Perl2Exe Code Obfuscation Weakness
BID:6909
Info
Perl2Exe Code Obfuscation Weakness
| Bugtraq ID: | 6909 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 22 2002 12:00AM |
| Updated: | Feb 22 2002 12:00AM |
| Credit: | Discovery of this issue is credited to Simon Cozens. |
| Vulnerable: |
IndigoSTAR Software Perl2Exe 6.0 IndigoSTAR Software Perl2Exe 5.0 2 IndigoSTAR Software Perl2Exe 1.0 9 |
| Not Vulnerable: | |
Discussion
Perl2Exe Code Obfuscation Weakness
Perl2Exe obfuscates Perl source code using a reversible algorithm when converting it to an executable format. This occurs when the "encrypt" option is selected. Those who use Perl2Exe with the expectation that the source code will be concealed from the end user may have a false sense of security as a result.
Perl2Exe obfuscates Perl source code using a reversible algorithm when converting it to an executable format. This occurs when the "encrypt" option is selected. Those who use Perl2Exe with the expectation that the source code will be concealed from the end user may have a false sense of security as a result.
Exploit / POC
Perl2Exe Code Obfuscation Weakness
The following proof-of-concept has been made available:
The following proof-of-concept has been made available:
Solution / Fix
Perl2Exe Code Obfuscation Weakness
Solution:
The vendor has acknowledged this issue and stated that Perl2Exe should be not be used to obfuscate Perl source code.
Solution:
The vendor has acknowledged this issue and stated that Perl2Exe should be not be used to obfuscate Perl source code.
References
Perl2Exe Code Obfuscation Weakness
References:
References:
- Perl2Exe EXEs Can Be Decompiled (Simon Cozens)
- teso Releases (teso)
- Perl2Exe EXEs Can Be Decompiled (update) ("Domainbox, Tim Abenath"
)