Flashbang is an open-source Flash-security helper tool designed to extract and display flashVars from a SWF that is “naked” (i.e. not wrapped in a bigger application) so that security testers can begin analysis (e.g. for XSS or other vectors) without decompiling the whole SWF. It is built atop Mozilla’s Shumway project. It works in modern browsers via HTML/JS, can also be run locally, and does not upload SWFs to servers (processing stays local). It is still considered alpha quality. Clone the repo using the --recursive flag, so that all necessary submodules are cloned as well. Ideally, clone it into an Apache web-root (or any other web server). Prepare the environment for Shumway to work properly.

Features

  • Extracts flashVars from SWF files without requiring full decompilation
  • Runs in browser via Shumway (web-based environment)
  • Local installation support so one can run offline or self-hosted
  • Open tool (open source) under MPL-2.0 license
  • Does not upload user files—privacy preserved in that regard
  • Comes with a test set of SWFs (flash-files) including vulnerable examples, for experimentation and evaluation

Project Samples

Project Activity

See All Activity >

Categories

Security

License

Mozilla Public License 1.0 (MPL)

Follow Flashbang

Flashbang Web Site

Other Useful Business Software
Go From AI Idea to AI App Fast Icon
Go From AI Idea to AI App Fast

One platform to build, fine-tune, and deploy ML models. No MLOps team required.

Access Gemini 3 and 200+ models. Build chatbots, agents, or custom models with built-in monitoring and scaling.
Try Free
Rate This Project
Login To Rate This Project

User Reviews

Be the first to post a review of Flashbang!

Additional Project Details

Programming Language

ActionScript

Related Categories

ActionScript Security Software

Registered

2025-09-23