User Guide
About HObfus
HObfus is a PHP library that allows you to easily obfuscate the HTML code generated by PHP. Simply enclose the code that you want to obfuscate inside a HObfus block and you are all set!

<?php HObfus_begin(); ?>
<div id="obfuscate-me">
	<span class="obfuscate-me">
		<?php echo $obfuscate_me; ?> 
	</span>
</div>
<?php HObfus_end(); ?>
HObfus has a bonus feature that can remove all <script> blocks from the Elements tab of DevTools. This feature makes it very difficult to find the JavaScript code on the page using Developer Tools. For more information about the feature, see $cfg["remove-script"].

Note: HObfus works for UTF-8 encoding files only. If the encoding is not specified, then HObfus automatically sets it to UTF-8, so you don't need to explicitly specify it. All you have to be careful is not to save your PHP files in an encoding other than UTF-8.

Installation
This page will explain how to install HObfus in your website.

1.  Unzipping product zip file
Unzip the product zip file onto your Desktop and then find the folder named hobfus.


 Unzipping zip file
2.  Uploading script to your website
Upload the hobfus folder to your website.

You can put it anywhere on your website but it is recommended to put it in the root directory of the website (e.g. public_html, www, htdocs ), so it is easier to remember where it is located. If you are putting it somewhere other than at the root directory, make sure to note down the path where you put it because later you will refer to the path when you apply HObfus to your PHP pages.
The installation of HObfus is now complete. You can now check out demos of HObfus or obfuscate your PHP pages with HObfus.

Running Demos
In the hobfus folder that you installed in the installation page, there is a folder named examples, which contains HObfus demo pages. HObfus is preset in these demo pages, allowing you to observe how it works by opening them in your browser.

NOTE: If you no longer need the demo pages, you can delete the examples folder from your website. Deleting the examples folder does not affect HObfus.

Viewing demo pages in browser
To view demo pages, open hobfus/examples/index.php in your browser. You will see the menu of the HObfus demo pages, as shown below. Click a menu item to open it in another tab.


 Demo Index Page
Viewing obfuscated code
HObfus obfuscates the HTML code generated by the demo PHP pages. Let's see how it is obfuscated. We will use the demo index page ( /hobfus/examples/index.php) as an example.

Open the demo index page in your browser if it is not opened yet.

1
Right-click the demo index page. A popup menu appears.

 Right-click
2
Select View Page Source from the pop-up menu to see the page source in a new tab.

 Click "View Page Source"
Viewing PHP source code
Now let's check out the original PHP source code of the demo pages. Open hobfus/examples/ in your file manager (not web browser!). You will find all the demo files here.


 hobfus/examples/
Open demo files in a text editor to view the source code.

When you browse the demo PHP files, you may notice that in most of the files, the code is enclosed in HObfus_begin() and HObfus_end() like

<?php HObfus_begin(); ?>
...........................
...........................
...........................
<?php HObfus_end(); ?>
HObfus_begin() and HObfus_end() will mark the beginning and end point of obfuscation. These two functions allow you to specify the code to obfuscate. For more information about HObfus_begin() and HObfus_end(), see Using HObfus.

Using HObfus
Using HObfus is very easy. The idea is to enclose the code you want to obfuscate inside HObfus_begin() and HObfus_end(), like this.

<?php HObfus_begin(); ?>
<div id="obfuscate-this">
	<span class="obfuscate-me">
		<?php echo "I want to obfuscate this HTML code!"; ?> 
	</span>
</div>
<?php HObfus_end(); ?>
You can obfuscate the entire HTML code, or just parts of it if you want.

OK, let's get started!

First Example
This first example will walk you through the process for setting up HObfus in a PHP page. We will explain how to set up HObfus in a PHP page so the HTML code generated by the PHP page gets obfuscated when opened in a browser. We will use the following PHP page as an example to show how to use HObfus.

<!doctype html>
<html>
	<head>
		<meta charset="utf-8">
		<title>My PHP Page</title>
	</head>
	<body>
		<?php echo "The current time is ".date("Y-m-d H:i:s"); ?> 
	</body>
</html>
1.  Specify code to obfuscate
To specify the code that you want to obfuscate, enclose it inside <?php HObfus_begin(); ?> and <?php HObfus_end(); ?>. In this example, we will obfuscate the entire page, so insert <?php HObfus_begin(); ?> and <?php HObfus_end(); ?> at the beginning and the end of the file, respectively, as shown below.

<?php HObfus_begin(); ?>
<!doctype html>
<html>
	<head>
		<meta charset="utf-8">
		<title>My PHP Page</title>
	</head>
	<body>
		<?php echo "The current time is ".date("Y-m-d H:i:s"); ?> 
	</body>
</html>
<?php HObfus_end(); ?>
The HTML code generated between <?php HObfus_begin(); ?> and <?php HObfus_end(); ?> will be obfuscated when the PHP page is opened in a browser.

2.  Include HObfus.inc.php
Before testing the PHP page, there is one more thing to be done. In the previous step, you added two functions: HObfus_begin() and HObfus_end() to the PHP page. These functions are declared in the file, hobfus/HObfus.inc.php, which you installed in the installation page. To make the functions available to your PHP page, you need to include hobfus/HObfus.inc.php using the require_once() function, like shown below.

<?php require_once("PATH-TO-HObfus.inc.php"); ?>
<?php HObfus_begin(); ?>
<!doctype html>
<html>
	<head>
		<meta charset="utf-8">
		<title>My PHP Page</title>
	</head>
	<body>
		<?php echo "The current time is ".date("Y-m-d H:i:s"); ?> 
	</body>
</html>
<?php HObfus_end(); ?>
You must replace PATH-TO-HObfus.inc.php with the actual path to hobfus/HObfus.inc.php. If you are not sure about the path, see Find the path to HObfus.inc.php for more help.

The position of require_once() is usually at the top of the PHP file, however, you can place it anywhere as long as it comes before the first <?php HObfus_begin(); ?>.

3.  Test your PHP page
Now you are ready to test it. Open the PHP file in your browser and check the source. You should find that the HTML source code is obfuscated.

Obfuscating a Part of a Webpage
The basic steps to obfuscate a part of a webpage is the same as obfuscating the whole page, which is explained in the first example.

To obfuscate a part of a webpage,

1
first enclose the code that you want to obfuscate inside <?php HObfus_begin(); ?> and <?php HObfus_end(); ?>, like shown below.
<?php echo HObfus_begin(); ?>
<div>
	<span>
		<?php echo "The current time is ".date("Y-m-d H:i:s"); ?> 
	</span>
</div>
<?php HObfus_end(); ?>
Make sure that all paired HTML tags are closed and the HTML is formatted properly. Malformed HTML code can cause issues with HObfus.

2
Include hobfus/HObfus.inc.php using the require_once() function, like shown below.
<?php require_once("PATH-TO-HObfus.inc.php"); ?>
.................
.................
.................
.................
.................
<?php echo HObfus_begin(); ?>
<div>
	<span>
		<?php echo "The current time is ".date("Y-m-d H:i:s"); ?> 
	</span>
</div>
<?php HObfus_end(); ?>
You must replace PATH-TO-HObfus.inc.php with the actual path to hobfus/HObfus.inc.php. If you are not sure about the path, see Find path to HObfus.inc.php for more details.

The position of require_once() is usually at the top of the PHP file, however, you can place it anywhere as long as it comes before the first <?php HObfus_begin(); ?>.

Multiple Obfuscations in a Webpage
You can obfuscate more than one block of HTML code. You need to enclose each block in inside <?php HObfus_begin(); ?> and <?php HObfus_end(); ?> as shown below.

<?php HObfus_begin(); ?>
<div>
	<?php echo "This is HTML code #1"; ?> 
</div>
<?php HObfus_end(); ?>

<?php HObfus_begin(); ?>
<div>
	<?php echo "This is HTML code #2"; ?> 
</div>
<?php HObfus_end(); ?>

<?php HObfus_begin(); ?>
<div>
	<?php echo "This is HTML code #3"; ?> 
</div>
<?php HObfus_end(); ?>
Don't forget to include HObfus.inc.php to the PHP page. To do so, use the require_once() function like shown below.

<?php require_once("PATH-TO-HObfus.inc.php"); ?>
Find Path to HObfus.inc.php
To use HObfus in your PHP file, you need to include HObfus.inc.php, which you installed in your website in the installation page. You can include HObfus.inc.php using the require_once function like shown below.

<?php require_once("PATH-TO-HObfus.inc.php"); ?>
where PATH-TO-HObfus.inc.php must be replaced with the actual path to hobfus/HObfus.inc.php.

To figure out the path to HObfus.inc.php, you can use a very simple PHP script like shown below.

<?php echo dirname(__FILE__)."/HObfus.inc.php"; ?>
Copy the PHP code above and put it in a text editor such as Notepad. Save it as find-path.php in the hobfus folder, which you installed in your website in the installation page.

Now open hobfus/find-path.php in your web browser. The browser will display the path to your hobfus/HObfus.inc.php like this.

/this/is/path/to/hobfus/HObfus.inc.php
Copy the path and paste it in the require_once function. For example,

<?php require_once("/this/is/path/to/hobfus/HObfus.inc.php"); ?>
Important!
Remove find-path.php from your web site after using it to avoid a security risk.
Configuring HObfus
HObfus offers some customizable settings to tweak its behavior. While default values are effective in most situations, there may be instances where you want to make changes to it.

To configure HObfus, open hobfus/config.inc.php in a text editor (such as Notepad). The following customizable settings are available. Click on the link for more details.

$cfg["verify-hostname"]
Verify whether the hostname used by the server matches the one used by the client.
$cfg["verify-protocol"]
Verify whether the transfer protocol is HTTP/HTTPS.
$cfg["prepend"]
Prepend a text/tabs to HObfus obfuscations.
$cfg["remove-script"]
Remove all <script> blocks from the Elements tab of DevTools.
$cfg["remove-comment"]
Remove all comment blocks (<!-- ... -->) from the Elements tab of DevTools.
$cfg["return-output"]
Return obfuscated code as a PHP string.
$cfg["verify-hostname"]
$cfg["verify-hostname"] controls whether HObfus should check if the hostname used by the server matches the one used by the client.

Set $cfg["verify-hostname"] to 1 to enable the checking.

$cfg["verify-hostname"]=1;
If $cfg["verify-hostname"]=1 (enabled), then HObfus checks if the hostname used by the server and the one used by the client match. If they don't match, then HObfus does not output HTML code. The hostname mismatch typically occurs when an obfuscated webpage is downloaded and placed in another website.

Set $cfg["verify-hostname"] to 0 to disable the checking.

$cfg["verify-hostname"]=0;
The default value of $cfg["verify-hostname"] is 1 (enabled).

$cfg["verify-hostname"]=1;
It is a good idea to keep it enabled to make it harder to unobfuscate the HObfus obfuscation.

In most websites, the hostname used by the server and the one used by the client should match (unless the webpage is moved to another domain). However, there are websites that don't report the hostname as a FQDN (Fully Qualified Domain Name), and so the server and client hostnames do not match. To use HObfus in those websites, you need to disable it by setting $cfg["verify-hostname"] to 0.
$cfg["verify-protocol"]
$cfg["verify-protocol"] controls whether HObfus should check if the transfer protocol is HTTP or HTTPS.

Set $cfg["verify-protocol"] to 1 to enable the checking.

$cfg["verify-protocol"]=1;
If $cfg["verify-protocol"]=1 (enabled), then HObfus checks if the transfer protocol is HTTP or HTTPS. If neither, then HObfus will not output HTML code.

Note that if you open the page locally in a file manager ( instead of a web browser ), the transfer protocol is FILE ( neither HTTP nor HTTPS ).

It is a good idea to keep it enabled to make it harder to unobfuscate the webpage when it is downloaded and opened locally.

Set $cfg["verify-protocol"] to 0 to disable the checking.

$cfg["verify-protocol"]=0;
The default value of $cfg["verify-protocol"] is 1 (enabled).

$cfg["verify-protocol"]=1;
$cfg["prepend"]
$cfg["prepend"] defines a text (or # of tabs) to be prepended to the front of each HObfus obfuscation. Suppose you assign "I think, therefore I am." to $cfg["prepend"] like this.

$cfg["prepend"]="I think, therefore I am.";
Then HObfus will prepend "I think, therefore I am." to each HObfus obfuscation like shown below.


If you assign a number to $cfg["prepend"], then the same number of tabs will be prepended to each HObfus obfuscation. For example, in the following setting, 25 tabs will be prepended.

$cfg["prepend"]=25;
If you do not want to prepend any text or tabs, then set $cfg["prepend"] to an empty string like this.

$cfg["prepend"]="";
The default value of $cfg["prepend"] is 100, which prepends 100 tabs to each HObfus obfuscation.

$cfg["prepend"]=100;
$cfg["remove-script"]
$cfg["remove-script"] controls whether HObfus should remove all the <script> tags from the Elements tab of DevTools.

Set $cfg["remove-script"] to 1 to enable the feature that removes all the <script> tags from the Elements tab of DevTools.

$cfg["remove-script"]=1;
Set $cfg["remove-script"] to 0 to disable the feature.

$cfg["remove-script"]=0;
When $cfg["remove-script"] is enabled, all <script> tags are removed from the Elements tab of DevTools, regardless of the locations of <?php HObfus_begin(); ?> and <?php HObfus_end(); ?>.
The default value of $cfg["remove-script"] is 0 (disabled).

$cfg["remove-script"]=0;
$cfg["remove-comment"]
$cfg["remove-comment"] controls whether HObfus should remove all the HTML comment tags ( <!-- ... --> ) from the Elements tab of DevTools.

Set $cfg["remove-comment"] to 1 to enable the feature that removes all the HTML comment tags from the Elements tab of DevTools.

$cfg["remove-comment"]=1;
Set $cfg["remove-comment"] to 0 to disable the feature.

$cfg["remove-comment"]=0;
When $cfg["remove-comment"] is enabled, all the HTML comment tags are removed from the Elements tab of DevTools, regardless of the locations of <?php HObfus_begin(); ?> and <?php HObfus_end(); ?>.
The default value of $cfg["remove-comment"] is 0 (disabled).

$cfg["remove-comment"]=0;
$cfg["return-output"]
$cfg["return-output"] controls whether HObfus_end() should output obfuscated code to the browser or return it as a PHP string.

If $cfg["return-output"] is 0, HObfus_end() will output obfuscated code to the browser.

$cfg["return-output"]=0;
If $cfg["return-output"] is 1, HObfus_end() will return obfuscated code as a PHP string.

$cfg["return-output"]=1;
For example, the following code will assign the obfuscated code to a PHP variable named '$my_code':

$my_code=HObfus_end();
It is up to you how you utilize the value of the variable. You may want to save it to a file and use it at a later time.

It is very rare that you want to set $cfg["return-output"] to 1 in the configuration file. Instead, you would rather want to override it in HObfus_begin() like:

HObfus_begin(array(
  "return-output"=>1
));
The default value of $cfg["return-output"] is 0 (disabled).

$cfg["return-output"]=0;
Override Configurations
You can override the HObfus configurations on a per-instance basis. To do so, pass the key-value pairs of HObfus configurations to the HObfus_begin function as a PHP array, like shown below.

HObfus_begin(array(
	key1=>value1,
	key2=>value2,
	key3=>value3,
	......
	......
	......
	keyN=>valueN,
));
Example 1
Override $cfg["verify-hostname"] and $cfg["verify-protocol"] with 1 and 0, respectively.

<?php HObfus_begin(array(
	"verify-hostname"=>1,
	"verify-protocol"=>0,
)); ?>
	...PHP/HTML code...
	...PHP/HTML code...
	...PHP/HTML code...
<?php HObfus_end(); ?>
Example 2
Override $cfg["remove-script"] with 1.

<?php HObfus_begin(array(
	"remove-script"=>1,
)); ?>
	...PHP/HTML code...
	...PHP/HTML code...
	...PHP/HTML code...
<?php HObfus_end(); ?>
Example 3
Override $cfg["remove-comment"] with 1.

<?php HObfus_begin(array(
	"remove-comment"=>1,
)); ?>
	...PHP/HTML code...
	...PHP/HTML code...
	...PHP/HTML code...
<?php HObfus_end(); ?>
HObfus Home
