Advice needed! (.sw...
 
Notifications
Clear all

Advice needed! (.swf)

7 Posts
4 Users
0 Reactions
751 Views
(@csusama008)
Eminent Member
Joined: 17 years ago
Posts: 22
Topic starter  

Does anyone know/have any theories if a perp can hack into a pc using a 30KB flash file (with a .swf extension but it does not play in a player)? I have found all of the relevant data in this type of file - it's signature reports it as "unknown". WWYD (what would you do?) What "codes" contained within this file should I be on the look out for?

Thanks


   
Quote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

Does anyone know/have any theories if a perp can hack into a pc using a 30KB flash file (with a .swf extension but it does not play in a player)? I have found all of the relevant data in this type of file - it's signature reports it as "unknown". WWYD (what would you do?) What "codes" contained within this file should I be on the look out for?

A couple of things…

First, I'd look to see what the signature actually is…"unknown" doesn't help a great deal. Also, I'd look at what tool you're using.

As to any vulnerabilities that might be of use, there may be several, depending upon the OS in question. For example, if its Windows, I'd check out this blog
http//windowsir.blogspot.com/2009/02/looking-for-bad-stuff-part-i.html

HTH


   
ReplyQuote
jaclaz
(@jaclaz)
Illustrious Member
Joined: 18 years ago
Posts: 5133
 

Something you can quickly do is to see if TriD
http//mark0.net/soft-trid-e.html
identifies a given format.

jaclaz


   
ReplyQuote
(@csusama008)
Eminent Member
Joined: 17 years ago
Posts: 22
Topic starter  

Thanks! The OS is XP and http//mark0.net/onlinetrid.aspx says it is a Macromedia Flash Player Compressed Movie which just doesn't make sense with the data contained within the file.


   
ReplyQuote
(@bithead)
Noble Member
Joined: 20 years ago
Posts: 1206
 

Could this be of some use?
Hide and Seek in A. Flash

or this?
Spammed SWF URLs Abuse ImageShack, Lead to Rogue AV


   
ReplyQuote
(@csusama008)
Eminent Member
Joined: 17 years ago
Posts: 22
Topic starter  

Excellent find BitHead, I'm sure this type file was used by a remote hacker to execute information online from another user's pc. Now to find out more information in regards to the code written in this file. Any suggestions?


   
ReplyQuote
(@bithead)
Noble Member
Joined: 20 years ago
Posts: 1206
 

Excellent find BitHead, I'm sure this type file was used by a remote hacker to execute information online from another user's pc. Now to find out more information in regards to the code written in this file. Any suggestions?

Read THIS article at SANS on analyzing SWF file actions.


   
ReplyQuote
Share: