{"id":2548,"date":"2020-04-12T00:04:19","date_gmt":"2020-04-12T00:04:19","guid":{"rendered":"https:\/\/portasftpserver.com\/?p=2548"},"modified":"2021-02-04T16:12:14","modified_gmt":"2021-02-05T00:12:14","slug":"obfuscation-in-software-development","status":"publish","type":"post","link":"https:\/\/portasftpserver.com\/obfuscation-in-software-development\/","title":{"rendered":"Obfuscation Software Development in .NET"},"content":{"rendered":"\n<p class=\"sera-block-paragraph\">When you published your compiled application and thought that your ideas on how your build it can&#8217;t be stolen, then you made a big mistake. There are a lot of decompiler software out there like <a rel=\"noreferrer noopener\" href=\"https:\/\/discoverdot.net\/projects\/ilspy\" target=\"_blank\">ILSpy<\/a>, which use to convert machine code to how originally or close to it looks like before . <\/p>\n\n\n\n<p class=\"sera-block-paragraph\">Now, how to protect your code or intellectual property? Well that&#8217;s why I want to tackle &#8220;Obfuscation Software Development in .NET&#8221;. So, <a rel=\"noreferrer noopener\" href=\"https:\/\/en.wikipedia.org\/wiki\/Obfuscation\" target=\"_blank\">Obfuscation<\/a> is way of making the original message or computer functions to a very difficult to understand. In the following you can see a example how executable file can be decompiled using <a rel=\"noreferrer noopener\" href=\"https:\/\/discoverdot.net\/projects\/ilspy\" target=\"_blank\">ILspy<\/a>.<\/p>\n\n\n\n<p class=\"sera-block-paragraph\">This is a sample of how your code looks if its in executable format meaning it is a ready to be executed from the CPU. This is where all the encoded operation and reference to all DLL files that use in the applications. Don&#8217;t worry this not intended to be read, I just wanna show how it unpleasant in the eye.<\/p>\n\n\n\n<figure class=\"sera-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1004\" height=\"471\" src=\"https:\/\/portasftpserver.com\/sera-uploads\/2020\/04\/exec.jpg\" alt=\"\" class=\"sera-image-2556\" srcset=\"https:\/\/portasftpserver.com\/sera-uploads\/2020\/04\/exec.jpg 1004w, https:\/\/portasftpserver.com\/sera-uploads\/2020\/04\/exec-600x281.jpg 600w, https:\/\/portasftpserver.com\/sera-uploads\/2020\/04\/exec-585x274.jpg 585w, https:\/\/portasftpserver.com\/sera-uploads\/2020\/04\/exec-768x360.jpg 768w, https:\/\/portasftpserver.com\/sera-uploads\/2020\/04\/exec-100x47.jpg 100w\" sizes=\"auto, (max-width: 1004px) 100vw, 1004px\" \/><\/figure>\n\n\n\n<p class=\"sera-block-paragraph\">This is the &#8220;Hello World&#8221; console application program that will be become a executable file.<\/p>\n\n\n\n<figure class=\"sera-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"836\" height=\"381\" src=\"https:\/\/portasftpserver.com\/sera-uploads\/2020\/04\/consoleapp.jpg\" alt=\"\" class=\"sera-image-2567\" srcset=\"https:\/\/portasftpserver.com\/sera-uploads\/2020\/04\/consoleapp.jpg 836w, https:\/\/portasftpserver.com\/sera-uploads\/2020\/04\/consoleapp-600x273.jpg 600w, https:\/\/portasftpserver.com\/sera-uploads\/2020\/04\/consoleapp-585x267.jpg 585w, https:\/\/portasftpserver.com\/sera-uploads\/2020\/04\/consoleapp-768x350.jpg 768w, https:\/\/portasftpserver.com\/sera-uploads\/2020\/04\/consoleapp-100x46.jpg 100w\" sizes=\"auto, (max-width: 836px) 100vw, 836px\" \/><\/figure>\n\n\n\n<figure class=\"sera-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"788\" height=\"166\" src=\"https:\/\/portasftpserver.com\/sera-uploads\/2020\/04\/hello.jpg\" alt=\"\" class=\"sera-image-2561\" srcset=\"https:\/\/portasftpserver.com\/sera-uploads\/2020\/04\/hello.jpg 788w, https:\/\/portasftpserver.com\/sera-uploads\/2020\/04\/hello-600x126.jpg 600w, https:\/\/portasftpserver.com\/sera-uploads\/2020\/04\/hello-585x123.jpg 585w, https:\/\/portasftpserver.com\/sera-uploads\/2020\/04\/hello-768x162.jpg 768w, https:\/\/portasftpserver.com\/sera-uploads\/2020\/04\/hello-100x21.jpg 100w\" sizes=\"auto, (max-width: 788px) 100vw, 788px\" \/><\/figure>\n\n\n\n<p class=\"sera-block-paragraph\">Now let&#8217;s try to decompile it using ILSpy<\/p>\n\n\n\n<figure class=\"sera-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"880\" height=\"326\" src=\"https:\/\/portasftpserver.com\/sera-uploads\/2020\/04\/consoleDec.jpg\" alt=\"\" class=\"sera-image-2568\" srcset=\"https:\/\/portasftpserver.com\/sera-uploads\/2020\/04\/consoleDec.jpg 880w, https:\/\/portasftpserver.com\/sera-uploads\/2020\/04\/consoleDec-600x222.jpg 600w, https:\/\/portasftpserver.com\/sera-uploads\/2020\/04\/consoleDec-585x217.jpg 585w, https:\/\/portasftpserver.com\/sera-uploads\/2020\/04\/consoleDec-768x285.jpg 768w, https:\/\/portasftpserver.com\/sera-uploads\/2020\/04\/consoleDec-100x37.jpg 100w\" sizes=\"auto, (max-width: 880px) 100vw, 880px\" \/><\/figure>\n\n\n\n<p class=\"sera-block-paragraph\">As you can see above, the decoded is almost no difference with the original one. <\/p>\n\n\n\n<h2 class=\"sera-block-heading\">So, how to Obfuscate our code?<\/h2>\n\n\n\n<p class=\"sera-block-paragraph\">Here are the list of Obfuscation software in this <a rel=\"noreferrer noopener\" href=\"https:\/\/everipedia.org\/wiki\/lang_en\/List_of_obfuscators_for_.NET\" target=\"_blank\">link<\/a>. In my case since I am usng VS2019, I will Obfuscate my project using ConfuserEx. You can also install <a rel=\"noreferrer noopener\" href=\"https:\/\/marketplace.visualstudio.com\/items?itemName=AvinabMalla.ConfuserExforVisualStudio2017-18023\" target=\"_blank\">ConfuserEx from visual studio market place<\/a>.<\/p>\n\n\n\n<p class=\"sera-block-paragraph\">After you installing ConfuserEx in your visual studio, go to Tools-&gt; and enable it by selecting &#8220;Protect With ConfuserEx&#8221;. This will Obfuscate your code when building it in release mode.<\/p>\n\n\n\n<figure class=\"sera-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"868\" height=\"294\" src=\"https:\/\/portasftpserver.com\/sera-uploads\/2020\/04\/image.png\" alt=\"\" class=\"sera-image-2573\" srcset=\"https:\/\/portasftpserver.com\/sera-uploads\/2020\/04\/image.png 868w, https:\/\/portasftpserver.com\/sera-uploads\/2020\/04\/image-600x203.png 600w, https:\/\/portasftpserver.com\/sera-uploads\/2020\/04\/image-585x198.png 585w, https:\/\/portasftpserver.com\/sera-uploads\/2020\/04\/image-768x260.png 768w, https:\/\/portasftpserver.com\/sera-uploads\/2020\/04\/image-100x34.png 100w\" sizes=\"auto, (max-width: 868px) 100vw, 868px\" \/><\/figure>\n\n\n\n<p class=\"sera-block-paragraph\">Now let&#8217;s see how the Obfuscated code look like.<\/p>\n\n\n\n<figure class=\"sera-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1200\" height=\"533\" src=\"https:\/\/portasftpserver.com\/sera-uploads\/2020\/04\/consoleapp1-1200x533.jpg\" alt=\"\" class=\"sera-image-2577\" srcset=\"https:\/\/portasftpserver.com\/sera-uploads\/2020\/04\/consoleapp1-1200x533.jpg 1200w, https:\/\/portasftpserver.com\/sera-uploads\/2020\/04\/consoleapp1-600x267.jpg 600w, https:\/\/portasftpserver.com\/sera-uploads\/2020\/04\/consoleapp1-585x260.jpg 585w, https:\/\/portasftpserver.com\/sera-uploads\/2020\/04\/consoleapp1-768x341.jpg 768w, https:\/\/portasftpserver.com\/sera-uploads\/2020\/04\/consoleapp1-1536x683.jpg 1536w, https:\/\/portasftpserver.com\/sera-uploads\/2020\/04\/consoleapp1-100x44.jpg 100w, https:\/\/portasftpserver.com\/sera-uploads\/2020\/04\/consoleapp1.jpg 1708w\" sizes=\"auto, (max-width: 1200px) 100vw, 1200px\" \/><\/figure>\n\n\n\n<p class=\"sera-block-paragraph\">Now that our code has been Obfuscated. The ILSpy decompiler sees different output, which is too hard for human eye to understand. This is now more difficult and impossible to point out what is the program actually doing. <\/p>\n\n\n\n<p class=\"sera-block-paragraph\"><\/p>\n\n\n\n<h3 class=\"sera-block-heading\">That&#8217;s it!<\/h3>\n\n\n\n<p class=\"sera-block-paragraph\"><strong>Follow us for daily hack news<\/strong> \ud83d\ude42<\/p>\n\n\n\n<figure class=\"sera-block-embed-instagram sera-block-embed is-type-rich is-provider-instagram\"><div class=\"sera-block-embed__wrapper\">\n<blockquote class=\"instagram-media\" data-instgrm-captioned data-instgrm-permalink=\"https:\/\/www.instagram.com\/p\/B-rF5swArcw\/?utm_source=ig_embed&amp;utm_campaign=loading\" data-instgrm-version=\"12\" style=\" background:#FFF; border:0; border-radius:3px; box-shadow:0 0 1px 0 rgba(0,0,0,0.5),0 1px 10px 0 rgba(0,0,0,0.15); margin: 1px; max-width:658px; min-width:326px; padding:0; width:99.375%; width:-webkit-calc(100% - 2px); width:calc(100% - 2px);\"><div style=\"padding:16px;\"> <a href=\"https:\/\/www.instagram.com\/p\/B-rF5swArcw\/?utm_source=ig_embed&amp;utm_campaign=loading\" style=\" background:#FFFFFF; line-height:0; padding:0 0; text-align:center; text-decoration:none; width:100%;\" target=\"_blank\"> <div style=\" display: flex; flex-direction: row; align-items: center;\"> <div style=\"background-color: #F4F4F4; border-radius: 50%; flex-grow: 0; height: 40px; margin-right: 14px; width: 40px;\"><\/div> <div style=\"display: flex; flex-direction: column; flex-grow: 1; justify-content: center;\"> <div style=\" background-color: #F4F4F4; border-radius: 4px; flex-grow: 0; height: 14px; margin-bottom: 6px; width: 100px;\"><\/div> <div style=\" background-color: #F4F4F4; border-radius: 4px; flex-grow: 0; height: 14px; width: 60px;\"><\/div><\/div><\/div><div style=\"padding: 19% 0;\"><\/div> <div style=\"display:block; height:50px; margin:0 auto 12px; width:50px;\"><svg width=\"50px\" height=\"50px\" viewBox=\"0 0 60 60\" version=\"1.1\" xmlns=\"https:\/\/www.w3.org\/2000\/svg\" xmlns:xlink=\"https:\/\/www.w3.org\/1999\/xlink\"><g stroke=\"none\" stroke-width=\"1\" fill=\"none\" fill-rule=\"evenodd\"><g transform=\"translate(-511.000000, -20.000000)\" fill=\"#000000\"><g><path d=\"M556.869,30.41 C554.814,30.41 553.148,32.076 553.148,34.131 C553.148,36.186 554.814,37.852 556.869,37.852 C558.924,37.852 560.59,36.186 560.59,34.131 C560.59,32.076 558.924,30.41 556.869,30.41 M541,60.657 C535.114,60.657 530.342,55.887 530.342,50 C530.342,44.114 535.114,39.342 541,39.342 C546.887,39.342 551.658,44.114 551.658,50 C551.658,55.887 546.887,60.657 541,60.657 M541,33.886 C532.1,33.886 524.886,41.1 524.886,50 C524.886,58.899 532.1,66.113 541,66.113 C549.9,66.113 557.115,58.899 557.115,50 C557.115,41.1 549.9,33.886 541,33.886 M565.378,62.101 C565.244,65.022 564.756,66.606 564.346,67.663 C563.803,69.06 563.154,70.057 562.106,71.106 C561.058,72.155 560.06,72.803 558.662,73.347 C557.607,73.757 556.021,74.244 553.102,74.378 C549.944,74.521 548.997,74.552 541,74.552 C533.003,74.552 532.056,74.521 528.898,74.378 C525.979,74.244 524.393,73.757 523.338,73.347 C521.94,72.803 520.942,72.155 519.894,71.106 C518.846,70.057 518.197,69.06 517.654,67.663 C517.244,66.606 516.755,65.022 516.623,62.101 C516.479,58.943 516.448,57.996 516.448,50 C516.448,42.003 516.479,41.056 516.623,37.899 C516.755,34.978 517.244,33.391 517.654,32.338 C518.197,30.938 518.846,29.942 519.894,28.894 C520.942,27.846 521.94,27.196 523.338,26.654 C524.393,26.244 525.979,25.756 528.898,25.623 C532.057,25.479 533.004,25.448 541,25.448 C548.997,25.448 549.943,25.479 553.102,25.623 C556.021,25.756 557.607,26.244 558.662,26.654 C560.06,27.196 561.058,27.846 562.106,28.894 C563.154,29.942 563.803,30.938 564.346,32.338 C564.756,33.391 565.244,34.978 565.378,37.899 C565.522,41.056 565.552,42.003 565.552,50 C565.552,57.996 565.522,58.943 565.378,62.101 M570.82,37.631 C570.674,34.438 570.167,32.258 569.425,30.349 C568.659,28.377 567.633,26.702 565.965,25.035 C564.297,23.368 562.623,22.342 560.652,21.575 C558.743,20.834 556.562,20.326 553.369,20.18 C550.169,20.033 549.148,20 541,20 C532.853,20 531.831,20.033 528.631,20.18 C525.438,20.326 523.257,20.834 521.349,21.575 C519.376,22.342 517.703,23.368 516.035,25.035 C514.368,26.702 513.342,28.377 512.574,30.349 C511.834,32.258 511.326,34.438 511.181,37.631 C511.035,40.831 511,41.851 511,50 C511,58.147 511.035,59.17 511.181,62.369 C511.326,65.562 511.834,67.743 512.574,69.651 C513.342,71.625 514.368,73.296 516.035,74.965 C517.703,76.634 519.376,77.658 521.349,78.425 C523.257,79.167 525.438,79.673 528.631,79.82 C531.831,79.965 532.853,80.001 541,80.001 C549.148,80.001 550.169,79.965 553.369,79.82 C556.562,79.673 558.743,79.167 560.652,78.425 C562.623,77.658 564.297,76.634 565.965,74.965 C567.633,73.296 568.659,71.625 569.425,69.651 C570.167,67.743 570.674,65.562 570.82,62.369 C570.966,59.17 571,58.147 571,50 C571,41.851 570.966,40.831 570.82,37.631\"><\/path><\/g><\/g><\/g><\/svg><\/div><div style=\"padding-top: 8px;\"> <div style=\" color:#3897f0; font-family:Arial,sans-serif; font-size:14px; font-style:normal; font-weight:550; line-height:18px;\"> View this post on Instagram<\/div><\/div><div style=\"padding: 12.5% 0;\"><\/div> <div style=\"display: flex; flex-direction: row; margin-bottom: 14px; align-items: center;\"><div> <div style=\"background-color: #F4F4F4; border-radius: 50%; height: 12.5px; width: 12.5px; transform: translateX(0px) translateY(7px);\"><\/div> <div style=\"background-color: #F4F4F4; height: 12.5px; transform: rotate(-45deg) translateX(3px) translateY(1px); width: 12.5px; flex-grow: 0; margin-right: 14px; margin-left: 2px;\"><\/div> <div style=\"background-color: #F4F4F4; border-radius: 50%; height: 12.5px; width: 12.5px; transform: translateX(9px) translateY(-18px);\"><\/div><\/div><div style=\"margin-left: 8px;\"> <div style=\" background-color: #F4F4F4; border-radius: 50%; flex-grow: 0; height: 20px; width: 20px;\"><\/div> <div style=\" width: 0; height: 0; border-top: 2px solid transparent; border-left: 6px solid #f4f4f4; border-bottom: 2px solid transparent; transform: translateX(16px) translateY(-4px) rotate(30deg)\"><\/div><\/div><div style=\"margin-left: auto;\"> <div style=\" width: 0px; border-top: 8px solid #F4F4F4; border-right: 8px solid transparent; transform: translateY(16px);\"><\/div> <div style=\" background-color: #F4F4F4; flex-grow: 0; height: 12px; width: 16px; transform: translateY(-4px);\"><\/div> <div style=\" width: 0; height: 0; border-top: 8px solid #F4F4F4; border-left: 8px solid transparent; transform: translateY(-4px) translateX(8px);\"><\/div><\/div><\/div><\/a> <p style=\" margin:8px 0 0 0; padding:0 4px;\"> <a href=\"https:\/\/www.instagram.com\/p\/B-rF5swArcw\/?utm_source=ig_embed&amp;utm_campaign=loading\" style=\" color:#000; font-family:Arial,sans-serif; font-size:14px; font-style:normal; font-weight:normal; line-height:17px; text-decoration:none; word-wrap:break-word;\" target=\"_blank\">Zoom Caught in Cybersecurity Debate \u2014 Here&#39;s Everything You Need To Know https:\/\/thehackernews.com\/2020\/04\/zoom-cybersecurity-hacking.html<\/a><\/p> <p style=\" color:#c9c8cd; font-family:Arial,sans-serif; font-size:14px; line-height:17px; margin-bottom:0; margin-top:8px; overflow:hidden; padding:8px 0 7px; text-align:center; text-overflow:ellipsis; white-space:nowrap;\">A post shared by <a href=\"https:\/\/www.instagram.com\/cybersec_engineers_developers\/?utm_source=ig_embed&amp;utm_campaign=loading\" style=\" color:#c9c8cd; font-family:Arial,sans-serif; font-size:14px; font-style:normal; font-weight:normal; line-height:17px;\" target=\"_blank\"> CyberSec, Eng.&amp; Devs (Klivanion)<\/a> (@cybersec_engineers_developers) on <time style=\" font-family:Arial,sans-serif; font-size:14px; line-height:17px;\" datetime=\"2020-04-07T08:41:36+00:00\">Apr 7, 2020 at 1:41am PDT<\/time><\/p><\/div><\/blockquote><script async src=\"\/\/www.instagram.com\/embed.js\"><\/script>\n<\/div><\/figure>\n\n\n\n<h3 class=\"sera-block-heading\"><strong>Please share if you like this post.<\/strong><\/h3>\n","protected":false},"excerpt":{"rendered":"<p>When you published your compiled application and thought that your ideas on how your build it can&#8217;t be stolen, then you made a big mistake. There are a lot of decompiler software out there like ILSpy, which use to convert machine code to how originally or close to it looks like before . Now, how [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":2550,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-2548","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-programming-software"],"_links":{"self":[{"href":"https:\/\/portasftpserver.com\/sera-json\/wp\/v2\/posts\/2548","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/portasftpserver.com\/sera-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/portasftpserver.com\/sera-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/portasftpserver.com\/sera-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/portasftpserver.com\/sera-json\/wp\/v2\/comments?post=2548"}],"version-history":[{"count":0,"href":"https:\/\/portasftpserver.com\/sera-json\/wp\/v2\/posts\/2548\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/portasftpserver.com\/sera-json\/wp\/v2\/media\/2550"}],"wp:attachment":[{"href":"https:\/\/portasftpserver.com\/sera-json\/wp\/v2\/media?parent=2548"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/portasftpserver.com\/sera-json\/wp\/v2\/categories?post=2548"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/portasftpserver.com\/sera-json\/wp\/v2\/tags?post=2548"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}