash without the need for obfuscating the Flash code.

Thanks,
Brian

-----Original Message-----
From: 0x4150 [mailto:[email protected]] 
Sent: Friday, April 30, 2010 2:00 PM
To: Brad Causey
Cc: Paul Melson; [email protected]; [email protected]
Subject: [WEB SECURITY] Re: Flash Obfuscation

My company had a pen test of the application and the tester reported
that we should obfuscate the flash content. I would like to make it as
difficult as possible for an attacker to reverse and understand the
application logic. The application deals with sensitive data so I want
to protect it (as much as possible). I was told there were ~3 products
on the market which can obfuscate flash, but none seemed reputable.

On Fri, Apr 30, 2010 at 6:58 AM, Brad Causey <[email protected]> wrote:
> What's your goal? Maybe thatll help us help you.
>
> On 4/30/10, Paul Melson <[email protected]> wrote:
>> On Thu, Apr 29, 2010 at 2:05 AM, 0x4150 <[email protected]> wrote:
>>> Has anyone done obfuscation of a flash application? If so, what
>>> tool(s) would you recommend?
>>
>> I wouldn't recommend any of them as a way to actually secure anything
>> as the end result must still be a SWF file that Flash Player can parse
>> correctly, and therefore they can be decompiled or debugged in order
>> to reverse the code.
>>
>> The only example of obfuscated ActionScript that I've seen to date has
>> been a malware dropper. In that case it was about 20 minutes by hand
>> to reverse. About 1 minute for Wepawet to do the same.
>>
>> PaulM
>>
>>
>>
>> This list is sponsored by Cenzic
>> --------------------------------------
>> Let Us Hack You. Before Hackers Do!
>> It's Finally Here - The Cenzic Website HealthCheck. FREE.
>> Request Yours Now!
>> http://www.cenzic.com/2009HClaunch_Securityfocus
>> --------------------------------------
>>
>>
>
> --
> Sent from my mobile device
>
> -Brad Causey
> CISSP, MCSE, C|EH, CIFI, CGSP
>
> http://www.owasp.org
> --
> "Si vis pacem, para bellum"
> --
>

----------------------------------------------------------------------------
Join us on IRC: irc.freenode.net #webappsec

Have a question? Search The Web Security Mailing List Archives: 
http://www.webappsec.org/lists/websecurity/archive/

Subscribe via RSS: 
http://www.webappsec.org/rss/websecurity.rss [RSS Feed]

Join WASC on LinkedIn
http://www.linkedin.com/e/gis/83336/4B20E4374DBA


----------------------------------------------------------------------------
Join us on IRC: irc.freenode.net #webappsec

Have a question? Search The Web Security Mailing List Archives: 
http://www.webappsec.org/lists/websecurity/archive/

Subscribe via RSS: 
http://www.webappsec.org/rss/websecurity.rss [RSS Feed]

Join WASC on LinkedIn
http://www.linkedin.com/e/gis/83336/4B20E4374DBA
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.