This presentation will discuss the prevalence of flash related vulnerabilities on the web today and the common misconceptions of the flash security model while showcasing two new tools that help explore the boundaries of the cross domain policy structure. I will also demonstrate an 0-day in a common Flash module and the remediation process to ensure your web application doesnt become part of the statistics.