RE: NotLiteCode | Protect Sensitive Code Remotely! 09-15-2016, 05:19 PM
#3
(09-15-2016, 12:50 PM)hybris.softwares Wrote: Hello,
This is a pretty neat release, however i've found some things i would do in another way. I might do a push request later to github.
1) The AES_Encrypt and AES_Decrypt methods could be moved inside the sClient struct for 2 reasons : First you could initialize your aes engine one time per client and store it in a field to reduce overhead in initializing and disposing it.
2) You could avoid using MemoryStream by using :
3)You could use an enum backed by a byte to send headersCode:using(ICryptoTransform encryptor = AES.CreateEncryptor()) { encryptedBytes = encryptor.TransformFinalBlock(bytesToBeEncrypted, 0, bytesToBeEncrypted.Length); }
This way you could improve the packet structure.Code:enum Headers : byte { HEADER_CALL , HEADER_RETURN, HEADER_HANDSHAKE, HEADER_MOVE, }
Regards,
Hybris Softwares
Thanks for the response, as to 1: wouldn't that consume more RAM overhead as you would be storing an additional class for each client? As to 2: I really didnt take much time to look at the encryption, was just some cookie cutter I found on stack overflow, I'd like to get an AES GCM class in there but I'm not aware of how to do it without a third party lib. And for 3: That's what I was doing, however it had problems with that method as the bytes wernt serializing correctly, I plan to come back however and see if I can fix it.




![[+]](https://sinister.li/images/modern/collapse_collapsed.png)