Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 42 guests online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Web Applicationsarrow How to decompile ActionScript v3 for free?
EH-Net
May 24, 2013, 03:24:55 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: How to decompile ActionScript v3 for free?  (Read 5769 times)
0 Members and 1 Guest are viewing this topic.
zelda
Newbie
*
Offline Offline

Posts: 8


View Profile
« on: July 26, 2011, 08:12:41 AM »

Hi guys!

Do you have any experiences with decompiling ActionScript v3 for free?

I have tried to do that with HP SWFScan (they are saying that it supports AS v3), but wasn’t successful. Commercial Sothink SWF Decompiler was able to do that, but not for free  Wink

Thanks for suggestions!

Regards,
zelda 
Logged
tturner
Sr. Member
****
Offline Offline

Posts: 432


View Profile WWW
« Reply #1 on: July 26, 2011, 09:37:22 AM »

I've used http://nowrap.de/flare.html in the past to good effect for v1 and v2, and while I have not touched it since my SEC542 class, the OWASP project SWFIntruder may be a good option as well. It's a run-time analysis tool designed for security.

https://www.owasp.org/index.php/Category:SWFIntruder
Logged

Certifications:
CISSP, CISA, GPEN, GWAPT, GAWN, GCIA, GCIH, GSEC, OPSE, CSWAE, CSTP, VCP

WIP: OSWP, GSSP-JAVA, GXPN

Udacity on hold, again. I suck.

http://sentinel24.com/blog  @tonylturner http://bsidesorlando.org
zelda
Newbie
*
Offline Offline

Posts: 8


View Profile
« Reply #2 on: July 27, 2011, 05:00:12 AM »

tturner,

thank you very much for your reply. Unfortunately neither flare or SWFintruter can't decompile SWF with ActionSript v3.

For now it seems that the only option to decompile ASv3 is to buy some commercial product.

zelda
Logged
tturner
Sr. Member
****
Offline Offline

Posts: 432


View Profile WWW
« Reply #3 on: July 27, 2011, 07:54:46 AM »

It's also possible that the HP tool is not working because protection mechanisms like http://www.dcomsoft.com/ http://www.kindi.com/swf-encryption.php http://www.amayeta.com/software/swfencrypt/ (as well as many other examples) have been used to prevent it.

There's no guarantee that commercial tools will help here if such methods have been employed.

You may find some other alternatives at http://www.swftools.com/tools-category.php?cat=759

I know one of my developers has used this site for some freeware utilities but I have no direct experience myself.
Logged

Certifications:
CISSP, CISA, GPEN, GWAPT, GAWN, GCIA, GCIH, GSEC, OPSE, CSWAE, CSTP, VCP

WIP: OSWP, GSSP-JAVA, GXPN

Udacity on hold, again. I suck.

http://sentinel24.com/blog  @tonylturner http://bsidesorlando.org
zelda
Newbie
*
Offline Offline

Posts: 8


View Profile
« Reply #4 on: July 27, 2011, 09:53:31 AM »

Thanks for the idea with obfuscation - it is definitely obfuscated! But Sothink Decompiler can do the job, while HP SWFScan can't Sad

Thanks for the link with alternatives. Still, every tool there, that can possibly do the job can't be used in commercial matter Sad

z.

Logged
tturner
Sr. Member
****
Offline Offline

Posts: 432


View Profile WWW
« Reply #5 on: July 27, 2011, 01:26:06 PM »

So did Sothink work for you? I'm curious because I may have to take a look at it for my own toolset.
Logged

Certifications:
CISSP, CISA, GPEN, GWAPT, GAWN, GCIA, GCIH, GSEC, OPSE, CSWAE, CSTP, VCP

WIP: OSWP, GSSP-JAVA, GXPN

Udacity on hold, again. I suck.

http://sentinel24.com/blog  @tonylturner http://bsidesorlando.org
zelda
Newbie
*
Offline Offline

Posts: 8


View Profile
« Reply #6 on: July 28, 2011, 02:09:20 AM »

Sothink worked even in trial version, but you can't export the code (due the trial).

Actually I wasn't able to decompile any ASv3 with HP SWFScan, flare or SWFIntruder, even sample SWF files from web - not obfuscated.

If any of you was successful in it, please let me know.

Thanks,
z.
Logged
tturner
Sr. Member
****
Offline Offline

Posts: 432


View Profile WWW
« Reply #7 on: July 28, 2011, 07:30:38 AM »

Yeah Flare does not support v3 at all. It's somewhat dated and has not been updated in awhile but it works great for v1 and v2. SwfIntruder is used for runtime analysis, I don't know that it will decompiler a swf but it will provide you much of the same information you'd be looking for in a decompiler with the added benefit of doing several security checks on the analyzed swf. It does support v3 as far as I know. I really don't understand why the HP tool would not work. Would you mind linking to the sample files you are discussing? I'm interested to see whats going on here.
Logged

Certifications:
CISSP, CISA, GPEN, GWAPT, GAWN, GCIA, GCIH, GSEC, OPSE, CSWAE, CSTP, VCP

WIP: OSWP, GSSP-JAVA, GXPN

Udacity on hold, again. I suck.

http://sentinel24.com/blog  @tonylturner http://bsidesorlando.org
zelda
Newbie
*
Offline Offline

Posts: 8


View Profile
« Reply #8 on: July 28, 2011, 08:33:08 AM »

I was wrong, sorry  Embarrassed

HP SWFScan can decompile ASv3 but not the one I need to test. Might be because of the obfuscation (?), I don't know.

I tried to obfuscate the ASv3 SWF that was OK with SWFScan before, but now the error showed up "Decompile operation failed".

When I'm trying to decompile the needed file, no error shows up. It just finds "nothing" in the file, except urls and AS version. No source code is found.

z.

Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.062 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.