Sinisterly
hacking the exe file - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Coding (https://sinister.li/Forum-Coding)
+--- Forum: Visual Basic & .NET Framework (https://sinister.li/Forum-Visual-Basic-NET-Framework)
+--- Thread: hacking the exe file (/Thread-hacking-the-exe-file)

Pages: 1 2 3 4


hacking the exe file - Shad0w Warr10r - 04-16-2013

Hi all,
I've a question about the security of a program. In case of using a registration password (e.g. "12345-67890") and storing this in my program, will it be save there? I mean, if I would write it like that:


Quote:Private Sub Form_Load()
RegPass = "12345-67890"
End Sub

Private Sub cmd_Click()
if txt.Text = RegPass then
'OK
Else
'...
End if
End Sub

Or is there a possiblity to hack the exe file and get the password?

Thanks and regards


hacking the exe file - Shad0w Warr10r - 04-16-2013

Hi all,
I've a question about the security of a program. In case of using a registration password (e.g. "12345-67890") and storing this in my program, will it be save there? I mean, if I would write it like that:


Quote:Private Sub Form_Load()
RegPass = "12345-67890"
End Sub

Private Sub cmd_Click()
if txt.Text = RegPass then
'OK
Else
'...
End if
End Sub

Or is there a possiblity to hack the exe file and get the password?

Thanks and regards


RE: hacking the exe file - Deque - 04-16-2013

If you hardcode the password like this, you can just view it using a hex editor.
Edit: You can use a hash instead, although this still won't prevent some reverse engineers to crack your program, it will make it harder than just opening a hex editor. You have to hash the user input and compare it with your own hash. Use a secure algorithm for that, i.e. scrypt.


RE: hacking the exe file - Deque - 04-16-2013

If you hardcode the password like this, you can just view it using a hex editor.
Edit: You can use a hash instead, although this still won't prevent some reverse engineers to crack your program, it will make it harder than just opening a hex editor. You have to hash the user input and compare it with your own hash. Use a secure algorithm for that, i.e. scrypt.


RE: hacking the exe file - Coder-san - 04-16-2013

Plain password protection can be cracked in VB in 3 ways:-
1) Ollydbg and bypass password prompt [Moderate]
2) Decompiling by .Net reflector, Dis#, etc. [Easy]
3) Simply viewing in a text-editor [Easy]

If you encrypt it then it can be done in 2 ways:-
1) Ollydbg and bypass password prompt [Moderate]
2) Decompiling by .Net reflector, Dis#, etc. [Easy]

If you obfuscate it then it can be done in 1 way:-
1) Ollydbg and bypass password prompt [Moderate]


RE: hacking the exe file - Coder-san - 04-16-2013

Plain password protection can be cracked in VB in 3 ways:-
1) Ollydbg and bypass password prompt [Moderate]
2) Decompiling by .Net reflector, Dis#, etc. [Easy]
3) Simply viewing in a text-editor [Easy]

If you encrypt it then it can be done in 2 ways:-
1) Ollydbg and bypass password prompt [Moderate]
2) Decompiling by .Net reflector, Dis#, etc. [Easy]

If you obfuscate it then it can be done in 1 way:-
1) Ollydbg and bypass password prompt [Moderate]


RE: hacking the exe file - ArkPhaze - 04-17-2013

Never do that, it's never secure and regardless of whether this is .NET or C/C++, it still wouldn't be secure. If you do this in .NET you're basically asking for someone to crack your program though. It would take me about 2 seconds (literally) to get that key.


RE: hacking the exe file - ArkPhaze - 04-17-2013

Never do that, it's never secure and regardless of whether this is .NET or C/C++, it still wouldn't be secure. If you do this in .NET you're basically asking for someone to crack your program though. It would take me about 2 seconds (literally) to get that key.


RE: hacking the exe file - Shad0w Warr10r - 04-17-2013

(04-16-2013, 03:08 PM)Coder-san Wrote: Plain password protection can be cracked in VB in 3 ways:-
1) Ollydbg and bypass password prompt [Moderate]
2) Decompiling by .Net reflector, Dis#, etc. [Easy]
3) Simply viewing in a text-editor [Easy]

If you encrypt it then it can be done in 2 ways:-
1) Ollydbg and bypass password prompt [Moderate]
2) Decompiling by .Net reflector, Dis#, etc. [Easy]

If you obfuscate it then it can be done in 1 way:-
1) Ollydbg and bypass password prompt [Moderate]

thanks

(04-16-2013, 03:04 PM)Deque Wrote: If you hardcode the password like this, you can just view it using a hex editor.
Edit: You can use a hash instead, although this still won't prevent some reverse engineers to crack your program, it will make it harder than just opening a hex editor. You have to hash the user input and compare it with your own hash. Use a secure algorithm for that, i.e. scrypt.

got it thanks for helping me.


RE: hacking the exe file - Shad0w Warr10r - 04-17-2013

(04-16-2013, 03:08 PM)Coder-san Wrote: Plain password protection can be cracked in VB in 3 ways:-
1) Ollydbg and bypass password prompt [Moderate]
2) Decompiling by .Net reflector, Dis#, etc. [Easy]
3) Simply viewing in a text-editor [Easy]

If you encrypt it then it can be done in 2 ways:-
1) Ollydbg and bypass password prompt [Moderate]
2) Decompiling by .Net reflector, Dis#, etc. [Easy]

If you obfuscate it then it can be done in 1 way:-
1) Ollydbg and bypass password prompt [Moderate]

thanks

(04-16-2013, 03:04 PM)Deque Wrote: If you hardcode the password like this, you can just view it using a hex editor.
Edit: You can use a hash instead, although this still won't prevent some reverse engineers to crack your program, it will make it harder than just opening a hex editor. You have to hash the user input and compare it with your own hash. Use a secure algorithm for that, i.e. scrypt.

got it thanks for helping me.