legend Posted July 6, 2015 Share Posted July 6, 2015 (edited) I've found a issue, regarding : _Crypt_EncryptFileIf you provide a wrong password, and even use @error, it will still try to decompile the file, the result will be a 1 kb file. Edited July 7, 2015 by legend Link to comment Share on other sites More sharing options...
JohnOne Posted July 6, 2015 Share Posted July 6, 2015 Bug Tracker link. AutoIt Absolute Beginners Require a serial Pause Script Video Tutorials by Morthawt ipify Monkey's are, like, natures humans. Link to comment Share on other sites More sharing options...
legend Posted July 6, 2015 Author Share Posted July 6, 2015 I suppose it's this one? :https://www.autoitscript.com/trac/autoit/newticket Link to comment Share on other sites More sharing options...
JohnOne Posted July 6, 2015 Share Posted July 6, 2015 You suppose right. AutoIt Absolute Beginners Require a serial Pause Script Video Tutorials by Morthawt ipify Monkey's are, like, natures humans. Link to comment Share on other sites More sharing options...
legend Posted July 6, 2015 Author Share Posted July 6, 2015 Assume would probably have been the correct work.I thank you :). Link to comment Share on other sites More sharing options...
JohnOne Posted July 6, 2015 Share Posted July 6, 2015 I'm not certain that what you assume, is a bug. I don't see anything in the help file that says that is incorrect behaviour.What error do you get? Whatever it is, you have the opportunity to delete any files. AutoIt Absolute Beginners Require a serial Pause Script Video Tutorials by Morthawt ipify Monkey's are, like, natures humans. Link to comment Share on other sites More sharing options...
legend Posted July 6, 2015 Author Share Posted July 6, 2015 (edited) There's no particular error in the syntax, but the behaviour is indeed a bug as I see it. Why would it be able to detect if the decryption was wrong, and then it will still attempt to decrypt it?.See the first picture in the first post.Sure I can delete the file that it generates, with the content: ÿÿÿÿYet it's not a nice solution. Edited July 6, 2015 by legend Link to comment Share on other sites More sharing options...
JohnOne Posted July 6, 2015 Share Posted July 6, 2015 Yes, already did.Again, what error are you getting? AutoIt Absolute Beginners Require a serial Pause Script Video Tutorials by Morthawt ipify Monkey's are, like, natures humans. Link to comment Share on other sites More sharing options...
legend Posted July 6, 2015 Author Share Posted July 6, 2015 I'm not getting any erros, It's the behaviour of _Crypt_EncryptFile, that it will generate a file with the content of "ÿÿÿÿ" When a wrong decryption password was used. that behaviour is just not logical, when it can detect it by @error. Link to comment Share on other sites More sharing options...
JohnOne Posted July 6, 2015 Share Posted July 6, 2015 So you are not getting an error but the message box shows only if there's an error, and the message box shows.OK.Best of luck. AutoIt Absolute Beginners Require a serial Pause Script Video Tutorials by Morthawt ipify Monkey's are, like, natures humans. Link to comment Share on other sites More sharing options...
legend Posted July 6, 2015 Author Share Posted July 6, 2015 (edited) The message box only shows if the decryption password was correct,I have no clue how you aren't seeing that as a bug (the behaviour of creating a file, when a wrong decrypting password is provided). But thank's for the luck. Edited July 6, 2015 by legend Link to comment Share on other sites More sharing options...
guinness Posted July 6, 2015 Share Posted July 6, 2015 This has been mentioned already. I think the conclusion was NO BUG! UDF List: _AdapterConnections() • _AlwaysRun() • _AppMon() • _AppMonEx() • _ArrayFilter/_ArrayReduce • _BinaryBin() • _CheckMsgBox() • _CmdLineRaw() • _ContextMenu() • _ConvertLHWebColor()/_ConvertSHWebColor() • _DesktopDimensions() • _DisplayPassword() • _DotNet_Load()/_DotNet_Unload() • _Fibonacci() • _FileCompare() • _FileCompareContents() • _FileNameByHandle() • _FilePrefix/SRE() • _FindInFile() • _GetBackgroundColor()/_SetBackgroundColor() • _GetConrolID() • _GetCtrlClass() • _GetDirectoryFormat() • _GetDriveMediaType() • _GetFilename()/_GetFilenameExt() • _GetHardwareID() • _GetIP() • _GetIP_Country() • _GetOSLanguage() • _GetSavedSource() • _GetStringSize() • _GetSystemPaths() • _GetURLImage() • _GIFImage() • _GoogleWeather() • _GUICtrlCreateGroup() • _GUICtrlListBox_CreateArray() • _GUICtrlListView_CreateArray() • _GUICtrlListView_SaveCSV() • _GUICtrlListView_SaveHTML() • _GUICtrlListView_SaveTxt() • _GUICtrlListView_SaveXML() • _GUICtrlMenu_Recent() • _GUICtrlMenu_SetItemImage() • _GUICtrlTreeView_CreateArray() • _GUIDisable() • _GUIImageList_SetIconFromHandle() • _GUIRegisterMsg() • _GUISetIcon() • _Icon_Clear()/_Icon_Set() • _IdleTime() • _InetGet() • _InetGetGUI() • _InetGetProgress() • _IPDetails() • _IsFileOlder() • _IsGUID() • _IsHex() • _IsPalindrome() • _IsRegKey() • _IsStringRegExp() • _IsSystemDrive() • _IsUPX() • _IsValidType() • _IsWebColor() • _Language() • _Log() • _MicrosoftInternetConnectivity() • _MSDNDataType() • _PathFull/GetRelative/Split() • _PathSplitEx() • _PrintFromArray() • _ProgressSetMarquee() • _ReDim() • _RockPaperScissors()/_RockPaperScissorsLizardSpock() • _ScrollingCredits • _SelfDelete() • _SelfRename() • _SelfUpdate() • _SendTo() • _ShellAll() • _ShellFile() • _ShellFolder() • _SingletonHWID() • _SingletonPID() • _Startup() • _StringCompact() • _StringIsValid() • _StringRegExpMetaCharacters() • _StringReplaceWholeWord() • _StringStripChars() • _Temperature() • _TrialPeriod() • _UKToUSDate()/_USToUKDate() • _WinAPI_Create_CTL_CODE() • _WinAPI_CreateGUID() • _WMIDateStringToDate()/_DateToWMIDateString() • Au3 script parsing • AutoIt Search • AutoIt3 Portable • AutoIt3WrapperToPragma • AutoItWinGetTitle()/AutoItWinSetTitle() • Coding • DirToHTML5 • FileInstallr • FileReadLastChars() • GeoIP database • GUI - Only Close Button • GUI Examples • GUICtrlDeleteImage() • GUICtrlGetBkColor() • GUICtrlGetStyle() • GUIEvents • GUIGetBkColor() • Int_Parse() & Int_TryParse() • IsISBN() • LockFile() • Mapping CtrlIDs • OOP in AutoIt • ParseHeadersToSciTE() • PasswordValid • PasteBin • Posts Per Day • PreExpand • Protect Globals • Queue() • Resource Update • ResourcesEx • SciTE Jump • Settings INI • SHELLHOOK • Shunting-Yard • Signature Creator • Stack() • Stopwatch() • StringAddLF()/StringStripLF() • StringEOLToCRLF() • VSCROLL • WM_COPYDATA • More Examples... Updated: 22/04/2018 Link to comment Share on other sites More sharing options...
jchd Posted July 6, 2015 Share Posted July 6, 2015 legend,How on earth can you expect a cryptographic method to "see" that the recovered plaintext is wrong due to a wrong passphrase?That would require one of two taboo things: either the passphrase is stored somewhere in the cyphertext (in which case decryption doesn't need you supply the passphrase, hence defeating the whole purpose of encryption) or the decrypt method has a way to behave as an oracle and recognize that the passphrase and the recovered plaintext is correct, which destroys plausible deniability and introduces a galaxy-large hole in the robustness of the cryptographic method employed.Engage brain before posting and shouting bug! This wonderful site allows debugging and testing regular expressions (many flavors available). An absolute must have in your bookmarks.Another excellent RegExp tutorial. Don't forget downloading your copy of up-to-date pcretest.exe and pcregrep.exe hereRegExp tutorial: enough to get startedPCRE v8.33 regexp documentation latest available release and currently implemented in AutoIt beta. SQLitespeed is another feature-rich premier SQLite manager (includes import/export). Well worth a try.SQLite Expert (freeware Personal Edition or payware Pro version) is a very useful SQLite database manager.An excellent eBook covering almost every aspect of SQLite3: a must-read for anyone doing serious work.SQL tutorial (covers "generic" SQL, but most of it applies to SQLite as well)A work-in-progress SQLite3 tutorial. Don't miss other LxyzTHW pages!SQLite official website with full documentation (may be newer than the SQLite library that comes standard with AutoIt) Link to comment Share on other sites More sharing options...
legend Posted July 6, 2015 Author Share Posted July 6, 2015 Since it can detect if the decryption password was wrong, using: if @error, then it must be able to check whenever it's right or wrong i guess. Link to comment Share on other sites More sharing options...
JohnOne Posted July 6, 2015 Share Posted July 6, 2015 Or you detect that it's wrong and act accordingly. That's what @error is for. AutoIt Absolute Beginners Require a serial Pause Script Video Tutorials by Morthawt ipify Monkey's are, like, natures humans. Link to comment Share on other sites More sharing options...
legend Posted July 7, 2015 Author Share Posted July 7, 2015 Since i'm clearly not able to explain the issue with words, I've made a video that shows the issue here:http://youtu.be/osWWAud8MY4 Link to comment Share on other sites More sharing options...
JohnOne Posted July 7, 2015 Share Posted July 7, 2015 Well that message box clearly shows up, so why are you lying about not getting @error? AutoIt Absolute Beginners Require a serial Pause Script Video Tutorials by Morthawt ipify Monkey's are, like, natures humans. Link to comment Share on other sites More sharing options...
legend Posted July 7, 2015 Author Share Posted July 7, 2015 I though you meant an error in the syntax checker. Link to comment Share on other sites More sharing options...
Moderators Melba23 Posted July 7, 2015 Moderators Share Posted July 7, 2015 legend,I have run the following snippet:#include "Crypt.au3" _Crypt_EncryptFile("test.txt", "encrypted.txt", "123", $CALG_AES_256) ; Use incorrect password $bRet = _Crypt_DecryptFile("encrypted.txt", "wrongdecrypted.txt", "wrongpassword", $CALG_AES_256) ConsoleWrite("Wrong Pword: " & $bRet & " - " & @error & @CRLF) ; Use correct password $bRet = _Crypt_DecryptFile("encrypted.txt", "rightdecrypted.txt", "123", $CALG_AES_256) ConsoleWrite("Right Pword: " & $bRet & " - " & @error & @CRLF) ; Use incorrect file $bRet = _Crypt_DecryptFile("test.txt", "wrongfile.txt", "123", $CALG_AES_256) ConsoleWrite("Wrong File: " & $bRet & " - " & @error & @CRLF)The results are as follows:Wrong Pword: False - 420 Right Pword: True - 0 Wrong File: False - 420According to the Help file, the error says that the function "Failed to create key" and "Failed to decrypt final piece" - which seems perfectly logical to me and there is no differentiation between the 2 cases to help a would-be cracker determine the exact reason for the failure. In both error cases a small 4-byte file is created - which is the product of the internal Windows decryption code used by the Crypt library and nothing to do with AutoIt itself.So what exactly are you complaining about?M23 Any of my own code posted anywhere on the forum is available for use by others without any restriction of any kind Open spoiler to see my UDFs: Spoiler ArrayMultiColSort ---- Sort arrays on multiple columnsChooseFileFolder ---- Single and multiple selections from specified path treeview listingDate_Time_Convert -- Easily convert date/time formats, including the language usedExtMsgBox --------- A highly customisable replacement for MsgBoxGUIExtender -------- Extend and retract multiple sections within a GUIGUIFrame ---------- Subdivide GUIs into many adjustable framesGUIListViewEx ------- Insert, delete, move, drag, sort, edit and colour ListView itemsGUITreeViewEx ------ Check/clear parent and child checkboxes in a TreeViewMarquee ----------- Scrolling tickertape GUIsNoFocusLines ------- Remove the dotted focus lines from buttons, sliders, radios and checkboxesNotify ------------- Small notifications on the edge of the displayScrollbars ----------Automatically sized scrollbars with a single commandStringSize ---------- Automatically size controls to fit textToast -------------- Small GUIs which pop out of the notification area Link to comment Share on other sites More sharing options...
JohnOne Posted July 7, 2015 Share Posted July 7, 2015 I though you meant an error in the syntax checker.So going back to what I said earlier and with the help of Melba23 posting the error, you might do something like...If @error = 420 Then FileDelete("decrypted.txt") ;deal with whatever you need to EndIf BrewManNH 1 AutoIt Absolute Beginners Require a serial Pause Script Video Tutorials by Morthawt ipify Monkey's are, like, natures humans. Link to comment Share on other sites More sharing options...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now