=======================================================================
2025-05-01
-----------------------------------------------------------------------
HObfus.inc.php内にあるdummy document.write.toString()はさらに
ややこしくしたほうがいいかもしれない。
`thisArg` はかなりの内部情報をハッカーに与えてしまう。

	//------------------------------------------------------
	// [ thisArg ]
	//------------------------------------------------------
	// `thisArg` is `this` used in the `target` function.
	//------------------------------------------------------
	let func;
	if(thisArg===document.write){
		func="write";
	}else if(thisArg===window.decodeURIComponent){
		func="decodeURIComponent";
	}else if(thisArg===document.write.toString){
	//}else if(thisArg===document.write.toString.toString){
	//}else if(thisArg===window.decodeURIComponent.toString){
	//}else if(thisArg===window.decodeURIComponent.toString.toString){
		func="toString";
	}else{
		func="none";
	}
	//------------------------------------------------------

=======================================================================

=======================================================================
2025-04-27
-----------------------------------------------------------------------
tester の php files は ソースからコピーするのではなく、
そのフォルダ内で上書きされることなく使用できるのが望ましい。
-----------------------------------------------------------------------
2025-04-28 Done!
=======================================================================

=======================================================================
2025-04-27
-----------------------------------------------------------------------
$_(identifier) を obfuscate するクラスは、static のものがのぞましい。
なぜなら、スクリプト全体で共有して使うものだからだ。
(現在は、$osr というポインターをパラメータとして各ファンクションに
送るという面倒なことをやっている。)
include/compiler/CObfUtil はいらないと思う。
=======================================================================

=======================================================================
2025-04-27
-----------------------------------------------------------------------
ETObf でやったように、$opx を static object( COpx ) に変更すべき。
=======================================================================

=======================================================================
remove-scriptやremove-commentはスクリプト内でかなり奥まったところで実行している。
ErrorEventが発生した場合、remove-scriptやremove-commentも実行されない可能性が
高い。remove-scriptやremove-commentなどの、スクリプトがAbortされた時でも
実行してほしいタスクは、外側で実行すべきである。
=======================================================================

=======================================================================
難読化した文字列に < と > 含まれないようにしたほうがいい。
理由はHObfusを使って生成した難読化された文字列内に、
以下のような文字列が偶発的に含んでいた場合、
-----------------
<?
?>
<%
%>
-----------------
それを、ダイナミックページ(PHP,Ruby,Perl,Python)にペーストした時に
プログラム領域に入った/出たと勘違いされてエラーが発生する可能性が高い。

難読化において、< と > は百害あって一利なしである。
=======================================================================


=======================================================================
token_get_all()
PhpToken::tokenize()
token_name() 
-----------------------------------------------------------------------
PHP has useful functions to tokenize php source code.
You can use tokenized source code to obfuscate it.
=======================================================================

=======================================================================
Use eval to obfuscate PHP code
-----------------------------------------------------------------------
=======================================================================

=======================================================================
Use the entire range of UTF-8 characters to obfuscate HTML code
-----------------------------------------------------------------------
=======================================================================

=======================================================================
Make the charcode of an obfuscated character look random, depending on
the position in text.
-----------------------------------------------------------------------
=======================================================================
