What is it

Flare processes an SWF and extracts all scripts from it. The output is written to a single text file. Only ActionScript is extracted, no text or images. Flare is freeware. Windows, Mac OS X and Linux versions are available.

The main purpose of decompiler is to help you recover your own lost source code. However, there are other uses, like finding out how a component works, or trying to understand poorly documented interface. Depending on where you live, some of them may be forbidden by law. It's your responsibility to make sure you don't break the law using Flare.

If you develop Flash applications for living, you probably know that your code is not secure in SWF. It's not the existence of decompiler that makes your code insecure though, it's design of SWF format. Although no ActionScipt is stored there, most of it can be recovered from bytecodes.

Download and usage

Most recent Flare version is 0.51.

Windows Explorer extension

Download flare05setup.exe. After installation right-click on any SWF file in Windows Explorer and choose Decompile from context menu. Flare will decompile somename.swf and store decomiled code in somename.flr in the same folder. somename.flr is a simple text file, you can open it with your favorite text editor. If Flare encounters problems during decompilation, it will display some warnings. If everything goes well, it will quit silently. That's all, Flare has no other GUI. To unistall, execute Start>Programs>Flare>Uninstall.

Command line versions

DOS/Windows binary:  flare05doswin.zip
Linux x86 binary:  flare05linux.tgz
Mac OS X binary:  flare05mac.tgz

There is no installation procedure for command line versions. Just create a folder named flare somewhere and unpack the archive there. To uninstall, delete the folder and you're done.

To use it, you have to open DOS window first (Windows). On Mac OS X, open terminal window: Applications/Utilities/Terminal. Now go to the Flare folder with cd c:\flare (windows)  or cd /flare (Mac/Linux), assuming you saved it here. Then call Flare with SWF path and name as only parameter: flare somepath\somename.swf (Windows) or ./flare somepath/somename.swf (Mac/Linux). There are no options. A text file named somename.flr will be created in SWF's folder, warnings (if any) will be shown to the console.

If you're unsure what Windows version to download, get Windows Explorer extension.

History

In July 2003 I had some thoughts about effective SWF obfuscation. Obfuscation may be the wrong word though, I mean something more complex than renaming variables — kind of scrambling. Anyway, I decided to write a decompiler first to find out what's really hard to decompile. Meanwhile I think scrambling is well possible. Flare is a side-effect of this work. I was going to release a commercial scrambler in 2004, but I've had enough work and not enough time. Now let's hope 2005 is a more realistic estimate. The scrambler will do more than just confuse Flare, which isn't that difficult. It will make decompiling SWFs mathematically hard. Other decompilers, even very good ones, will not be able to recover complex scripts at all.

Project state

Flare is alpha software. Please don't rely on Flare doing anything important — source control comes to mind. It may not format your hard drive, but it probably will crash on some SWFs or fail to decompile certain patterns. If you happen to find such a pattern, and the bug isn't listed below, please tell me about it. It would be nice if instead of sending me the SWF, you try to localize the bug yourself, and attach the FLA containing failed code only.

Albeit Flare will never be a full-featured GUI decompiler like ASV, it will continue to evolve in what it does. Expect better ActionScript II support, bug fixes and speed improvements. I may also decide to write a GUI wrapper for Flare. Since it's not my only project, development will take time though.

Bugs and missing features

Flare shows ActionScript I code even if source was ActionScript II. ActionScript II is mostly compiled to ActionScript I in SWF, with some additional instructions. There's no strong typing there, for example. While it would be possible to restore it, currently Flare can't do that.

while loops are shown instead of for loops. They are equivalent with one exception: continue statement. In the future I'll attempt to recover most for loops.

Multiple assignments a = b = c = 10; are shown as separate statements. Normally, it's not a problem. However, if used as loop condition, generated code may be incorrect.

You may be surprised by the code within catch clause of try/catch/finally block. Flash MX 2004 compiles typed exceptions to the code that actually checks the type of exception variable. Flare shows this code instead of restoring the more high-level original format.

Starting with Flash MX, movie clips may contain button event handlers. Flare incorrectly shows onClipEvent events instead of on events here. For buttons, correct event handlers are shown.

If left side of an assignment is calculated, Flare incorrectly uses eval. Since Flash MX, eval isn't allowed here, such assignment should be converted to set(var,val); form.

Flash 5 has no separate strict equality === or strict inequality !== operators, typeof is used instead. Flare will not recover them. Since switch statements depend on ===, Flash 5 switch can't be recovered.

In Flash 5 SWFs the condition of if statement may be reversed: (5>v) is shown instead of (v<5). It's not wrong, just unpleasant.

Flash MX 2004 optimizes certain branches away. Control flow recovery may be incomplete for edge cases.

Flare can't handle non-latin (russian, chinese) file names.

Non bugs

Flare can't make changes in SWF — it's not a compiler. Decompiler and compiler are completely different matters. To change an SWF, you may try Flasm or Kinetic Fusion.

No images, sounds or text are extracted — ActionScript only. I have no plans to add these in the near future.

There are no comments in SWF, they are compiled away. No decompiler can recover what's not there.

Flare doesn't work on earlier Mac OS versions. It only works on Mac OS X.

Flare may show equivalent code that looks different from original code and does the same. While I try to show the code in its original form, sometimes it's not possible. Before you submit a bug, please make sure the code is wrong.

Flare isn't well suited for simple cut'n'paste. In decompiled text file all frames, events and classes are shown together. To re-use it you have to know where the code belongs to.

Flare works best on code compiled in Flash. It's not always possible to decompile, say, hand-optimized code.

Flash MX 2004 will replace some local variables with registers. Names of these variables are not recoverable. Neither are the names changed by obfuscators.

Some Flash MX 2004 actions — extends or implements, for example, won't compile outside of classes. As long as Flare doesn't decompile to ActionScript II, there is no way to show them correctly.

Related software

Free

Flasm
Disassembler and assembler, maintained by yours truly. With Flasm, you can make changes to SWF. However, it doesn't show ActionScript — only bytecodes. If you're unfamiliar with them, it may be difficult to grasp. Free with source code.

KineticFusion
Free product, written in Java. SWF to XML and back, including ActionScript.

Commercial

All commercial decompilers extract images, sounds and text, not only ActionScript. I haven't made any tests regarding their quality. If you need one, try demo versions yourself.

Action Script Viewer
The first and probably the best decompiler for Windows. Somewhat costly.

Sothink SWF Decompiler

Imperator FLA
Claims to re-build most of the original FLA from SWF, including ActionScript.

DeFlash
Low-cost decompiler, handles SWFs up to Flash MX.

Gordon
Decompiler for Mac.

Terms of use

Copyright © 2003-2004  Igor Kogan.
All rights reserved.

Flare is copyrighted freeware. It costs nothing. Neither do I ask for donations. However, there are some restrictions on its usage. Flare is provided „as is“ and without any warranties. Please read the license included in the distribution for details. If you want to distribute Flare as part of commercial product, or need access to the source code, or do anything else which isn't covered by this license, please contact me for conditions.

Macromedia and Flash are registered trademarks of Macromedia, Inc.
Macromedia does not sponsor, affiliate, or endorse this product.

Enjoy

Igor Kogan


Last update:  30 September 2004 Logo