2024-04-04
	-Released HObufs
2024-04-20
	-First Purchase of HObfus form Britain
2024-05-01
	-[ZEBRA1211] Implemented 'insert random string at the beginning of JavaScript'
2024-05-10
	-[ZEBRA1255]
		Added date to each PHP example file.
		Removed `begin-func` comments from example PHP files
		Removed echo "<scr"."ipt>"; because it seems Windows Defender stopped
			tagetting <script> 
2024-05-14
	-[ZEBRA1266]
		Handle the older version of doctype:
			-----------------------------------------------------------------
			<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
			-----------------------------------------------------------------
			//@@ remove <!doctype html> from text
			//@@ pattern='/^\s*<!doctype\s+html[^>]*>/i'
			//@@ pattern="/^\\s*<!doctype\\s+html[^>]*>/i"
			if($doctype=preg_match("/^\\s*<!doctype\\s+html[^>]*>/i",
				$text,$mx)?$mx[0]:null){
				$text=substr($text,strlen($doctype));
				$doctype=trim($doctype);
			}
			-----------------------------------------------------------------
		Added 'echo' to config.inc.php in HObfus
			-----------------------------------------------------------------
			// It is up to you how you utilize the value of the variable.
			// You may want to save it to a file and send it to a browser
			// at a later time. To send it to a browser, use 'echo' like
			//
			// echo $my_code;
			-----------------------------------------------------------------
2024-06-11
	[ZEBRA1433]
		Moved document.write to another line in JSX.

			-----------------------------------------------------------------
			HObfus.inc.php
			-----------------------------------------------------------------
			//@@ output code
			$_qax.$_docwrite=((
				$_master_obj,
				$_local,
				$_f_a,
				$_f_b,
				$_random_string_func
			)=>{
				//@@ random string generator
				$_random_string_func="rAx1poBsdfC";
				$_local[$_random_string_func]=($_ch,$_n,$_s,$_patt,$_i)=>{
					$_s="";
					$_patt="abcdefghijklmnopqrstuvwxyz0123456789";
					for($_i=0;$_i<$_n;$_i++){
						$_s+=$_patt.charAt(Math.floor(Math.random()*$_patt.length));
					}
					return $_ch+$_s;
				};
				//@@ setup `$_f_a` and `$_f_b` with random string generator
				$_f_a=$_local[$_random_string_func]("a",134);
				$_f_b=$_local[$_random_string_func]("b",122);
				//@@ this is a `B` function that emits the output string
				$_local[$_f_b]=($_obj)=>{
					//@@ delete '$_f_a' and '$_f_b'
					delete $_window[$_f_a];
					delete $_window[$_f_b];
					//@@ check if master_obj and obj are identical
					return($_master_obj===$_obj)?$_rstr:"";
				};
				//@@ call a local function with the same name
				$_window[$_f_a]=$_document.write.bind($_document);
				$_window[$_f_b]=($_obj)=>$_local[$_f_b]($_obj);
				//@@ In the following Function creatiion, you are passing
				//@@ `this` parameter. We assume that it's not possible to
				//@@ access to the `this` parameter, so we use it to
				//@@ check if `$_f_b()` is called from inside this Function(....)
				//@@ instead of being called directly.
				return(new $_window.Function($_f_a+"("+$_f_b+"("+"this"+"))")).bind($_master_obj);
				//@@ Unfortunately, you can not delete '$_f_a' and '$_f_b' in this function
				//@@ becuase they must exist when the function is excuted.
			})({},{});

			//@@[BEGIN:js-qax-block]
			$_qax.$_docwrite();
			//@@[END:js-qax-block]
			-----------------------------------------------------------------

			-----------------------------------------------------------------
			CHObfusjsx.class.php
			-----------------------------------------------------------------
			public static function make($opx,$osr,$txt){

				$linex=array();
				$linex[]=CHObfusJsx_passcode::make($opx,$osr);
				if($opx["enable-js-onerr"]){
					$linex[]=CHObfusJsx_onerr::make($opx,$osr);
				}
				$linex[]=CHObfusJsx_hexstr::make($opx,$osr);
				$linex[]=CHObfusJsx_protocol::make($opx,$osr);
				$linex[]=CHObfusJsx_hostname::make($opx,$osr);
				$linex[]=CHObfusJsx_rscript::make($opx,$osr);
				$linex[]=CHObfusJsx_rcomment::make($opx,$osr);
				$linex[]=$txt;
				$linex[]=CHObfusJsx_docwrite::make($opx,$osr);<-------
			-----------------------------------------------------------------
			[NEW] CHObfusJsx_docwrite.class.php
			-----------------------------------------------------------------

		Added hobfus/index.php that redrects to examples/index.php

2025-05-02
	==============================================================================
	RACCOON362
	==============================================================================

	OBF-Method: ZEBRA1452 をアップグレードする必要が出てきた。
	新OBF-Method　は RACCOON362 になる。

	アップグレードの必要は以下の２つが要因である。

	------------------------------------------------------------------------------
	1) https://blog.deobfuscate.io/investigating-html-obfuscator
		に対処しなければいけない。

	2) ETObfが完成して、ETObfとHObfusを組み合わせて使う場合の問題点を解決しなければいけない。
	------------------------------------------------------------------------------

	今回にアップグレードは以下の6つの点である。

	------------------------------------------------------------------------------
	[X] 1) <!doctype html> と <script> の間に <meta charset="utf-8"> を入れて、
	ページにCharsetをUTF-8に設定する。
	==>(ZEBRA1453で改造済み)

	[X] 2) document.characterSetでページにcharsetを調べる。
	もしcharsetがUTF-8でなかったら、console.logにエラーを出して、
	スクリプトの実行を中断する。

	[X] 3) Networkタブに表示されるVMのスタックを最小限にするために、
	document.writeするfunctionをコア内部で実行せず、
	これをCJsLineのforEachの別のスレッドからCallする。
	==>これはすでにImplementされていた。

	[X] 4) ETObfで行ったように、function.toString()を用いて、
	シールドのレイヤーを作り、コア部分を守る。
	==>CJsObfShield_shift.class.phpの移植完了

	[X] 5) document.write & window.decodeURIComponent のFake対策を行う。
	==>(ZEBRA1454で改造済み)

	[X] 6) Change `window.Function` to `(()=>{}).constructor`
	==>(ZEBRA1454で改造済み)

	[X] 7) Added the feature to find Obf-Method.
		See tester/test-obf-method-finder.php
	==>(RACCOON362)
	==============================================================================

2025-05-25
	==============================================================================
	RACCOON363
	==============================================================================
	Imported CJsObfShield_shift.class.php from ETOBF ( Set $n_shift=13 )
	Imported CJsObfWord_dollar.class.php from ETOBF
	==============================================================================

2025-06-13
	==============================================================================
	OSPREY845
	==============================================================================
	[X] 1) builder を code-builder に名前を変更する
	==>Done!
	
	[X] 2) $optをCOptとして統一して使う。
	==>Done!
	
	[X] 3) $dollar Obfuscationを統一する。
	==>Done!
	
	[X] 4) obfword、obfunit をリタイアさせる。
	==> obunitはリタイアさせられたが、vintage-obfstr と vintage-obfwordは残る。
	
	[X] 5) timer(console.time,console.timeEnd) オプションをつける。
	==>
	
	[X] 6) if(!$_isnative(...) によるプロセスの中断の位置を
			ハッカーに悟られないようにする。
	==>
	
	[X] 7) `toString proxy`でHackする方法に、`name proxy`で対処する。
	==>
	
	[X] 8) Element.remove()のHackingを防ぐ。
	==>
	
	[X] 9) Scripts/Commentsの削除はdocument.writeのすぐ後に行うようにする。
			（今はDOMContentLoaded eventで行われている。)
	==>
	
	[X] 10) For-Loop内での関数はbindしてから使う。
	==>
	
	[X] 11) PHP側のObfuscationメソッドを変更する。ランダムprefixを付け加える。
	==>
	
	[X] 12) JavaScrip内の self を window へ戻す。('self'は書き換え可能だから)
	==>
	==============================================================================
