I know a number of people who want to be Flashers. Also there are many people who would like to know how is to be working on this line. Here is my perspective:
What you need:
1. Know what Flash is about. You can only achieve excellence if you know what Flash can do and eventually try to push its limits. It's basically visual programming, an unique mixture between let's say C# and Paintbrush.
2. Love Flash. In my opinion, you are a Flasher if you are a good programmer with some aesthetic sense or a good animator. For programmers check this.
3. Know how to interface Flash with third party technologies (if a programmer). Flash by itself can do only so much: video/audio, games, animations, simulators, presentations and such. If you really want to get to the heavy stuff, you have to connect it to servers and make disseminated data reach people. Of course you can treat server-side as a black box, still I consider preferably to know some server side insides if you are to push those limits. No one else will do it as server guys don't really understand Flash that well. Flash has yet to make known its capacities, and here you come into place.
Saturday, March 10, 2007
Thursday, March 8, 2007
Applications possible with Flash
Too many people think Flash is for sites and slide shows. Here's a short list of things you can do using Flash and Flex. I should mention that everything here is capable of running in a browser or as a desktop application.
Multimedia CMSs
Video delivery: news, video sharing
Live data delivery
Stocks, secure financial data
Management
Project management
Accounting
Simulators
Device interfaces
Visual/Audio interfaces that you can use from PDAs to sea ships
Security systems
Remote recording, motion detection, face detection and recognition, complete user and administrator interface.
Virtual life systems
Social networks based on video, audio and text.
Games
Multiplayer
2D and software 3D
I'll add to this list in time and possibly add some links for every entry.
Multimedia CMSs
Video delivery: news, video sharing
Live data delivery
Stocks, secure financial data
Management
Project management
Accounting
Simulators
Device interfaces
Visual/Audio interfaces that you can use from PDAs to sea ships
Security systems
Remote recording, motion detection, face detection and recognition, complete user and administrator interface.
Virtual life systems
Social networks based on video, audio and text.
Games
Multiplayer
2D and software 3D
I'll add to this list in time and possibly add some links for every entry.
Sunday, March 4, 2007
Employees evaluation
Our company began a process of establishing an employee evaluation system on a trimester basis. I'll come back to it when it will be completed and tested, until then I'll just state my view.
Why?
Why does a company need this in the first place? Because you want to position and pay people right. In order to do that, you need a fair system that includes all important aspects to the company and eliminates most subjectiveness.
How?
I see the employment as a transaction. You give something to the company and you get something in return. Therefore an evaluation should point out how valuable you are to the company in the short and medium term. In other words, how much money your involvement brings.
Of course it's not that easy to calculate that and give a percent. Plus, people need some stability.
Large groups do that, cumulate individual dynamic energies and acts upon the median result.
Next, you have to figure out some criteria. Let's see how you can bring money:
1. Contributing to your current money maker project.
2. Contributing to the well being of the team. That means supporting other people and activities.
1. How to evaluate work? By the amount of effort you put in. Effort is Time x Complexity. Hence, our first two criteria.
What if you come up with an idea that saves resources and thus making the project more profitable? This is called Innovation, our third criteria.
2. What can you do to help your team work efficiently? Make the results of your work easy to use. Keep in mind that an easy to use product will save resources multiplied by the number of times involved. I'll name this Quality of work.
Most times you need to work together w/ the team to make individual parts work together. Therefore we have Availability. Sometimes the team needs working solutions and organizing. Let's call it Involvement.
Let's summarize:
Time
Complexity
Innovation
Quality of work
Availability
Involvement
What you can do with these? You can give them a mark for a period of time (several months). Next you have to think how important is every criteria in the great purpose of making money. The difference between the results of two salesmen on the same day can translate to several thousands work hours in production. Same with managers. A smart approach can make serious profits. If you go for a weighted average you need custom calculus for every position. Criteria above should be weighted differently.
Let's discuss similar positions.
We got Bill that works pretty standard and Dick that works twice as fast but only half the time. They should get equal pay right? Excluding the Availability criteria, the answer is yes. Thus Time & Complexity should mix together (Effort?). Let's consider normal time (marked with one unit) over normal complexity (also an unit). This should be the base for our future calculations. If someone works usually 1.2 complexity in the interest of the company, he should have 20% bigger paycheck.
Innovation. This one is tricky. One innovation can save 2 hours of normal work, another 2000. If we would be to calculate sums, we should add 2000 o the work of a person over a semester, we would have 1056+2000. He saved the work of two other team members! If you would have to get an average mark for the evaluation mark, the maximum weight for innovation should be twice that for the effort. With an usual value of zero, innovations are a rare thing.
Quality of work. A decent quality should be the norm. High quality that makes interconnecting and future modifications less costlier should be rewarded. If the usual amount of time for such operations is 15 percent of the work, doubling the speed should result in 7.5% economy. This would save 89.2 normal work hours for the six month period. Doesn't seem like much. More often we meet cases when sloppy work increases costs. The weight for this criteria should be no more than 0.14 if we admit a 10x reduction. Default value: 0
Availability
Seems similar to the previous. So let's say 0.15
Involvement
0.20 sounds good?
Of course, all numbers should be calculated, not chosen by feel. Varies from company to company, from position to position.
All this don't do much for the progress of a quality personnel. Someone brought the idea of goal, thus imprinting an attitude of continuous grow. People perform better when they know where they are and what they can do to get to the next step. It's at the core of the occidental civilization. So, you want a raise? Here's what you can do to get it. Those are also included in most evaluations forms, still being based on the criteria discussed.
Who's to make the evaluations? Technical performance can be evaluated by experts, the rest by the HR department using info from the employee him/herself and colleagues. Big responsibility ;) I heard of a case where soldered teams were almost dismantled by this. Not everyone is ready to accept that every person is entitled to an opinion and malevolent actions are a fact of life. You just have to make the best of the situation. An evaluation based on measurable results and large margins for eventual effects it is pretty much all that can be done. Add transparency and consent.
Why?
Why does a company need this in the first place? Because you want to position and pay people right. In order to do that, you need a fair system that includes all important aspects to the company and eliminates most subjectiveness.
How?
I see the employment as a transaction. You give something to the company and you get something in return. Therefore an evaluation should point out how valuable you are to the company in the short and medium term. In other words, how much money your involvement brings.
Of course it's not that easy to calculate that and give a percent. Plus, people need some stability.
Large groups do that, cumulate individual dynamic energies and acts upon the median result.
Next, you have to figure out some criteria. Let's see how you can bring money:
1. Contributing to your current money maker project.
2. Contributing to the well being of the team. That means supporting other people and activities.
1. How to evaluate work? By the amount of effort you put in. Effort is Time x Complexity. Hence, our first two criteria.
What if you come up with an idea that saves resources and thus making the project more profitable? This is called Innovation, our third criteria.
2. What can you do to help your team work efficiently? Make the results of your work easy to use. Keep in mind that an easy to use product will save resources multiplied by the number of times involved. I'll name this Quality of work.
Most times you need to work together w/ the team to make individual parts work together. Therefore we have Availability. Sometimes the team needs working solutions and organizing. Let's call it Involvement.
Let's summarize:
Time
Complexity
Innovation
Quality of work
Availability
Involvement
What you can do with these? You can give them a mark for a period of time (several months). Next you have to think how important is every criteria in the great purpose of making money. The difference between the results of two salesmen on the same day can translate to several thousands work hours in production. Same with managers. A smart approach can make serious profits. If you go for a weighted average you need custom calculus for every position. Criteria above should be weighted differently.
Let's discuss similar positions.
We got Bill that works pretty standard and Dick that works twice as fast but only half the time. They should get equal pay right? Excluding the Availability criteria, the answer is yes. Thus Time & Complexity should mix together (Effort?). Let's consider normal time (marked with one unit) over normal complexity (also an unit). This should be the base for our future calculations. If someone works usually 1.2 complexity in the interest of the company, he should have 20% bigger paycheck.
Innovation. This one is tricky. One innovation can save 2 hours of normal work, another 2000. If we would be to calculate sums, we should add 2000 o the work of a person over a semester, we would have 1056+2000. He saved the work of two other team members! If you would have to get an average mark for the evaluation mark, the maximum weight for innovation should be twice that for the effort. With an usual value of zero, innovations are a rare thing.
Quality of work. A decent quality should be the norm. High quality that makes interconnecting and future modifications less costlier should be rewarded. If the usual amount of time for such operations is 15 percent of the work, doubling the speed should result in 7.5% economy. This would save 89.2 normal work hours for the six month period. Doesn't seem like much. More often we meet cases when sloppy work increases costs. The weight for this criteria should be no more than 0.14 if we admit a 10x reduction. Default value: 0
Availability
Seems similar to the previous. So let's say 0.15
Involvement
0.20 sounds good?
Of course, all numbers should be calculated, not chosen by feel. Varies from company to company, from position to position.
All this don't do much for the progress of a quality personnel. Someone brought the idea of goal, thus imprinting an attitude of continuous grow. People perform better when they know where they are and what they can do to get to the next step. It's at the core of the occidental civilization. So, you want a raise? Here's what you can do to get it. Those are also included in most evaluations forms, still being based on the criteria discussed.
Who's to make the evaluations? Technical performance can be evaluated by experts, the rest by the HR department using info from the employee him/herself and colleagues. Big responsibility ;) I heard of a case where soldered teams were almost dismantled by this. Not everyone is ready to accept that every person is entitled to an opinion and malevolent actions are a fact of life. You just have to make the best of the situation. An evaluation based on measurable results and large margins for eventual effects it is pretty much all that can be done. Add transparency and consent.
Tuesday, February 27, 2007
Girls do flash
There aren't so many ladies in IT. There are even less female flashers. At least I don't know of any.
Romanians of our level of education are not misogynists, so I think the main reason why men cover almost 99% percent of the industry is the perception of IT, which is, "purely technical".
Yet we are fortunate enough to have two young Flash ladies in the immediate future. Because we train them. And I'm quite confident about them.
Now, why do I write about it only now? It struck me when I was looking for a partner, for a dance course I began today. After all my friends had to say no to me (either they can't meet the schedule, or I'm too ugly), I asked around the company w/o much hope. And guess what: I get myself a dance partner! And one that knows a bit of Flash! Awesome! I think you know what we're gonna talk about at the studio.
No, it's not Flash!
God, why is my blog read only by geeks?!?
Romanians of our level of education are not misogynists, so I think the main reason why men cover almost 99% percent of the industry is the perception of IT, which is, "purely technical".
Yet we are fortunate enough to have two young Flash ladies in the immediate future. Because we train them. And I'm quite confident about them.
Now, why do I write about it only now? It struck me when I was looking for a partner, for a dance course I began today. After all my friends had to say no to me (either they can't meet the schedule, or I'm too ugly), I asked around the company w/o much hope. And guess what: I get myself a dance partner! And one that knows a bit of Flash! Awesome! I think you know what we're gonna talk about at the studio.
No, it's not Flash!
God, why is my blog read only by geeks?!?
Sunday, February 25, 2007
Planning in Flash
Flash "industry" is plagued by poor programmers. Main causes:
1. Real programmers don't know what Flash is offering now (especially concerning ActionScript3).
2. Current "flashers" are mostly graphic designers forced to learn some AS in order to enhance their sites, presentations and eventually make simple games.
There are lots of awful practices like including code into the graphics file (.fla) and such only because Flash allows it. Flash was meant from the beginning to be easy on non programmers and thus permissive. Worse than Visual Basic.
One good practice used everywhere else but not so much in Flash is planning the application's technical architecture. What are the advantages of this?
1. You have a clear idea of what the app should do and how does it do it.
2. It's easier to scale and modify.
3. It generates all the code, leaving you to write only the code inside methods
4. Makes it easier for new programmers to join the team at a later point in development.
5. Easier to trace and debug.
Although at first it seems overkill, you'll soon see that it's a must for apps larger than 20 classes.
I personally prefer Visio for my diagrams (C# data models), but you can use any tool according to your style and needs. See a list here.
Check this for the things you need to have in your UML tool.
1. Real programmers don't know what Flash is offering now (especially concerning ActionScript3).
2. Current "flashers" are mostly graphic designers forced to learn some AS in order to enhance their sites, presentations and eventually make simple games.
There are lots of awful practices like including code into the graphics file (.fla) and such only because Flash allows it. Flash was meant from the beginning to be easy on non programmers and thus permissive. Worse than Visual Basic.
One good practice used everywhere else but not so much in Flash is planning the application's technical architecture. What are the advantages of this?
1. You have a clear idea of what the app should do and how does it do it.
2. It's easier to scale and modify.
3. It generates all the code, leaving you to write only the code inside methods
4. Makes it easier for new programmers to join the team at a later point in development.
5. Easier to trace and debug.
Although at first it seems overkill, you'll soon see that it's a must for apps larger than 20 classes.
I personally prefer Visio for my diagrams (C# data models), but you can use any tool according to your style and needs. See a list here.
Check this for the things you need to have in your UML tool.
Hacking in Flash. Part two
I'll discuss here hacking into socket apps. It doesn't really require Flash to do it, but the stakes are higher here, usually significant money are involved.
Hack 1: Get an account into the system
Vulnerability: Weak overall security model.
Method: Sniff the data passed on connection. Or adapt the hack described here for socket.
If the connection is not crypted and they usually are not, you can intercept everything on it. Just look for the tools to do that.
Protection against hack: There are various methods here:
1. Exchange credentials via https. Then use an authentication key for every future message. Unfortunately this alone is not sufficient as you will see on hack 2 bellow.
2. Use an encrypted connection. Flash Media Server supports this feature. I don't recommend implementing your own encryption, since the benefits are too small and security increase not that significant.
Hack 2: Hijack an existing connection
Vulnerability: Weak overall security model.
Method: You'll need to control a network node for this. Replace the original client (the client end of the connection) with your own.
Socket connections are not that continuous as they seem. The hijack won't be detected by both server and client unless some tricks are developed especially for this. The hijacker can be a half proxy, half illegitimate app. Can bypass basic checks like unique auth keys per message. You just have to decompile the original client and use the code sequence to encrypt the keys.
Protection against hack: SSH mixed with unique auth keys per message will make hacker's life so hard he will probably quit. Also implement intrusion detection for both client and server. Most probably the client will be completely blocked for paralel distress connections, the hacker simulating a network failure, but the server can implement a policy for this.
Hack 1: Get an account into the system
Vulnerability: Weak overall security model.
Method: Sniff the data passed on connection. Or adapt the hack described here for socket.
If the connection is not crypted and they usually are not, you can intercept everything on it. Just look for the tools to do that.
Protection against hack: There are various methods here:
1. Exchange credentials via https. Then use an authentication key for every future message. Unfortunately this alone is not sufficient as you will see on hack 2 bellow.
2. Use an encrypted connection. Flash Media Server supports this feature. I don't recommend implementing your own encryption, since the benefits are too small and security increase not that significant.
Hack 2: Hijack an existing connection
Vulnerability: Weak overall security model.
Method: You'll need to control a network node for this. Replace the original client (the client end of the connection) with your own.
Socket connections are not that continuous as they seem. The hijack won't be detected by both server and client unless some tricks are developed especially for this. The hijacker can be a half proxy, half illegitimate app. Can bypass basic checks like unique auth keys per message. You just have to decompile the original client and use the code sequence to encrypt the keys.
Protection against hack: SSH mixed with unique auth keys per message will make hacker's life so hard he will probably quit. Also implement intrusion detection for both client and server. Most probably the client will be completely blocked for paralel distress connections, the hacker simulating a network failure, but the server can implement a policy for this.
Sunday, February 18, 2007
Hacking in Flash. Part one
A lot of software companies develop Flash based applications w/ serious security issues.
This part will review hacking methods for server-side scripts, while the second will delve into socket methods.
Tools you need:
1. Data transfer sniffer.
This will help you discover the protocol used by communication. Browser sniffer (IE, FF), network sniffer, whatever works. I recommend to search one that will describe data structures used. Usually for GET and simple POST transfers you can manage w/o, but for AMF, it's better you have one.
2. Decompiler
This will allow you to see the AS code used by the original Flash component of the application. This will also help you get the protocol. In the course of hacking, you will replace the original Flash with your own or you can use them both side by side.
Hack 1: Get an account in the system
Vulnerability: Weak security model on the server.
Method: apply brute force to discover passwords. This can be used to simple HTML forms too (PHP, ASP, Perl, it doesn't matter).
You'll need some dictionary files for this and possibly a names file. This files usually store one value per line. Just search for some on the Internet. Then you need to find the data structure. For HTML forms, just read the HTML source code, use the decompiler for SWF files. Make an algorithm to cycle through names and passwords. Check the auth failure response and implement a test that will take notice of successful attempts. Show the right values in a textfield or use some other method to store them.
If you have a lot of time, make an algorithm that will compose passwords from ground up. 1, 2, 3, 4 letter combinations will run pretty quick, depending on your connection. For 5, 6 letters and more, expect to wait serveral hours, days, and so on :) Basic optimisation: first make only lower letters combinations. Then capital. Then numbers. Then lower and capital. Then lower and numbers. You get the idea.
Protection against hack: Simple. Just block the account for that IP, class or everything for 10 minutes after detection of 3 auth failures. This will make even 3 letter passwords very hard to catch. If you detect more than 3 auth in 3 seconds or more than 60 per hour, then block that IP for 1 month. Good job, mr. Programmer :)
Hack 2: Access data beyond your rightful area in apps where you already have an account. Trick timed tests. Forge scores in games.
Vulnerability: Weak security model on the server.
Method: determine the Flash part to deliver false data.
Step1. Because you need to be authenticated when you're making calls to the server, just authenticate w/ the original app and open a new tab in browser. Auth sessions are browser based and not tab/window based, therefore you can run operations from another tab and the server will see you as authenticated.
Step2. Send the fake data. For GET and simple POST you don't even need Flash. Now you can take 15 minutes tests in any time period you want, you can send scores to your liking. If the server delivers information by id, just use other ids than the ones offered to your account until you find what you need.
Protection against hack: Don't believe everything the client (Flash) says. If it's about time, make your own verifications. If it requests a resource, verify the client's right to that one.
I know systems where the client is requested to deliver user id, company id and such at each call. How stupid is that?
There are other methods of breaking into Flash apps, but those are not involving Flash directly so I won't go into them. Next we'll discuss hacking on Flash using sockets.
This part will review hacking methods for server-side scripts, while the second will delve into socket methods.
Tools you need:
1. Data transfer sniffer.
This will help you discover the protocol used by communication. Browser sniffer (IE, FF), network sniffer, whatever works. I recommend to search one that will describe data structures used. Usually for GET and simple POST transfers you can manage w/o, but for AMF, it's better you have one.
2. Decompiler
This will allow you to see the AS code used by the original Flash component of the application. This will also help you get the protocol. In the course of hacking, you will replace the original Flash with your own or you can use them both side by side.
Hack 1: Get an account in the system
Vulnerability: Weak security model on the server.
Method: apply brute force to discover passwords. This can be used to simple HTML forms too (PHP, ASP, Perl, it doesn't matter).
You'll need some dictionary files for this and possibly a names file. This files usually store one value per line. Just search for some on the Internet. Then you need to find the data structure. For HTML forms, just read the HTML source code, use the decompiler for SWF files. Make an algorithm to cycle through names and passwords. Check the auth failure response and implement a test that will take notice of successful attempts. Show the right values in a textfield or use some other method to store them.
If you have a lot of time, make an algorithm that will compose passwords from ground up. 1, 2, 3, 4 letter combinations will run pretty quick, depending on your connection. For 5, 6 letters and more, expect to wait serveral hours, days, and so on :) Basic optimisation: first make only lower letters combinations. Then capital. Then numbers. Then lower and capital. Then lower and numbers. You get the idea.
Protection against hack: Simple. Just block the account for that IP, class or everything for 10 minutes after detection of 3 auth failures. This will make even 3 letter passwords very hard to catch. If you detect more than 3 auth in 3 seconds or more than 60 per hour, then block that IP for 1 month. Good job, mr. Programmer :)
Hack 2: Access data beyond your rightful area in apps where you already have an account. Trick timed tests. Forge scores in games.
Vulnerability: Weak security model on the server.
Method: determine the Flash part to deliver false data.
Step1. Because you need to be authenticated when you're making calls to the server, just authenticate w/ the original app and open a new tab in browser. Auth sessions are browser based and not tab/window based, therefore you can run operations from another tab and the server will see you as authenticated.
Step2. Send the fake data. For GET and simple POST you don't even need Flash. Now you can take 15 minutes tests in any time period you want, you can send scores to your liking. If the server delivers information by id, just use other ids than the ones offered to your account until you find what you need.
Protection against hack: Don't believe everything the client (Flash) says. If it's about time, make your own verifications. If it requests a resource, verify the client's right to that one.
I know systems where the client is requested to deliver user id, company id and such at each call. How stupid is that?
There are other methods of breaking into Flash apps, but those are not involving Flash directly so I won't go into them. Next we'll discuss hacking on Flash using sockets.
Subscribe to:
Posts (Atom)