Hacking Premium Features on Desktop Application

2 years ago 135
BOOK THIS SPACE FOR AD
ARTICLE AD

Rejinold Pearson

The Price Hacking !

DISCLAIMER : This is only for educational purposes. Hacking into Desktop Application can be lot more fun, but please do not use it for any illegal purposes. I’m not hell responsible for those action. This is a complete Client Application Penetration Testing methodology. Nothing Illegal!

Hey there, My name is Rejinold Pearson, Cyber Security Researcher. Today In this section we are gonna be looking at Client Application Penetration Testing methodology to unlock premium features on desktop application. Complete beginner friendly. You don’t wanna be a Client Application Penetration Tester for doing this. With that been said, let’s get started.

For the purpose of demonstration I’m gonna be using a application called DroidCam. It’s fantabulous application that allows you to use mobile camera as a webcam. Available for Windows, Mac, Linux and Android.

DroidCam Client Application

Now In this application If you look at the bottom of the app, You could see “DroidCamX Pro Controls” which is premium feature. So, We are gonna be unlocking the premium feature with just some mouse clicks. To move further we need just a single file called WinSpy++. Click here to download the file.

Now I’m gonna open the WinSpy and the target application DroidCam.

WinSpy++ and DroidCam

On the WinSpy++, Just drag the finder tool over any of the feature under the DroidCamX Pro Controls. I’m gonna drag this over the JPG feature to unlock it.

Dragging the finder tool over the JPG feature

Now You’ll see some details on WinSpy++. Now under General tab > click on the dropdown menu on the “handle” and click on “Visible”. BoOm! We unlock the JPG Premium feature.

Unlock JPG Premium Feature

Proof of Concept

That’s basically for this blog. This is based on GUI Hacking or you can say Client Application Penetration Testing. And I also encourage you to test this vulnerability on different client application and report it.

Read Entire Article