<< Prev
[ Mode: 10 ]
Next >>
document.__proto__.__proto__.write=function(str){
printStr(str);
};
//---------------------------------------------------
// Hacking Example
//---------------------------------------------------
// If CJsObfShield_shift がある場合、
// 1回目のコールは、オリジナルの関数をコールする。
// 2回ー12回までは、
// "function write() { [native code] }";
// 13回では、
// "function decodeURIComponent() { [native code] }";
// それ以降は、
// "function toString() { [native code] }";
//---------------------------------------------------
let CtS=0;
const handlers={
apply: function (target, thisArg, argumentsList) {
//------------------------------------------------------
// [ target ]
//------------------------------------------------------
// `target` is a function with the name 'toString' like
// `function toString(){...}`
//------------------------------------------------------
// `traget.name` returns "toString"
//------------------------------------------------------
// target's base is `Function` so the following equation
// returns `true`
// (target.__proto__.constructor===Function) ==> true
//------------------------------------------------------
// <test code>
// console.log(target.name,(target.__proto__.constructor===Function))
//------------------------------------------------------
//------------------------------------------------------
// [ thisArg ]
//------------------------------------------------------
// `thisArg` is `this` used in the `target` function.
//------------------------------------------------------
// Hackers can use this parameter to determine
// what name should be inserted into
// `function <name>() { [native code] }`
//
// To counteract, HObfus should try a 'toString' call of
// some rarely used function like 'window.getSelection()'
// to see how the fake toString function will react.
//------------------------------------------------------
let func;
if(thisArg===document.write){
func="write";
}else if(thisArg===window.decodeURIComponent){
func="decodeURIComponent";
}else if(thisArg===document.write.toString){
//}else if(thisArg===document.write.toString.toString){
//}else if(thisArg===window.decodeURIComponent.toString){
//}else if(thisArg===window.decodeURIComponent.toString.toString){
func="toString";
}else{
func="none";
}
//------------------------------------------------------
console.log("CtS: "+(++CtS)+" : "+func);
if(CtS==1){
return Reflect.apply(target, thisArg, argumentsList);
}else if(CtS<=12){
return "function write() { [native code] }";
}else if(CtS<=13){
return "function decodeURIComponent() { [native code] }";
}else{
return "function toString() { [native code] }";
}
}
};
document.write.__proto__.toString=new Proxy(document.write.__proto__.toString,handlers);
Uncheck Remove JavaScript Error Report to see ERROR MESSAGE!
Open console.log for Error Messages.