Giter Club home page Giter Club logo

flashbang's People

Contributors

cure53 avatar flabbergastedbd avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

flashbang's Issues

Hello yes

it told me to report a bug in the thing, i tried to run the first Achievement Unlocked in the thing and it popped up with an error. idk why it did that, but it did. pls fix

Plan first API pattern for Flashbang

Flashbang will need a rough outline for a first API. Something like:

Flashbang.load()
Flashbang.scan()
Flashbang.info()
Flashbang.close()

We need to think who this could look like and what we want to do in the early alpha.

Replicate all flashVars as get parameters in the url

This is to ensure that if swf tries to parse parameters from url our flashVars still work. Detection of flashVars is complex in this case though.

loaderInfo._url has to be tampered : Help

P.S: Think of something for detection, may be we can proxy the calls of _url

Collect vulnerable Flash files

We need an overall of ten to fifteen vulnerable (to XSS) Flash files to show them to the Shumway team. Ideally we have them in a folder - each embedded in HTML with a button to trigger the vulnerability.

We need bugs that exploit vulnerabilities in as many different Flash/AS methods as possible. Further, some of the bugs should be requiring user interaction to be exploited, others should be exploitable without user interaction.

This step is important before we re-connect with the Shumway team. They basically will use this input to understand, what APIs we would need.

UI / UX Enhancements before launch

We need the following enhancements to make Flashbang be more usable:

  • Communicate that currently only Chrome works well
  • Add a "close SWF" button
  • Add a "rerun analysis" button
  • Add a spinner / progress indicator
  • Implement a console.log that logs into a <textarea>

Extract all FlashVars for a given swf

  • Using shumway, all the FlashVars for a given flash file have to be collected

If some extra information about variables is available during this stage, which can be leveraged to guess the type of variables then it will be useful

Create bitmap mock-up for posible Flashbang UI

We need to think what features we would like to present - and how a very early UI could look like. All Flashbang features should be available as API, the early UI draft should respect this.

[UI] Trace terminal

  • Inability to scroll horizontally incase of long lines of text in trace terminal
  • If possible one raw version and one interpreted version of the data ending up in sinks

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.