download
- Flash-Security.ppsMD5: F16C66D291117326A1E879330E573EE1
SHA1:F7BF76A396C1B5813AB82A954056E157E0327FF1 - FlashSecurityCrossdomain.zipMD5: 9CF7E4E2C40C2DB545281ACC80ADD5C2
SHA1:87AD01237149CAB09E2814FE63A3809AE08B4F4F
Flash Security
This presentation given at RIATalks, it's about fundamental flash security issues, attack surface of Flash and secure development.
During the presentation there was stealing data through vulnerable Crossdomain.xml files, you can download source code of this file - FlashSecurityCrossdomain.zip.
Last Updated : 31/10/2008 16:00:50
Related Applications
- BSQL brute forcer V2Updated version of the Blind SQL Injection Brute Forcer from www.514.es. Works against PostgreSQL, MySQL, MSSQL and Oracle and supports custom SQL Queries.
- BSQL HackerBSQL (Blind SQL) Hacker is an automated SQL Injection Framework / Tool designed to exploit SQL injection vulnerabilities virtually in any database.
- DoS Attacks Using SQL WildcardsThis paper discusses abusing Microsoft SQL Query wildcards to consume CPU in database servers. This can be achieved using only the search field present in most common web applications.
- hoppyHTTP options prober and information disclosure scanner
- How to Detect and Exploit 99% of XSS Vulnerabilities
- Insecure Trends in Web 2.0 Applications
- Web Application Password Reset Good Practice GuideOver the years of application testing we have seen many bad password reset implementations, so we have put together a good practice guide to help design a secure process for your applications
- XSS ShellXSS Shell is a powerful XSS backdoor, in XSS Shell one can interactively send requests and get responses from victim and it allows you to keep the control of session
- XSS TunnellingXSS Tunnelling is the tunnelling of HTTP traffic through an XSS Channel to use virtually any application that supports HTTP proxies. This paper explains the idea and the real world implementation.

