Indecent Exposure: Your Secrets are Showing
ID: 197379d6-5366-50e2-9081-102b57e4209d
STIX ID: report--197379d6-5366-50e2-9081-102b57e4209d
Feed Name: Black Hills Infosec Blog
This blog post recounts the discovery of hard-coded AES cryptographic materials embedded in a closed-source .NET application's DLL and demonstrates how those secrets were decoded and used to decrypt stored passwords. The author shows two practical methods: (1) exfiltrate and modify the DLL with dnSpy to expose the class, and (2) use PowerShell reflection to load the unmodified assembly, invoke an internal constructor, and call decrypt methods to recover plaintext, and discusses implications and tooling opportunities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
