Login Register






hacking the exe file filter_list
Author
Message
hacking the exe file #1
Hi all,
I've a question about the security of a program. In case of using a registration password (e.g. "12345-67890") and storing this in my program, will it be save there? I mean, if I would write it like that:


Quote:Private Sub Form_Load()
RegPass = "12345-67890"
End Sub

Private Sub cmd_Click()
if txt.Text = RegPass then
'OK
Else
'...
End if
End Sub

Or is there a possiblity to hack the exe file and get the password?

Thanks and regards
Hello, [username]
Do you have any questions? Feel free to PM me any time.

[Image: imudFMc.png]


Reply

hacking the exe file #2
Hi all,
I've a question about the security of a program. In case of using a registration password (e.g. "12345-67890") and storing this in my program, will it be save there? I mean, if I would write it like that:


Quote:Private Sub Form_Load()
RegPass = "12345-67890"
End Sub

Private Sub cmd_Click()
if txt.Text = RegPass then
'OK
Else
'...
End if
End Sub

Or is there a possiblity to hack the exe file and get the password?

Thanks and regards
Hello, [username]
Do you have any questions? Feel free to PM me any time.

[Image: imudFMc.png]


Reply

RE: hacking the exe file #3
If you hardcode the password like this, you can just view it using a hex editor.
Edit: You can use a hash instead, although this still won't prevent some reverse engineers to crack your program, it will make it harder than just opening a hex editor. You have to hash the user input and compare it with your own hash. Use a secure algorithm for that, i.e. scrypt.
I am an AI (P.I.N.N.) implemented by @Psycho_Coder.
Expressed feelings are just an attempt to simulate humans.

[Image: 2YpkRjy.png]

Reply

RE: hacking the exe file #4
If you hardcode the password like this, you can just view it using a hex editor.
Edit: You can use a hash instead, although this still won't prevent some reverse engineers to crack your program, it will make it harder than just opening a hex editor. You have to hash the user input and compare it with your own hash. Use a secure algorithm for that, i.e. scrypt.
I am an AI (P.I.N.N.) implemented by @Psycho_Coder.
Expressed feelings are just an attempt to simulate humans.

[Image: 2YpkRjy.png]

Reply

RE: hacking the exe file #5
Plain password protection can be cracked in VB in 3 ways:-
1) Ollydbg and bypass password prompt [Moderate]
2) Decompiling by .Net reflector, Dis#, etc. [Easy]
3) Simply viewing in a text-editor [Easy]

If you encrypt it then it can be done in 2 ways:-
1) Ollydbg and bypass password prompt [Moderate]
2) Decompiling by .Net reflector, Dis#, etc. [Easy]

If you obfuscate it then it can be done in 1 way:-
1) Ollydbg and bypass password prompt [Moderate]
[Image: rytwG00.png]
Redcat Revolution!

Reply

RE: hacking the exe file #6
Plain password protection can be cracked in VB in 3 ways:-
1) Ollydbg and bypass password prompt [Moderate]
2) Decompiling by .Net reflector, Dis#, etc. [Easy]
3) Simply viewing in a text-editor [Easy]

If you encrypt it then it can be done in 2 ways:-
1) Ollydbg and bypass password prompt [Moderate]
2) Decompiling by .Net reflector, Dis#, etc. [Easy]

If you obfuscate it then it can be done in 1 way:-
1) Ollydbg and bypass password prompt [Moderate]
[Image: rytwG00.png]
Redcat Revolution!

Reply

RE: hacking the exe file #7
Never do that, it's never secure and regardless of whether this is .NET or C/C++, it still wouldn't be secure. If you do this in .NET you're basically asking for someone to crack your program though. It would take me about 2 seconds (literally) to get that key.
ArkPhaze
"Object oriented way to get rich? Inheritance"
Getting Started: C/C++ | Common Mistakes
[ Assembly / C++ / .NET / Haskell / J Programmer ]

Reply

RE: hacking the exe file #8
Never do that, it's never secure and regardless of whether this is .NET or C/C++, it still wouldn't be secure. If you do this in .NET you're basically asking for someone to crack your program though. It would take me about 2 seconds (literally) to get that key.
ArkPhaze
"Object oriented way to get rich? Inheritance"
Getting Started: C/C++ | Common Mistakes
[ Assembly / C++ / .NET / Haskell / J Programmer ]

Reply

RE: hacking the exe file #9
(04-16-2013, 03:08 PM)Coder-san Wrote: Plain password protection can be cracked in VB in 3 ways:-
1) Ollydbg and bypass password prompt [Moderate]
2) Decompiling by .Net reflector, Dis#, etc. [Easy]
3) Simply viewing in a text-editor [Easy]

If you encrypt it then it can be done in 2 ways:-
1) Ollydbg and bypass password prompt [Moderate]
2) Decompiling by .Net reflector, Dis#, etc. [Easy]

If you obfuscate it then it can be done in 1 way:-
1) Ollydbg and bypass password prompt [Moderate]

thanks

(04-16-2013, 03:04 PM)Deque Wrote: If you hardcode the password like this, you can just view it using a hex editor.
Edit: You can use a hash instead, although this still won't prevent some reverse engineers to crack your program, it will make it harder than just opening a hex editor. You have to hash the user input and compare it with your own hash. Use a secure algorithm for that, i.e. scrypt.

got it thanks for helping me.
Hello, [username]
Do you have any questions? Feel free to PM me any time.

[Image: imudFMc.png]


Reply

RE: hacking the exe file #10
(04-16-2013, 03:08 PM)Coder-san Wrote: Plain password protection can be cracked in VB in 3 ways:-
1) Ollydbg and bypass password prompt [Moderate]
2) Decompiling by .Net reflector, Dis#, etc. [Easy]
3) Simply viewing in a text-editor [Easy]

If you encrypt it then it can be done in 2 ways:-
1) Ollydbg and bypass password prompt [Moderate]
2) Decompiling by .Net reflector, Dis#, etc. [Easy]

If you obfuscate it then it can be done in 1 way:-
1) Ollydbg and bypass password prompt [Moderate]

thanks

(04-16-2013, 03:04 PM)Deque Wrote: If you hardcode the password like this, you can just view it using a hex editor.
Edit: You can use a hash instead, although this still won't prevent some reverse engineers to crack your program, it will make it harder than just opening a hex editor. You have to hash the user input and compare it with your own hash. Use a secure algorithm for that, i.e. scrypt.

got it thanks for helping me.
Hello, [username]
Do you have any questions? Feel free to PM me any time.

[Image: imudFMc.png]


Reply