Virtual Event Today: CodeSecCon - Learn to Secure Your Software > Join Event
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Rapid7 Adds Dynamic Flash Analysis to NeXpose

Rapid7, a Boston-based provider of vulnerability management and penetration testing solutions, today announced that its NeXpose product now provides full Adobe® Flash decompilation and analysis support. With the new feature, Rapid7’s Web application scanning goes beyond basic Flash support with the ability to discover more vulnerabilities and improve intelligence in Flash analysis.

Rapid7, a Boston-based provider of vulnerability management and penetration testing solutions, today announced that its NeXpose product now provides full Adobe® Flash decompilation and analysis support. With the new feature, Rapid7’s Web application scanning goes beyond basic Flash support with the ability to discover more vulnerabilities and improve intelligence in Flash analysis.

Rapid 7 NetExposeAdobe’s Flash player has been an increasingly attractive target for malicious hackers, and while many vulnerability scanners do check Flash player security, most are unable to provide the deep inspection of Flash applications that run in the environment, leaving both clients and servers unprotected from many dangerous security issues, including remote hijacking, SQL injections and malicious SWF files.

Rapid7’s support for Web application Flash content enables NeXpose 4.10.4 users to conduct vulnerability scans that provide a deeper level of analysis on all websites and discover more vulnerabilities. This protects both the consumer of the website against XSS attacks, as well as the hosts of the website against other vulnerabilities. The new capability enables Rapid7 users to analyze Flash forms, which can uncover more potential injection points in the application, information disclosures and coding mistakes. For example, users can now find pages only linked from Flash menus, discover hard-coded credentials in Flash elements and analyze HTTP POST requests in Flash forms for injection vulnerabilities.

“As companies face increasing Web application attacks today, especially with Adobe Flash and its excessive risks, it has remained our goal to stay ahead and proactively offer a broad range of Web security best practices, including solutions for NeXpose and Metasploit,” said Mike Tuchen, president and CEO, Rapid7.

Written By

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Dali Rajic is joining OpenAI as Chief Revenue Officer.

Erika Dean has been appointed Chief Information Security Officer at Tricentis.

C1 has named Jeff St. Clair Chief Revenue Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.