Skip to main content
GameDev.net gamedev.net
🔒 Locked

[.net] protecting our application on .NET

Started by afsajghfd Apr 2, 2009 at 10:36 AM 23 replies 5.2k views
Original Post
afsajghfd
afsajghfd
Hi, as you all should know, every software created on Visual Studio .NET are vulnerable to be decompiled at source code[1] level, even with name functions and variables given by programmers. Now, let's forget about obfuscators (even they seems are not the answer to the problem). How would we protect our software from crackers, if even the most powerful encryption algoritm for serials&keys will fall by viewing his source code? So, I'm trying to attach a little program to the aplication, then when the user start it, the software will check in a server on internet if it's a valid copy. If the program detected that it's not a valid copy, I will set the run boolean variable to false, so the program will not start. As you can imagine, if a cracker can see the source code, it may be trivial to him bypass the check and set always the run variable to true with a hexadecimal editor. What would be the best way of getting some protection ? Any comment will be appreciated. Saludos [1]http://www.remotesoft.com/salamander/index.html [Edited by - afsajghfd on April 7, 2009 1:22:57 PM]
Wan
Wan
Quote:
Original post by afsajghfd
Hi, as you all should know, every software created on Visual Studio .NET are vulnerable to be decompiled

Or any other compiler for that matter.
Quote:
Original post by afsajghfd
it may be trivial to him bypass the check and set always the run variable to true with a hexadecimal editor.

Yep, that's pretty trivial to crack if you really wanted to. You probably don't even have to reverse engineer it: change your host file and have the domain point to a local web server which will return 'true' with every request.

The question is, why is it so important to protect your application form these kind of 'attacks'?
afsajghfd
afsajghfd
Seeing c# (code with pretty nice name functions) than seeing asm has no comparation

Because why someone would buy something that can have for free? For many ppl,
the plus of have a valid copy (support,updates) it's not important and every non valid copy could be many less money.
Wan
Wan
Piracy is a problem, but even major publishers haven't been able to solve that issue in a consumer friendly way. You can try to make it as difficult as possible, but if someone puts his mind to it, it will be cracked.
TheTroll
TheTroll
Quote:
Original post by afsajghfd
Seeing c# (code with pretty nice name functions) than seeing asm has no comparation

Because why someone would buy something that can have for free? For many ppl,
the plus of have a valid copy (support,updates) it's not important and every non valid copy could be many less money.


Time for a little dose of cold reality. The people you are trying to protect your code against are never going to pay for you application. If for some reason they can't get a cracked copy, they are not going to use it. It is really that simple.

So you protect your application to keep the honest people and not worry about the other people because you are NEVER going to make money off of them.

The worse thing you can do is make it so the people that actually buy your program are bothered by your efforts against piracy.

As for cracking .Net apps vs. native apps, it really isn't any harder. Any decent cracker can read ASM without any problems. I know this from my misspent youth. You can not make an application that is run on a client computer unhackable, you just can't do it.

theTroll

Machaira
Machaira
Quote:
Original post by TheTroll
Time for a little dose of cold reality. The people you are trying to protect your code against are never going to pay for you application. If for some reason they can't get a cracked copy, they are not going to use it. It is really that simple.


Agreed. All the attempts that studios are using to protect their games just ruin it for the paying players. The games are cracked usually the same day they're released and sometimes before.
Former Microsoft XNA and Xbox MVP | Check out my blog for random ramblings on game development
ernow
ernow
Read about Gameguard
It showed me the problems and attempts to solve it.

I am not advocating GameGuard but this clearly shows what the problem is.

In the end, all processing on a client is a surface of attack.
afsajghfd
afsajghfd
Ok, then the conclusion of all, it's "Don't waste your time trying to protect software"

I will say this to my boss and I hope he understand that if we let the software
unprotected no one will even attempt to copy it, because it isn't a challenge, pretty cool uh.

it's very probably that this comment will make my user rating go down uh
stonemetal
stonemetal
pretty much what you want to do is obfuscate and maybe some sort of serial key system. Beyond that I own the system anything you put on it I can change. The only way to completely stop someone from hacking your stuff is to delete it now. With a close second being run it all server side where noone has direct access to the executables but that brings its own security issues.
Cornstalks
Cornstalks
Quote:
Original post by afsajghfd
Ok, then the conclusion of all, it's "Don't waste your time trying to protect software"

I will say this to my boss and I hope he understand that if we let the software
unprotected no one will even attempt to copy it, because it isn't a challenge, pretty cool uh.

It will still be pirated if you don't include DRM. It will still be pirated if you do include DRM. I mean, look at the computer game Spore. It was cracked four days before it was even released, and it was using state of the art DRM. Its DRM pissed off a bunch of honest users, which is the last thing you want to do. It was illegally downloaded from BitTorrent 1.7 million times three months after its release. Its DRM did absolutely nothing to stop hackers. In fact, including DRM encourages them. Hacking a program with state of the art DRM gets you kudos points in the hacking world. On the other hand, Sins of a Solar Empire included absolutely no DRM, and it's sold more than 500,000 copies. Those are incredible sales numbers for a relatively low budget game with little advertising and no real existing fan base. Sure it's been pirated by people, but the honest users love the publishers for not including DRM. Just do yourself a favor and don't waste your time pissing off honest users with DRM.

Quote:
Original post by afsajghfd
it's very probably that this comment will make my user rating go down uh

I wasn't going to rate you down until you said that. It's ok for you to disagree with others. But immaturely disregarding their points and then stating that you are intentionally being immature is not.

@stonemetal: Serial key systems can be cracked in no time.

[Edited by - MikeTacular on April 3, 2009 1:50:06 PM]
TheTroll
TheTroll
Quote:
Original post by afsajghfd
Ok, then the conclusion of all, it's "Don't waste your time trying to protect software"

I will say this to my boss and I hope he understand that if we let the software
unprotected no one will even attempt to copy it, because it isn't a challenge, pretty cool uh.

it's very probably that this comment will make my user rating go down uh


I will not rate you down because of this.

What you need to do is explain the cost/benefit of the different protection systems. A simple system (serial code and password) is very easy to implement and doesn't cost much. It will keep the honest people honest and will do nothing to keep the pirates away.

An advance system (some form of online checking system) is very costly to implement and will take a lot of time to code and test. This will keep the honest people honest, but will irritate them when it doesn't work right or they don't have access to internet and will do nothing to keep the pirates away.

Your boss needs to understand that you can't stop the hackers and ANY money and effort you put into it past the basics just money you are throwing away.

But as a general rule, make all of your classes internal.

theTroll
SimonForsman
SimonForsman
Quote:
Original post by MikeTacular
@stonemetal: Serial key systems can be cracked in no time.


The point shouldn't be to create something that is hard to crack, it is enough to send a clear signal that its not ok to give copies to friends or the general public and to force pirates in general to use less reputable sources to obtain the software, a serial key system does just that.
[size="1"]I don't suffer from insanity, I'm enjoying every minute of it.
The voices in my head may not be real, but they have some good ideas!
stonemetal
stonemetal
Quote:
Original post by MikeTacular
[@stonemetal: Serial key systems can be cracked in no time.


Yeah and banking can be cracked in no time too. That really isn't the point, it is a deterrent that is strong enough to stop those who are willing to be stopped. People talk about getting DRM strong enough to stop all but the truly determined hackers but there in lies the problem you don't stop the determined hackers and then it winds up on bit torrent where any noob and his brother can have a go at it. So you paint do not enter and lock the doors but any determined thief will have his with your property.
Semei
Semei
Nice discussion, i would like to ask how possible is for a hacker to get this hacked:

1. create separate thread
2. send request to server + some small, but important data to compute so that program can start new game level (like do some map loading stuff), provide serial key
3. server checks if serial is valid
4. if serial is valid (it exists in database and only one IP is using it)
5. compute that small but important stuff, send back to user, encrypted with serial key
6. decrypt data with serial key
7. load level using provided data
BlodBath
BlodBath
Quote:
Original post by Semei
Nice discussion, i would like to ask how possible is for a hacker to get this hacked:

1. create separate thread
2. send request to server + some small, but important data to compute so that program can start new game level (like do some map loading stuff), provide serial key
3. server checks if serial is valid
4. if serial is valid (it exists in database and only one IP is using it)
5. compute that small but important stuff, send back to user, encrypted with serial key
6. decrypt data with serial key
7. load level using provided data


All the hacker would need is one legit key and he could just get all the "small important data" legitimately from the server and patch the executable to not contact the server for it. Look at things like Adobe's CS4 or many Steam games: they phone home for things like that and are still hacked the day they get released.

The best protection scheme is to make software so good people want to buy it.
Semei
Semei
I don't think so - code never gets to client computer - it would take a long time till hacker is able to understand in-game map format and produce+inject working code. You see - i send like 100kb from map being loaded to server, server does some computations and send some data back. Hacker CAN'T possibly get to know inner map structure (im talking about game's map/level file) because he never knows what data from where is read, and also cant experiment with "i changed this bit in map, let's see what changes in game" method because server would ban user if it sends incorrect input and will not ever respond if map had been changed. At least this protection won't get cracked in one day :P

Other idea - online games - they are "uncrackable" because data is being sent to server and server does managing stuff. Cant connect to server with valid key - no game. You could make some fake servers, but they always tend to be real crap and you got a chance that player whos playing on illegal server will start to love the game if its good and go to the real server.
TheTroll
TheTroll
Quote:
Original post by Semei
Nice discussion, i would like to ask how possible is for a hacker to get this hacked:

1. create separate thread
2. send request to server + some small, but important data to compute so that program can start new game level (like do some map loading stuff), provide serial key
3. server checks if serial is valid
4. if serial is valid (it exists in database and only one IP is using it)
5. compute that small but important stuff, send back to user, encrypted with serial key
6. decrypt data with serial key
7. load level using provided data


Go through the whole game doing a mem dump of each level after it has been decrypted. Once they have all the levels, put in a jump that instead of going to the site they just load the hacked levels. Not really very hard at all.

Next, it means that a person HAS to have an internet connection to play. That is very irritating.

theTroll

afsajghfd
afsajghfd
I have thought all the weekend about this, and I realize that it's better to protect the app from the day2day user (without bother him with this protection)

As someone said, just a key/serial can be a nice approach

Thanks to all.
Cornstalks
Cornstalks
Quote:
Original post by stonemetal
Quote:
Original post by MikeTacular
[@stonemetal: Serial key systems can be cracked in no time.


Yeah and banking can be cracked in no time too. That really isn't the point, it is a deterrent that is strong enough to stop those who are willing to be stopped. People talk about getting DRM strong enough to stop all but the truly determined hackers but there in lies the problem you don't stop the determined hackers and then it winds up on bit torrent where any noob and his brother can have a go at it. So you paint do not enter and lock the doors but any determined thief will have his with your property.

Yes, I agree. Rereading your first post makes me realize I slightly misunderstood you the first time. When I first read your post I assumed you meant to simply use a serial key to stop the hackers. I understand what you originally meant now.
Monza
Monza
I've started using a utility call .NET Reactor which protects, encyrpts and obfusicates your code after compilation.

Different levels of protection are available, and it includes a serial key generator module if you want to copy protect as well. It is claimed to be nearly 100% effective against decompilation - I guess time will tell.

Personally, I also written a web service based licensing system which allows only one copy to be activated. This is working well, but it is only as safe as the first person who manages to decompile and modify the code.

Topic Locked

This topic has been locked by a moderator. New replies are not allowed.

Sign in to reply to this topic.