HP offers free security tool for Flash developers
HP is set to announce on Monday a free tool that developers can use to check for holes in the Flash applications they write, which can lead to data leaks and other security problems on Web sites.
HP SWFScan decompiles Flash applications and searches the code for vulnerabilities and violations of Adobe’s best security practices guideline. The tool works with all versions of Flash. Flash Player has been installed on more than 98% of Internet-connected computers globally. Flash applications are a popular target for attackers. HP analyzed nearly 4000 Web apps developed with the Flash platform and found that 35% violate Adobe’s security best practices.
Flash is traditionally used for creating animation and games and has been increasingly used for Web 2.0 apps destined for enterprise use, for which tighter measures are required.
While developers are striving to write more secure Flash apps, Adobe occasionally is forced to deal with security holds in the Flash Player itself. Adobe recently issued a patch for a hole in the player that could allow an attacker to remotely take control of a computer.


