The Obfuscat programme is designed for Microsoft VBA
Some obfuscation techniques depend on the object to be obfuscated. An interpreted language such as Visual Basic is very different from compiled executable code, such as C or assembly language. Furthermore, when obfuscating, the syntax of the language must be taken into account.
In the case of Obfuscat, the target is Microsoft VBA, which is commonly used for Excel or Word macros. The point is that VBA source code, created by the author, is interpreted directly in plain text during execution. The code can be executed in plain text, instruction by instruction. Imagine that the purpose of each instruction is quite obvious. This makes reverse engineering or unauthorised reuse of the source code much easier.
Remove comments.
Source code often contains comments that help the author understand the functionality of the statements. In VBA, comments are preceded by an apostrophe ( ‘ ) at the end of the statements. Comments are removed.
Remove indentation.
To visualise the programme’s structure, statements are usually indented further to the right as they become more deeply nested. All indentation is removed to eliminate the nesting.
Obfuscation of names for variables and line labels.
Normally, each variable is assigned a name that is more or less representative of its content. For example, ‘ClientName’ or ‘ClientCountry’. Other examples include function names (‘Function PrintPage’) or line labels (‘StartOfCalculation:’). Variable names are obfuscated and replaced with random names consisting solely of two pseudo-binary strings (‘o_’ and ‘l_’), such as ‘o_l_o_o_l_o_l_’.
The use of the underscore symbol ‘_’ is intentional, with the aim of causing confusion in the standard Microsoft Visual Basic for Applications (VBA) Editor when searching for names.
Note: Names not be obfuscated (exceptions) must be declared in such row of the ‘Dashboard’ sheet. Some names must remain unobfuscated, such as the typical Sub EntryPoint declaration that is called from an Excel button, or the constant Const Copyright as String = “Legal © …. “
Note: Numeric line codes (such as 1560: ) are not obfuscated, to facilitate debugging (VBA indicates the last line code before the error) in the Erl system variable. In any case, line numbers are essentially meaningless.
Constant obfuscation.
All constants (numbers and text) in assignment statements are obfuscated. For example, ‘myA = 2’ or ‘myB = “Please select a file”’. The decrypted value of each constant is only returned at runtime, when the assignment statement is actually executed.
The ‘Constants’ sheet contains a translation list of the names reserved by Microsoft VBA for constants (column A) alongside the constant’s value (column B), such as (vbBlack 0x0). The constant label, when it appears in the source code, is replaced by its value, and this value is then encrypted in turn. You can add further entries to the ‘Constants’ sheet.
Note: Constants in declarative statements (Const myLong As Long = 1) are very difficult to obfuscate, due to the very structure of the VBA language. Use variables that are not initialised with Private/Dim and assign a value to them using an imperative statement. (Dim myLong As Long: myLong = 1)
Encoding constants.
Some numbers for internal use are declared by Obfuscat at the beginning of the obfuscated code, such as Const l_o_o_l_l_l_l_ As Long = 70
Constants are stored in a very long encrypted string at the end of the obfuscated code, such as o_l_l_o_l_o_l_l_ = “007F0001000000 .. .
This very long encrypted string is managed by functions within the Obfuscat programme, which are also located at the end of the obfuscated code. This very long encrypted string is also protected by a runtime password
Password for internal contants is the runtime password that is provided as a parameter on the ‘Dashboard’ sheet and is included in the obfuscated code in an auto-encrypted form (by default). Alternatively, the runtime password would be provided explicitly at runtime, depending on the settings on the ‘Dashboard’ sheet tab, either supplied by the calling programme (in a shared variable or constant declared in the user programme) or by the user (via Application.InputBox with the Prompt and Title strings set as parameters, and with a shared variable declared in the user programme, which could be initialised with the password and which returns that password).
Note: Constants in declarative statements ( Const myLong As Long = 1 ) can hardly be obfuscated, because of the very structure of the VBA language. Please use Private/Dim uninitialized variables and assign the value with a imperative statement. ( Dim myLong As Long : myLong = 1 )
Encryption of constants.
Some numbers for internal use are declared at the beginning of the obfuscated code, such as Const l_o_o_l_l_l_l_ As Long = 70
The constants are stored in a very long encrypted string at the end of the obfuscated code, as o_l_l_o_l_o_l_l_ = “007F0001000000 …
This very long encrypted string is managed by functions of the Obfuscat program, also placed t the end of the obfuscated code. This very long encrypted string is also protected for a run time password
The run time password is provided as a parameter in the sheet Dashboard, and included selfencrypted (by default) in the obfuscated code. The run time password would be instead explicitly provided at run time, according to the parametrization in the sheet Dashboard well provided by the calling program (in a shared defined variable) or well by the user (by Application.InputBox with parametrized Prompt and Title )
Parametrization in Dashboard
Names not to be obfuscated (exceptions): List of VBA names NOT to be obfucated (tipically such as EntryPoint Copyright).
Obfuscate constants (Yes/No): Default: Yes. The ‘No’ option is used during debugging.
Obfuscate names (Yes/No): Default: Yes. The ‘No’ option is used during debugging.
Password for internal constants: Mandatory. The longer the password, the slower the processing. Four characters (letters, numbers and symbols) are enough.
Prefix of names reserved for Obfuscat: Z_Z_ (default). No other variable should begin with the same characters in the source code, to avoid name collisions.
Variable with password in source code: if no variable is specified, the Obfuscat programme manages the password at runtime. If a variable is specified (which must be declared in the client’s programme), the password is managed at runtime by the programmer or by the end user as well.
Err.Raise Number: Number between 513 and 65535 if password mismatch or is missing. Default 777.
Err.Raise Description: String describing the error if password mismatch or is missing. Default: Password for obfuscated code is not valid.
(Optional) Application.InputBox Prompt Title: The title for the dialog box asking the password to the end user. Default: Obfuscation password
(Optional) Application.InputBox Prompt Text: The message for the dialog box asking the password to the end user. Default: Please type the password for obfuscated code
To know more
stackoverflow.com/questions/16765277/obfuscation-tool-for-ms-excel-vba
www.excel-pratique.com/en/vba_tricks/vba-obfuscator
stackoverflow.com/questions/551892/how-effective-is-obfuscation
softwarerecs.stackexchange.com/questions/10785/c-code-obfuscator
Free Java Bytecode Obfuscator yworks.com/products/yguard
