logo

Indecent Exposure: Your Secrets are Showing 

ID: 197379d6-5366-50e2-9081-102b57e4209d

STIX ID: report--197379d6-5366-50e2-9081-102b57e4209d

Feed Name: Black Hills Infosec Blog

Threat Score
45/100

Date Published: 2025-01-09

Date Updated: 2026-04-27

Author: BHIS

...
...

This blog post recounts the discovery of hard-coded AES cryptographic materials embedded in a closed-source .NET application's DLL and demonstrates how those secrets were decoded and used to decrypt stored passwords. The author shows two practical methods: (1) exfiltrate and modify the DLL with dnSpy to expose the class, and (2) use PowerShell reflection to load the unmodified assembly, invoke an internal constructor, and call decrypt methods to recover plaintext, and discusses implications and tooling opportunities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.