Go Back   Exetools > General > General Discussion


Thread Tools Display Modes
Old 09-18-2004, 05:50
Posts: n/a
MS script decoder

I don't think I've ever seen this used for anything besides virus propagation, but there's a "feature" in IE that lets you encode your java script or vbscript so that someone casually browsing through your page source can't see what your scripts do. A while back I got an an amusing little malicious email that that tried to ues this trick to hide its real purpose, so I tracked down a few script decoders to see what it was really supposed to do (if I had been using Outlook + IE).

Anyway, to make a long story short
has a script decoder. But more importantly, he also wrote a detailed paper on how he reversed the encoding scheme without reversing the decoder built into IE. It's an interesting read on beginner crypto reversing that illustrates the thought process well, and also gives a good example of why "security through obscurity" is largely a stupid idea.

He also has a little Perl script that fetches and rips the latest dilbert cartoon as a GIF file from the official web page
Reply With Quote
Old 09-19-2004, 23:11
Posts: n/a
IMHO, "security through obscurity" is not such a stupid idea... Granted, it does not secure things that much... But it helps to keep honest people on the right side of the fence...

If i bury my gold in a field, anybody can take it, but i may hope to find it later... If i just leave it on the ground, there is almost no chance...

Now, that said, i must agree with the writter of this article regarding this script encoder... But anyway, the worse danger is, as always with security, to think you are protected.... As long as people are aware of that, i would recommend obscurity....
Reply With Quote
Old 10-08-2004, 11:09
Posts: n/a
you can use srcenc to encode source java code and then use escape to exchange the encoded code to double the obscurity.
like this
<script language="JavaScript" type="text/javascript">
Reply With Quote

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
[C++] ionCube 7 Decoder CryptXor Source Code 2 10-13-2015 13:56

All times are GMT +8. The time now is 07:24.

Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX
( 1998 - 2020 )