======================================================================= 2025-06-27 ----------------------------------------------------------------------- [ ] Automate testing more [ ] Make the JS source look obfuscated more uniformaly ======================================================================= ======================================================================= 2025-06-17 ----------------------------------------------------------------------- [X] Change console.timeLog to console.timeEnd ======================================================================= ======================================================================= 2025-06-17 ----------------------------------------------------------------------- [X] Change console.timeLog to console.timeEnd ======================================================================= ======================================================================= 2025-06-13 ----------------------------------------------------------------------- [X] Rev番号をつける。 ======================================================================= ======================================================================= 2025-05-01 ----------------------------------------------------------------------- [X] HObfus.inc.php内にあるdummy document.write.toString()はさらに ややこしくしたほうがいいかもしれない。 `thisArg` はかなりの内部情報をハッカーに与えてしまう。 //------------------------------------------------------ // [ thisArg ] //------------------------------------------------------ // `thisArg` is `this` used in the `target` function. //------------------------------------------------------ let func; if(thisArg===document.write){ func="write"; }else if(thisArg===window.decodeURIComponent){ func="decodeURIComponent"; }else if(thisArg===document.write.toString){ //}else if(thisArg===document.write.toString.toString){ //}else if(thisArg===window.decodeURIComponent.toString){ //}else if(thisArg===window.decodeURIComponent.toString.toString){ func="toString"; }else{ func="none"; } //------------------------------------------------------ ======================================================================= ======================================================================= 2025-04-27 ----------------------------------------------------------------------- [無効] tester の php files は ソースからコピーするのではなく、 そのフォルダ内で上書きされることなく使用できるのが望ましい。 ----------------------------------------------------------------------- 2025-04-28 Done! ======================================================================= ======================================================================= 2025-04-27 ----------------------------------------------------------------------- [X] $_(identifier) を obfuscate するクラスは、static のものがのぞましい。 なぜなら、スクリプト全体で共有して使うものだからだ。 (現在は、$osr というポインターをパラメータとして各ファンクションに 送るという面倒なことをやっている。) include/compiler/CObfUtil はいらないと思う。 ======================================================================= ======================================================================= 2025-04-27 ----------------------------------------------------------------------- [X] ETObf でやったように、$opx を static object( COpx ) に変更すべき。 ======================================================================= ======================================================================= [無効] remove-scriptやremove-commentはスクリプト内でかなり奥まったところで実行している。 ErrorEventが発生した場合、remove-scriptやremove-commentも実行されない可能性が 高い。remove-scriptやremove-commentなどの、スクリプトがAbortされた時でも 実行してほしいタスクは、外側で実行すべきである。 ======================================================================= ======================================================================= [X] 難読化した文字列に < と > 含まれないようにしたほうがいい。 理由はHObfusを使って生成した難読化された文字列内に、 以下のような文字列が偶発的に含んでいた場合、 ----------------- <% %> ----------------- それを、ダイナミックページ(PHP,Ruby,Perl,Python)にペーストした時に プログラム領域に入った/出たと勘違いされてエラーが発生する可能性が高い。 難読化において、< と > は百害あって一利なしである。 ======================================================================= ======================================================================= token_get_all() PhpToken::tokenize() token_name() ----------------------------------------------------------------------- PHP has useful functions to tokenize php source code. You can use tokenized source code to obfuscate it. ======================================================================= ======================================================================= Use the entire range of UTF-8 characters to obfuscate HTML code ----------------------------------------------------------------------- ======================================================================= ======================================================================= [不可能] On Chrome & Reload, it should clear [Violation] Avoid using document.write() [不可能] On FireFox, it should clear unblanced tree [X] Add dummy characters when the input HTML code is small like less than 100 chars [X] This should be extracted from script like ======================================================================= ======================================================================= Features: -------------------------------------------------------------------------- JavaScript: [X] Prevent opening in IE (It cause syntatic error, which is fine) [X] Prevent opening in protocol other than http and https [X] Detect overwriting document.write [X] Script Size Check [X] Remove itself -------------------------------------------------------------------------- PHP: [X] Match HObfus_begin and HObfus_end pairs (Unmatched end shouldn't be excuted) ======================================================================= ======================================================================= [X] ==> Prevent hackers from replacing "decodeURIComponent" function (e.g) $_rstr=$_window.decodeURIComponent($_rx.join("")); =======================================================================