A Tamper Check is a type of Check that detects whether an application has changed since Dotfuscator processed it.
For example, an attacker might modify application binaries to bypass restrictions or remove licensing information. A Tamper Check can detect this type of modification and react by notifying the application or hindering the attacker.
In other words, Tamper Checks help detect and react to unauthorized tampering of your application.
Configure Tamper Checks
You can configure Tamper Checks in two ways:
- In the source code, add and configure the Check attributes directly in your application.
- In the Config Editor, add the Check and configure its properties and locations.
Both methods allow you to specify the properties that determine how the Check operates.
To configure a Tamper Check in the Config Editor:
- Go to the Checks tab in Dotfuscator’s Config Editor.
- Select Add Tamper Check….
- Configure the Check properties.
- Configure the Check locations.
For the full list of available properties, see the TamperCheckAttribute section in the Check Attributes article.
If you are adding a Tamper Check to a Xamarin Android application, see the Tamper Check for Xamarin Android section in Enhance Protection After Your First Build.
Unsupported Application Types
Dotfuscator can inject Tamper Checks into all .NET assemblies except the following:
- Assemblies that target .NET 1.0
- Managed C++ assemblies that contain native and managed code
- Multi-module assemblies
- .NET Compact Framework assemblies
- UWP assemblies
- Xamarin iOS assemblies
Test Tamper Checks
Testing helps you confirm how your protected application reacts when tampering is detected.
For .NET Framework applications, Dotfuscator includes TamperTester.exe, a command-line utility that simulates tampering by modifying assembly metadata.
To test how your protected application reacts to tampering:
-
Open a command prompt. If needed, change to the directory of the protected assembly. For example:
cd C:\YourApp\Dotfuscated
-
Run
TamperTester.exeand specify the assembly for which you want to create a tampered version. ReplaceAssemblyName.exewith the name of your assembly:TamperTester.exe AssemblyName.exe
-
Optional: Specify a second argument to define the directory where the tampered assembly is placed.
If you do not specify a directory, the tampered assembly is placed in a subdirectory namedtampered.
Copy the other output assemblies to the directory of the tampered version. For example:xcopy /d *.* tampered
- Run the tampered assembly.
- Exercise the locations of your Tamper Checks to observe how the application reacts to tampering.
To test how Tamper Checks react to tampering in Xamarin.Android applications follow the testing path that matches how your application is signed.
If you sign the application after generating the archive
- In the project properties, clear Sign the .APK file using the following keystore details.
- Create a new application archive in Visual Studio.
- Select the newly created archive, then select Distribute....
- Select your preferred distribution channel.
- Sign the new package with a key that has a different SHA-1 fingerprint than the one specified by
DotfuscatorAndroidSigningCertFingerprint. - Deploy the application normally.
When signing the new archive, you can use the debug.keystore file or create a new signing key with custom properties.
If you sign the application in the project properties
- Open the project properties in Visual Studio.
- Go to the Android Project Properties tab.
- Clear Sign the .APK file using the following keystore details.
- Build and deploy the application normally.
This causes the deployed application to be signed with the debug.keystore file. This simulates an application that has been tampered with and repackaged.