<< Prev [ Mode: 10 ] Next >>

document.__proto__.__proto__.write=function(str){
	printStr(str);
};
//---------------------------------------------------
// Hacking Example
//---------------------------------------------------
// If CJsObfShield_shift がある場合、
// 1回目のコールは、オリジナルの関数をコールする。
// 2回ー12回までは、
//		"function write() { [native code] }";
// 13回では、
//		"function decodeURIComponent() { [native code] }";
// それ以降は、
//		"function toString() { [native code] }";
//---------------------------------------------------
let CtS=0;
const handlers={
	apply: function (target, thisArg, argumentsList) {

		//------------------------------------------------------
		// [ target ]
		//------------------------------------------------------
		// `target` is a function with the name 'toString' like
		//  `function toString(){...}`
		//------------------------------------------------------
		// `traget.name` returns "toString"
		//------------------------------------------------------
		// target's base is `Function` so the following equation
		// returns `true`
		// (target.__proto__.constructor===Function) ==> true
		//------------------------------------------------------
		// <test code>
		// console.log(target.name,(target.__proto__.constructor===Function))
		//------------------------------------------------------

		//------------------------------------------------------
		// [ thisArg ]
		//------------------------------------------------------
		// `thisArg` is `this` used in the `target` function.
		//------------------------------------------------------
		// Hackers can use this parameter to determine
		// what name should be inserted into
		// `function <name>() { [native code] }`
		//
		// To counteract, HObfus should try a 'toString' call of
		// some rarely used function like 'window.getSelection()'
		// to see how the fake toString function will react.
		//------------------------------------------------------
		let func;
		if(thisArg===document.write){
			func="write";
		}else if(thisArg===window.decodeURIComponent){
			func="decodeURIComponent";
		}else if(thisArg===document.write.toString){
		//}else if(thisArg===document.write.toString.toString){
		//}else if(thisArg===window.decodeURIComponent.toString){
		//}else if(thisArg===window.decodeURIComponent.toString.toString){
			func="toString";
		}else{
			func="none";
		}
		//------------------------------------------------------

		console.log("CtS: "+(++CtS)+" : "+func);

		if(CtS==1){
			return Reflect.apply(target, thisArg, argumentsList);
		}else if(CtS<=12){
			return "function write() { [native code] }";
		}else if(CtS<=13){
			return "function decodeURIComponent() { [native code] }";
		}else{
			return "function toString() { [native code] }";
		}
	}
};
document.write.__proto__.toString=new Proxy(document.write.__proto__.toString,handlers);
Uncheck Remove JavaScript Error Report to see ERROR MESSAGE!
Open console.log for Error Messages.