Wednesday, June 10, 2009

How to avoid auto string conversions in Visual Basic

When visual basic programs call outside sources like C++ DLL files, visual basic automatically converts Unicode strings into ASCII strings. After the outside function completes its task, visual basic will convert the ASCII string back into Unicode format. Sometimes the auto conversion done by visual basic can be a problem because programmers may want to keep the string in Unicode format. In order to get around the conversion, programmers should use byte arrays instead of strings.

bytearray() = mystring

The above tip can be very useful when programmers need to keep the string in Unicode format. Some windows API functions require Unicode strings to be passed in order for them to work. Hopefully Microsoft will eventually add an extra feature to allow programers to decide on the conversion process without a hack. Read More......

Calling C++ DLL files from Visual Basic

Since visual basic hides many details, programmers are limited on control. In general, programmers benefit from fewer details because they save on development time; however, some tasks are difficult or impossible to do without having access to more details then what visual basic provides. In this article, I'm going to illustrate how programmers can interface a C++ DLL with Visual Basic so that programmers can use C++ to solve specific problems with a visual basic program.

I am going to make the assumption that programmers know how to program in C++ and that they are using the Visual C++ compiler. Other compilers should still work, but programmers may have to check documentation for creating window DLL projects. Programmers who don't know C++ will not benefit from this article because they must learn the C++ language first, and teaching C++ in one article is impossible.

Step 1: Open Visual C++
a. Create a win32 Dynamic Link Library project with a meaningful name.
b. Add a source file and name it main.cpp
c. Add a header file and name it main.h
d. Add a text file and give it the same name as the project with the extension .def (Example: myproject.def)

Step 2. Add a reference to ws2_32.lib
a. In the main menu, select project and then settings.
b. Click on the link tab.
c. In the object and library modules, add ws2_32.lib
d. Hit ok.

The ws2.32.lib library is required for our project because it is used when working with visual basic strings.

Step 3. Include the following code in main.h




#include // This is used for strlen()

// use __stdcall or visual basic will not be able to pass parameters to the function:
void __stdcall xorString(char * text, const char * key);

The xorString function is the export function that we are going to call from visual basic. The function is going to accept a message string and a key string from visual basic. The output of the function is going to be a childishly simple encrypted message. Programmers should NEVER rely on the xor algorithm for securing information because it can be broken very quickly. In this article, the xor algorithm is being used for an example only.

Step 4. Include the following code in main.cpp




#include "main.h"

using namespace std;

// Again, you have to use __stdcall or visual basic can’t pass parameters
void __stdcall xorString(char * text, const char * key)
{
// This function takes text and xors it with a key.
// xor is a silly cipher on its own but can be useful
// when used with strong ciphers such as AES.

int textSize;
int keySize;

textSize = strlen(text);
keySize = strlen(key);

for (int i = 0; i <>

Step 5. Include the export function in the definition file. The following should be included in the text file we changed into a .def file in step 1.





LIBRARY "projectnamehere.dll" ;The quotes are suppose to be there.
EXPORTS ;List functions to export below this line.
xorString ; The function we wish to call from visual basic.

Step 6. Save and build the DLL file.

After the DLL file is built by the compiler, it will need to be located on the hard drive. The file should be in the project folder under debug or release. After the DLL file is found, it should be moved to another location so that it will be easier to remember. I would personally recommend C:\. Next, we will call the DLL file from visual basic.

Step 1. Open visual basic.
a. Select windows application from the project menu.
b. On the form, add a command button named Command1.
c. On the form, add a text control named Text1

Step 2. In code view, paste the following declaration at the top of the file.





Private Declare Function xorString Lib "c:\DLLFILENAMEHERE.dll" (ByVal text As String, ByVal key As String) As Long

The above code is our function declaration, and it tells visual basic where to find our DLL file, the name of the function, parameters the function expects, and the return type of the function.

Step 3.
Add the following code to the module.





Private Sub Command1_Click()
Dim str As String
Dim key As String

str = Text1.text ' Get Text
key = "blah" ' Set key

xorString str, key ' Call Dll to xor text =)

Text1.text = str ' Show Text
End Sub

After the above code has been added, the project can be executed. Simply type some text into the text box and click the command button. The text should change to weird looking characters. After clicking the command button a 2nd time, the text should change back to normal.

Read More......

Tuesday, June 9, 2009

Using Powerful Encryption in Visual Basic

From time to time, visual basic programmers need the ability to secure information. When security is needed in software, many visual basic programmers create childishly simple algorithms that can be easily broken; however, programmers have another option to secure information. Visual basic programmers can add powerful encryption to their programs when they plug their software into the CAPICOM library that is provided in the platform SDK by Microsoft.

Programmers must install the platform software development kit from the Microsoft web site before they can use CAPICOM library. Since Microsoft frequently changes its URLs, programmers should just do a search for platform SDK on the Microsoft web site. Since the platform SDK comes with an easy to use setup, vb programmers should have no trouble installing the kit.

After the platform software development kit has been installed, programmers can simply plug the library into their software. In visual basic, programmers should go to the menu and select project->references and select the COM tab. In the list of components, programmers should select “CAPICOM Type Library” and hit ok; now, programmers should be able to call CAPICOM functions from their software project.

After the CAPICOM library has been incorporated into the software project, programmers can encrypt and decrypt information with ease. For example, programmers can experiment with the following code.

Test Form Setup:
Programmers should add two text boxes and two command buttons to a standard form. The first text box should be large because it is going to hold the message.

Text Box 1. Name=txtMessage, text=nothing, Multiline=true
Text Box 2. Name=txtPassword, text=nothing, passwordchar=*
Command Button 1. Name=cmdDecrypt, text = Decrypt
Command Button 2. Name = cmdEncrypt, text = Encrypt

After programmers have added the above components to their form, they can paste the following code into the form's module.






Private Sub cmdDecrypt_Click()
'Make sure we have entered all the information:
If txtMessage.Text <> "" And txtPassword <> "" Then

'This is our encryption object
Dim DecryptData As New EncryptedData

'We send the object the password to use to unlock the encryption:
DecryptData.SetSecret (txtPassword.Text)

'Send the ciphertext to the object and tell it to decrypt it.
DecryptData.Decrypt (txtMessage.Text)

'Get our plaintext from the object
txtMessage.Text = DecryptData.Content
End If
End Sub

Private Sub cmdEncrypt_Click()
'Make sure we have entered all the information:
If txtMessage.Text <> "" And txtPassword <> "" Then

'This is our encryption object
Dim encryptdata As New EncryptedData

'Before we can start encrypting, we got to define the
'algorithm, keysize, and the password (Used to generate key)
'''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
'Algorithm to use: AES (Advanced Encryption Standard)
encryptdata.Algorithm = CAPICOM_ENCRYPTION_ALGORITHM_AES

'You could also use:
'''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
'encryptdata.Algorithm =CAPICOM_ENCRYPTION_ALGORITHM_3DES
'encryptdata.Algorithm = CAPICOM_ENCRYPTION_ALGORITHM_DES
'encryptdata.algorithm = CAPICOM_ENCRYPTION_ALGORITHM_RC2
'encryptdata.Algorithm = CAPICOM_ENCRYPTION_ALGORITHM_RC4

'Next we set our key size, which is a no brainer to put to max.
encryptdata.Algorithm.KeyLength = CAPICOM_ENCRYPTION_KEY_LENGTH_MAXIMUM

'Next we set our secret password to unlock the message.
'''''''''''''''''''''''''''''''''''''''''''''''''''''''''
encryptdata.SetSecret (txtPassword.Text)

'We send the object the plaintext scramble:
encryptdata.Content = txtMessage.Text

'Return message as base64
txtMessage.Text = encryptdata.Encrypt(CAPICOM_ENCODE_BASE64)
End If
End Sub

Read More......

Document Everything

Even though a programmer may write good code, the software may be of poor quality because the programmer failed to document the code clearly. A program of complexity will often have several programmers working to develop and maintain it, but poor documentation can make software projects hard or impossible to maintain. Programmers should always document their code well so that the software will be easier to maintain and extend.

Programmers should properly name all variables, functions, and class objects used in code. Variable names should be named according to their purpose so that the purpose of the variables will be obvious and clear throughout their lifetime. Programmers should generally avoid variable names like x, y, and z. Like variables, functions should also be named according to their purpose, and they should have clear in and out parameters. In addition, classes should be named according to their purpose or relationship. By using proper naming of variables, classes, and functions, programmers will create easier to read code.

Besides names, programmers should always comment the purpose of every function. Every single function in code should be commented to illustrate the intended purpose of the function in a complete sentence. For example, “// Function HexToDec – takes a hexadecimal number as input and outputs the number in decimal.” Function parameters should also be documented to clearly express expected input and output. Processes inside of the function should also be documented to describe how the function obtains its results. Since some functions can be very complex, it is very important to illustrate the process being used by the function. Properly documenting functions can lead to higher quality software and easier maintenance.

Like functions, programmers should comment every class. Class member data should be clearly named so that other programmers can better understand its usage in the class. Class constructors, deconstructions, overloading operators, and member functions should be well defined and commented to illustrate their purpose. Every class should be commented to illustrate the intended purpose of the class, and it should contain any necessary information for clients so that they can quickly implement the class. Since object oriented programming can lead to code reuse, documentation in classes are essential.

In conclusion, programmers should pay particular attention to the documentation of their software project so that they can maintain clarity throughout their code. When programmers fail to properly document their code, the resulting software is often of poor quality. Even though many people believe programming is only about writing code, writing documentation is also a very important part of the process of software development.
Read More......