=====================================================================================================
p
panel
danger
Feels Different from HTML Obfuscator?
If you have used HTML Obfuscator,
you may notice that the obfuscated JavaScript code generated by HTML Obfuscator and HObfus behave differently.
This is because their default configuration settings are different. The following four configuration settings are the major differences between the two.
HTML Obfuscator
$cfg["verify-hostname"]=0 (OFF)
$cfg["verify-protocol"]=0 (OFF)
$cfg["remove-script"]=1 (ON)
$cfg["remove-comment"]=1 (ON)
HObfus
$cfg["verify-hostname"]=1 (ON)
$cfg["verify-protocol"]=1 (ON)
$cfg["remove-script"]=0 (OFF)
$cfg["remove-comment"]=0 (OFF)
You can change the default configuration settings of HObfus by editing the HObfus configuration file or you can override the default configuration settings by passing an array to HObfus_begin().
=====================================================================================================
p
It is a good idea to keep it enabled to make it harder to unobfuscate the HObfus obfuscation.
info
In most websites, the hostname used by the server and the one used by the client should match (unless the webpage is moved to another domain). However, there are websites that don't report the hostname as a FQDN (Fully Qualified Domain Name), and so the server and client hostnames do not match. To use %app-name% in those websites, you need to disable it by setting k^$cfg["verify-hostname"]$ to b^0$.
=====================================================================================================
p
It is a good idea to keep it enabled to make it harder to unobfuscate the webpage when it is downloaded and opened locally.
=====================================================================================================