Flashbang is an open-source Flash-security helper tool designed to extract and display flashVars from a SWF that is “naked” (i.e. not wrapped in a bigger application) so that security testers can begin analysis (e.g. for XSS or other vectors) without decompiling the whole SWF. It is built atop Mozilla’s Shumway project. It works in modern browsers via HTML/JS, can also be run locally, and does not upload SWFs to servers (processing stays local). It is still considered alpha quality. Clone the repo using the --recursive flag, so that all necessary submodules are cloned as well. Ideally, clone it into an Apache web-root (or any other web server). Prepare the environment for Shumway to work properly.

Features

  • Extracts flashVars from SWF files without requiring full decompilation
  • Runs in browser via Shumway (web-based environment)
  • Local installation support so one can run offline or self-hosted
  • Open tool (open source) under MPL-2.0 license
  • Does not upload user files—privacy preserved in that regard
  • Comes with a test set of SWFs (flash-files) including vulnerable examples, for experimentation and evaluation

Project Samples

Project Activity

See All Activity >

Categories

Security

License

Mozilla Public License 1.0 (MPL)

Follow Flashbang

Flashbang Web Site

Other Useful Business Software
MongoDB Atlas runs apps anywhere Icon
MongoDB Atlas runs apps anywhere

Deploy in 115+ regions with the modern database for every enterprise.

MongoDB Atlas gives you the freedom to build and run modern applications anywhere—across AWS, Azure, and Google Cloud. With global availability in over 115 regions, Atlas lets you deploy close to your users, meet compliance needs, and scale with confidence across any geography.
Start Free
Rate This Project
Login To Rate This Project

User Reviews

Be the first to post a review of Flashbang!

Additional Project Details

Programming Language

ActionScript

Related Categories

ActionScript Security Software

Registered

2025-09-23