List of issuesList of issues

#365 Search in memory: Filter fake SWFs
Author: user focus
Date created:
Type: feature
Visibility: Everybody
Assigned to: developer honfika
Labels: Tools
State: closed Help

Would be nice to have such functionality since many packers use fake SWFs tactics to prevent original SWF dumpink. Like in the attached SWF (packed with DoSWF).
Filtering fake SWFs was improved. Now only those "files" are shown which has at least one non zero length tag from the following list: Define*, DoABCDefineTag, DoABCTag, DoActionTag, DoInitActionTag, ShowFrameTag Now your file returns "only" 43 results. Is this enough?
State: new→upgraded
Assigned:developer honfika
Yep, looks much better now!
Could you write an unpack for doswf so I can unpack the binary symbol then, pack back to swf?
And write back to memory? I don't think that it is a good idea to write to another process's memory. If you want to save the swf to your hard drive, then you already can edit the doABC tags. (AVM2 instuctions)
FFDec already allows you to unpack doSWF - just dump both swfs (with code and library) from memory. Read more in my blog post:
I'll close this due to inactivity. Feel free to create a new issue when you find any problem.
State: upgraded→closed
Google Translate: Translate to Czech Translate to Slovak Translate to Russian Translate to Hungarian Translate to Swedish Translate to French Translate to German Translate to Spanish Translate to Italian
Change style: oceanic classic