<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>gHacks technology news &#187; hp security</title>
	<atom:link href="http://www.ghacks.net/tag/hp-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ghacks.net</link>
	<description>A technology blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description>
	<lastBuildDate>Tue, 24 Nov 2009 23:31:44 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Adobe Flash Security Scan</title>
		<link>http://www.ghacks.net/2009/03/27/adobe-flash-security-scan/</link>
		<comments>http://www.ghacks.net/2009/03/27/adobe-flash-security-scan/#comments</comments>
		<pubDate>Fri, 27 Mar 2009 11:01:20 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[adobe flash]]></category>
		<category><![CDATA[adobe flash security]]></category>
		<category><![CDATA[flash]]></category>
		<category><![CDATA[flash security]]></category>
		<category><![CDATA[hp]]></category>
		<category><![CDATA[hp security]]></category>
		<category><![CDATA[hp software]]></category>
		<category><![CDATA[security-scan]]></category>
		<category><![CDATA[swf scan]]></category>
		<category><![CDATA[windows software]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/2009/03/27/adobe-flash-security-scan/</guid>
		<description><![CDATA[While Adobe Flash offers many exciting possibilities to web developers and users alike it also introduces several additional security risks to computer systems. We already discussed the impact of so called Flash Cookies which are able to track a user even if he deletes the normal cookies regularly across multiple web browsers. 
The HP Security [...]]]></description>
			<content:encoded><![CDATA[<p>While Adobe Flash offers many exciting possibilities to web developers and users alike it also introduces several additional security risks to computer systems. We already discussed the impact of so called <a href="http://www.ghacks.net/2008/07/30/delete-flash-cookies/">Flash Cookies</a> which are able to track a user even if he deletes the normal cookies regularly across multiple web browsers. </p>
<p>The HP Security Laboratory has created the application SWF Scan which can be used by both developers and end users to analyse Adobe Flash files for more than 60 vulnerabilities. Usage is pretty simple and straightforward although interpretation of the findings might require a deeper understanding of Adobe Flash or extensive research on the Internet. The application works with both local Adobe Flash files or those embedded in websites.</p>
<p>Users will first have to find out the direct url to the embedded flash file on the website. All web browser provide those capabilities. <a href="http://www.ghacks.net/tag/firefox/">Firefox</a> users for instance right-click the page and select Page Info from the context menu to get a list of objects that are embedded in the website. A click on the Media tab and a manual search for files of the type embed should be enough to find the url of the Adobe Flash file. A right-click on the flash object will open a menu with the option to copy the url to the clipboard.</p>
<p><span id="more-11491"></span><img src="http://www.ghacks.net/wp-content/uploads/2009/03/adobe_flash-500x245.jpg" alt="adobe flash" title="adobe flash" width="500" height="245" class="alignnone size-medium wp-image-11489" /></p>
<p>Once the url has been copied to the clipboard it can be pasted into the interface of the HP SWF Scan application. A click on the get button next to the url bar will initiate a connection attempt of the Adobe Flash security scanner. If the file is a valid Adobe Flash file it will automatically try to decompile it displaying the findings in the sidebar and the actual source in the right window.</p>
<p>A proficient Flash user can now analyze the code on his own. Everyone else is better of clicking on the Analyze button in the header of the security program. This will analyze the decompiled source code and provide a summary to the user.</p>
<p><img src="http://www.ghacks.net/wp-content/uploads/2009/03/hp_security-500x312.jpg" alt="hp security" title="hp security" width="500" height="312" class="alignnone size-medium wp-image-11490" /></p>
<p>The summary contains a list of vulnerabilities that have been found in the Adobe Flash file. This vulnerabilities mean that the Flash file might be vulnerable to certain exploits. Flash developers can then rewrite part of their application to fix the discovered vulnerabilities. End users on the other hand may be delighted to know that an Adobe Flash file does not contain any of the known vulnerabilities.</p>
<p>SWF Scan is a free <a href="https://h30406.www3.hp.com/campaigns/2009/wwcampaign/1-5TUVE/index.php?key=swf&#038;jumpid=go/swfscan">download</a> after a mandatory registration at the HP website. It is currently only available for the Microsoft Windows operating system.</p>

	Tags: <a href="http://www.ghacks.net/tag/adobe-flash/" title="adobe flash" rel="tag">adobe flash</a>, <a href="http://www.ghacks.net/tag/adobe-flash-security/" title="adobe flash security" rel="tag">adobe flash security</a>, <a href="http://www.ghacks.net/tag/flash/" title="flash" rel="tag">flash</a>, <a href="http://www.ghacks.net/tag/flash-security/" title="flash security" rel="tag">flash security</a>, <a href="http://www.ghacks.net/tag/hp/" title="hp" rel="tag">hp</a>, <a href="http://www.ghacks.net/tag/hp-security/" title="hp security" rel="tag">hp security</a>, <a href="http://www.ghacks.net/tag/hp-software/" title="hp software" rel="tag">hp software</a>, <a href="http://www.ghacks.net/tag/security-scan/" title="security-scan" rel="tag">security-scan</a>, <a href="http://www.ghacks.net/tag/swf-scan/" title="swf scan" rel="tag">swf scan</a>, <a href="http://www.ghacks.net/tag/windows-software/" title="windows software" rel="tag">windows software</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/09/04/mozilla-checks-flash-version-after-firefox-updates/" title="Mozilla Checks Flash Version After Firefox Updates (September 4, 2009)">Mozilla Checks Flash Version After Firefox Updates</a> (14)</li>
	<li><a href="http://www.ghacks.net/2008/05/28/vulnerabilities-in-latest-flash-version/" title="Vulnerabilities in latest Flash version (May 28, 2008)">Vulnerabilities in latest Flash version</a> (4)</li>
	<li><a href="http://www.ghacks.net/2008/05/29/new-information-about-latest-flash-vulnerability/" title="New Information about latest Flash Vulnerability (May 29, 2008)">New Information about latest Flash Vulnerability</a> (1)</li>
	<li><a href="http://www.ghacks.net/2009/09/19/mozilla-flash-upgrade-statistics/" title="Mozilla Flash Upgrade Statistics (September 19, 2009)">Mozilla Flash Upgrade Statistics</a> (5)</li>
	<li><a href="http://www.ghacks.net/2009/03/01/hp-usb-disk-storage-format-tool/" title="HP USB Disk Storage Format Tool (March 1, 2009)">HP USB Disk Storage Format Tool</a> (5)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2009/03/27/adobe-flash-security-scan/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
