Fly_flash 0.1 release 's

admin 2017年5月5日07:06:14评论339 views字数 844阅读2分48秒阅读模式
摘要

fly_flash — Jump/XSS/CSRF in FlashAuthor: [email protected]
Site: http://www.80sec.com
Date: 2009-8-26
From: http://www.80sec.com/release/fly_flash.txt
80SEC — know it then hack it !

fly_flash — Jump/XSS/CSRF in Flash

Author: [email protected]
Site: http://www.80sec.com
Date: 2009-8-26
From: http://www.80sec.com/release/fly_flash.txt
80SEC — know it then hack it !

[ description ]

fly_flash is a tool for penetration in flash

[ usage ]

upload fly_flash.swf and fly_flash.txt to your server in same directory, embed fly_flash.swf in other website, modify the fly_flash.txt first: <cmd>,<url>[,,,data]

cmd
0 — jump URL
1 — open window
2 — send GET Request
3 — send POST Request
4 — Call JavaScript

know it then hack it, but, do you know what’s allowNetworking/allowScriptAccess ?

[ example ]

jump to http://www.80sec.com
0,http://www.80sec.com

open window to http://www.80sec.com
1,http://www.80sec.com

send GET Request to 80sec.om
2,http://www.80sec.com/lake2/?hello

send POST Request to 80sec.om
3,http://www.80sec.com/lake2/?hello,,,str=knowitthenhackit

Call JavaScript
4,alert(/xss/)

[download]
http://www.80sec.com/release/fly_flash.rar

  • 左青龙
  • 微信扫一扫
  • weinxin
  • 右白虎
  • 微信扫一扫
  • weinxin
admin
  • 本文由 发表于 2017年5月5日07:06:14
  • 转载请保留本文链接(CN-SEC中文网:感谢原作者辛苦付出):
                   Fly_flash 0.1 release 'shttps://cn-sec.com/archives/44877.html

发表评论

匿名网友 填写信息