Register for your free account! | Forgot your password?

Go Back   elitepvpers > Coders Den > AutoIt
You last visited: Today at 14:47

  • Please register to post and access all features, it's quick, easy and FREE!

Advertisement



Autoit Security

Discussion on Autoit Security within the AutoIt forum part of the Coders Den category.

Reply
 
Old   #1
 
elite*gold: 0
Join Date: Jul 2013
Posts: 2
Received Thanks: 0
Autoit Security

Hi all, my first post and i think this is the right place where ask this type of question, many expert here.
I'll do short:
Autoit security is a big lack, a compiled script, obfuscated but the internal scite ( or better *****? ) or not, can decompiled in a few second, with a couple of click by "automated" tools around the web.
I want to avoid that tools, i know the script will be never secure but at least if someone what to see the .exe it must be decompile it manually, so not for the first lamer

I have think to:
-Maybe change the header or something in the strucuture of the exe to make it unrecognized by this tools? I know the header can be rebuilded, but read up ( avoid the automated tools, not the hackers with knowledge )
-Or maybe obfuscate the AutoIt Stub?

Obviously, i can't do nothing by myself and i don't know where to start, if someone was so gentle to post a step-by-step i'm very gratefully.
Thanks
TDark is offline  
Old 07/08/2013, 02:09   #2
 
Shadow992's Avatar
 
elite*gold: 77
Join Date: May 2008
Posts: 5,430
Received Thanks: 5,878
Quote:
Originally Posted by TDark View Post
Hi all, my first post and i think this is the right place where ask this type of question, many expert here.
I'll do short:
Autoit security is a big lack, a compiled script, obfuscated but the internal scite ( or better Shite? ) or not, can decompiled in a few second, with a couple of click by "automated" tools around the web.
I want to avoid that tools, i know the script will be never secure but at least if someone what to see the .exe it must be decompile it manually, so not for the first lamer

I have think to:
-Maybe change the header or something in the strucuture of the exe to make it unrecognized by this tools? I know the header can be rebuilded, but read up ( avoid the automated tools, not the hackers with knowledge )
-Or maybe obfuscate the AutoIt Stub?

Obviously, i can't do nothing by myself and i don't know where to start, if someone was so gentle to post a step-by-step i'm very gratefully.
Thanks
Both will not prevent tools from decompiling.
Because decompilers are searching for the given start of the script and this is (normally) always the same key. You have to change the key in the .exe and in the script if you want to confuse these decompilers.
Thats also what i did:



But there are some memory dumping decompilers which are also able to decompile that way of making secure. You have to use my tool and some tool which disables memory dumping. You could also try to implement a function for this by yourself, would be possible. You need to use several Anti-Hacking-Strategies (like hackshields do).

So if you combine Safe.exe, some Hack-Shield-Strategies, an unofficial obfuscator and a program which secures your .exe, you did all what you are able to do.

My Obfuscator:


Something that is free and still secures your script a little bit (not that much but enough to make some decompilers getting confused):
Enigma Virtual Box (just google it its freeware)

So in a nutshell:
1. Use an unofficial Obfuscator (recommended but it can destroy codes)
2. Use Safe.exe
3. Get some possible Anti-Hacking-Scripts and implement them in AutoIt
4. Use Enigma Virtual Box
Shadow992 is offline  
Old 07/08/2013, 09:06   #3
 
YatoDev's Avatar
 
elite*gold: 50
Join Date: Sep 2012
Posts: 3,841
Received Thanks: 1,462
-Crypt some text in your script
-Return some script functions from a php script and execute() them
-Execute() some strings from a crypted.txt
-Checks your own .exe :
//check md5 with the crypt.au3
//checks if @compiled
-Run a little "hackshield" on startup (FileInstall) or create the .exe within runtime
-Use the new obfuscator on the scite website (or shadows)
-Mayby you can write your own compiler
-Use ressource hacker to delete the autoit signature
YatoDev is offline  
Old 07/08/2013, 23:27   #4
 
Shadow992's Avatar
 
elite*gold: 77
Join Date: May 2008
Posts: 5,430
Received Thanks: 5,878
Have a look at that:
Shadow992 is offline  
Old 07/10/2013, 11:49   #5
 
elite*gold: 0
Join Date: Jul 2013
Posts: 2
Received Thanks: 0
Thanks, i'm checking ( i was think was easier to protect an exe for the automatic tools )
For the last link, what is the correct procedure?
1) Compile a script without UPX
2) ???
TDark is offline  
Old 07/11/2013, 09:22   #6
 
Shadow992's Avatar
 
elite*gold: 77
Join Date: May 2008
Posts: 5,430
Received Thanks: 5,878
Download tool --> unpack it --> Start Protecter.exe or .au3 does not matter --> Select the files you want to select if you need help click the help button or ask in that thread what exactly seems strange to you. Use you created file but do not rename it! For more degails read thread.
Shadow992 is offline  
Old 07/11/2013, 17:04   #7


 
K1ramoX's Avatar
 
elite*gold: 26
Join Date: Jan 2012
Posts: 3,474
Received Thanks: 18,844
maybe the use of virtual machines can help or adding some junkcode in your executable ;o
K1ramoX is offline  
Reply




All times are GMT +1. The time now is 14:48.


Powered by vBulletin®
Copyright ©2000 - 2026, Jelsoft Enterprises Ltd.
SEO by vBSEO ©2011, Crawlability, Inc.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Support | Contact Us | FAQ | Advertising | Privacy Policy | Terms of Service | Abuse
Copyright ©2026 elitepvpers All Rights Reserved.