Plateforme Level Extreme
Abonnement
Profil corporatif
Produits & Services
Support
Légal
English
VFP Encryption Library from Craig Boyd
Message
De
01/05/2006 14:38:08
 
 
À
20/04/2006 02:08:03
Information générale
Forum:
Visual FoxPro
Catégorie:
Produits tierce partie
Divers
Thread ID:
01114853
Message ID:
01118126
Vues:
35
Jos:

A thousand pardons for butting in but you raise a good point with regards to VFP and any encryption routine that requries passwords, encryption strings, etc. VFP is so blazingly easy to decompile that even without resorting to substituting a DLL, or FLL, a hacker could figure out the password. I started using MoleBox to encrypt the executable, and DLLs, in order to get around this vulnerability. An added benefit was getting rid of component registration issues and the whole package shrank in size by about 60%.

Sorry for the interruption,

Scott

>Hi Craig
>
>iro your VFP encryption library - because one needs to pass the password to the encryption/decryption routines would an attacker not find it quite easy to substiute their own dll/fll for yours and then intercept the password when the routines get called? Is this a possibility for attack? If so, is there a way around this perhaps by setting up the password in the main app and the dll/fll looking for it under a static variable name or something like that? Or do you feel this an unlikely scenario?
>
>Thanks.
Scott Ramey
BDS Software
Précédent
Suivant
Répondre
Fil
Voir

Click here to load this message in the networking platform