123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712 |
- import 'reflect-metadata';
- import format from 'string-template';
- import { assert } from 'chai';
- import { ServiceIdentifiers } from '../../../../../src/container/ServiceIdentifiers';
- import { ICryptUtils } from '../../../../../src/interfaces/utils/ICryptUtils';
- import { IInversifyContainerFacade } from '../../../../../src/interfaces/container/IInversifyContainerFacade';
- import { IObfuscationResult } from '../../../../../src/interfaces/source-code/IObfuscationResult';
- import { NO_ADDITIONAL_NODES_PRESET } from '../../../../../src/options/presets/NoCustomNodes';
- import { DomainLockTemplate } from '../../../../../src/custom-code-helpers/domain-lock/templates/DomainLockTemplate';
- import { GlobalVariableTemplate1 } from '../../../../../src/custom-code-helpers/common/templates/GlobalVariableTemplate1';
- import { InversifyContainerFacade } from '../../../../../src/container/InversifyContainerFacade';
- import { JavaScriptObfuscator } from '../../../../../src/JavaScriptObfuscatorFacade';
- import { readFileAsString } from '../../../../helpers/readFileAsString';
- /**
- * @param {string} currentDomain
- * @returns {string}
- */
- function getDocumentDomainTemplate (currentDomain: string): string {
- return `
- document = {
- domain: '${currentDomain}'
- };
- `
- }
- /**
- * @param {string} currentDomain
- * @returns {string}
- */
- function getDocumentLocationTemplate (currentDomain: string): string {
- return `
- document = {
- location: {
- hostname: '${currentDomain}'
- }
- };
- `
- }
- /**
- * @param {string} currentDomain
- * @returns {string}
- */
- function getDocumentDomainAndLocationTemplate (currentDomain: string): string {
- return `
- document = {
- domain: '${currentDomain}',
- location: {
- hostname: '${currentDomain}'
- }
- };
- `
- }
- /**
- * @param templateData
- * @param {string} callsControllerFunctionName
- * @param {string} documentTemplate
- * @returns {Function}
- */
- function getFunctionFromTemplate (
- templateData: any,
- callsControllerFunctionName: string,
- documentTemplate: string
- ): Function {
- const domainLockTemplate: string = format(DomainLockTemplate(), templateData);
- return Function(`
- ${documentTemplate}
- var ${callsControllerFunctionName} = (function(){
- return function (context, fn){
- return function () {
- return fn.apply(context, arguments);
- };
- }
- })();
- ${domainLockTemplate}
- `)();
- }
- describe('DomainLockTemplate', () => {
- const singleCallControllerFunctionName: string = 'callsController';
- let cryptUtils: ICryptUtils;
- before(() => {
- const inversifyContainerFacade: IInversifyContainerFacade = new InversifyContainerFacade();
- inversifyContainerFacade.load('', '', {});
- cryptUtils = inversifyContainerFacade.get<ICryptUtils>(ServiceIdentifiers.ICryptUtils);
- });
- describe('Variant #1: current domain matches with `domainsString`', () => {
- const domainsString: string = ['www.example.com'].join(';');
- const currentDomain: string = 'www.example.com';
- let testFunc: () => void;
- before(() => {
- const [
- hiddenDomainsString,
- diff
- ] = cryptUtils.hideString(domainsString, domainsString.length * 3);
- testFunc = () => getFunctionFromTemplate(
- {
- domainLockFunctionName: 'domainLockFunction',
- diff: diff,
- domains: hiddenDomainsString,
- globalVariableTemplate: GlobalVariableTemplate1(),
- singleCallControllerFunctionName
- },
- singleCallControllerFunctionName,
- getDocumentDomainTemplate(currentDomain)
- );
- });
- it('should correctly run code inside template', () => {
- assert.doesNotThrow(testFunc);
- });
- });
- describe('Variant #2: current domain matches with base domain of `domainsString`', () => {
- const domainsString: string = ['.example.com'].join(';');
- const currentDomain: string = 'www.example.com';
- let testFunc: () => void;
- before(() => {
- const [
- hiddenDomainsString,
- diff
- ] = cryptUtils.hideString(domainsString, domainsString.length * 3);
- testFunc = () => getFunctionFromTemplate(
- {
- domainLockFunctionName: 'domainLockFunction',
- diff: diff,
- domains: hiddenDomainsString,
- globalVariableTemplate: GlobalVariableTemplate1(),
- singleCallControllerFunctionName
- },
- singleCallControllerFunctionName,
- getDocumentDomainTemplate(currentDomain)
- );
- });
- it('should correctly run code inside template', () => {
- assert.doesNotThrow(testFunc);
- });
- });
- describe('Variant #3: current domain matches with root domain of `domainsString`', () => {
- const domainsString: string = ['.example.com'].join(';');
- const currentDomain: string = 'example.com';
- let testFunc: () => void;
- before(() => {
- const [
- hiddenDomainsString,
- diff
- ] = cryptUtils.hideString(domainsString, domainsString.length * 3);
- testFunc = () => getFunctionFromTemplate(
- {
- domainLockFunctionName: 'domainLockFunction',
- diff: diff,
- domains: hiddenDomainsString,
- globalVariableTemplate: GlobalVariableTemplate1(),
- singleCallControllerFunctionName
- },
- singleCallControllerFunctionName,
- getDocumentDomainTemplate(currentDomain)
- );
- });
- it('should correctly run code inside template', () => {
- assert.doesNotThrow(testFunc);
- });
- });
- describe('Variant #4: current root domain matches with `domainsString`', () => {
- describe('Variant #1', () => {
- const domainsString: string = ['example.com'].join(';');
- const currentDomain: string = 'example.com';
- let testFunc: () => void;
- before(() => {
- const [
- hiddenDomainsString,
- diff
- ] = cryptUtils.hideString(domainsString, domainsString.length * 3);
- testFunc = () => getFunctionFromTemplate(
- {
- domainLockFunctionName: 'domainLockFunction',
- diff: diff,
- domains: hiddenDomainsString,
- globalVariableTemplate: GlobalVariableTemplate1(),
- singleCallControllerFunctionName
- },
- singleCallControllerFunctionName,
- getDocumentDomainTemplate(currentDomain)
- );
- });
- it('should correctly run code inside template', () => {
- assert.doesNotThrow(testFunc);
- });
- });
- describe('Variant #2', () => {
- const domainsString: string = ['example.com', '.example.com'].join(';');
- const currentDomain: string = 'subdomain.example.com';
- let testFunc: () => void;
- before(() => {
- const [
- hiddenDomainsString,
- diff
- ] = cryptUtils.hideString(domainsString, domainsString.length * 3);
- testFunc = () => getFunctionFromTemplate(
- {
- domainLockFunctionName: 'domainLockFunction',
- diff: diff,
- domains: hiddenDomainsString,
- globalVariableTemplate: GlobalVariableTemplate1(),
- singleCallControllerFunctionName
- },
- singleCallControllerFunctionName,
- getDocumentDomainTemplate(currentDomain)
- );
- });
- it('should correctly run code inside template', () => {
- assert.doesNotThrow(testFunc);
- });
- });
- describe('Variant #3', () => {
- const domainsString: string = ['.example.com', 'example.com'].join(';');
- const currentDomain: string = 'subdomain.example.com';
- let testFunc: () => void;
- before(() => {
- const [
- hiddenDomainsString,
- diff
- ] = cryptUtils.hideString(domainsString, domainsString.length * 3);
- testFunc = () => getFunctionFromTemplate(
- {
- domainLockFunctionName: 'domainLockFunction',
- diff: diff,
- domains: hiddenDomainsString,
- globalVariableTemplate: GlobalVariableTemplate1(),
- singleCallControllerFunctionName
- },
- singleCallControllerFunctionName,
- getDocumentDomainTemplate(currentDomain)
- );
- });
- it('should correctly run code inside template', () => {
- assert.doesNotThrow(testFunc);
- });
- });
- describe('Variant #4', () => {
- const domainsString: string = ['sub1.example.com', 'sub2.example.com'].join(';');
- const currentDomain: string = 'sub1.example.com';
- let testFunc: () => void;
- before(() => {
- const [
- hiddenDomainsString,
- diff
- ] = cryptUtils.hideString(domainsString, domainsString.length * 3);
- testFunc = () => getFunctionFromTemplate(
- {
- domainLockFunctionName: 'domainLockFunction',
- diff: diff,
- domains: hiddenDomainsString,
- globalVariableTemplate: GlobalVariableTemplate1(),
- singleCallControllerFunctionName
- },
- singleCallControllerFunctionName,
- getDocumentDomainTemplate(currentDomain)
- );
- });
- it('should correctly run code inside template', () => {
- assert.doesNotThrow(testFunc);
- });
- });
- });
- describe('Variant #5: current domain matches with base domain of `domainsString` item', () => {
- const domainsString: string = ['www.test.com', '.example.com'].join(';');
- const currentDomain: string = 'subdomain.example.com';
- let testFunc: () => void;
- before(() => {
- const [
- hiddenDomainsString,
- diff
- ] = cryptUtils.hideString(domainsString, domainsString.length * 3);
- testFunc = () => getFunctionFromTemplate(
- {
- domainLockFunctionName: 'domainLockFunction',
- diff: diff,
- domains: hiddenDomainsString,
- globalVariableTemplate: GlobalVariableTemplate1(),
- singleCallControllerFunctionName
- },
- singleCallControllerFunctionName,
- getDocumentDomainTemplate(currentDomain)
- );
- });
- it('should correctly run code inside template', () => {
- assert.doesNotThrow(testFunc);
- });
- });
- describe('Variant #6: current domain doesn\'t match with `domainsString`', () => {
- describe('Variant #1', () => {
- const domainsString: string = ['www.example.com'].join(';');
- const currentDomain: string = 'www.test.com';
- let testFunc: () => void;
- before(() => {
- const [
- hiddenDomainsString,
- diff
- ] = cryptUtils.hideString(domainsString, domainsString.length * 3);
- testFunc = () => getFunctionFromTemplate(
- {
- domainLockFunctionName: 'domainLockFunction',
- diff: diff,
- domains: hiddenDomainsString,
- globalVariableTemplate: GlobalVariableTemplate1(),
- singleCallControllerFunctionName
- },
- singleCallControllerFunctionName,
- getDocumentDomainTemplate(currentDomain)
- );
- });
- it('should throw an error', () => {
- assert.throws(testFunc);
- });
- });
- describe('Variant #2', () => {
- const domainsString: string = ['sub1.test.com', 'sub2.test.com'].join(';');
- const currentDomain: string = 'sub3.test.com';
- let testFunc: () => void;
- before(() => {
- const [
- hiddenDomainsString,
- diff
- ] = cryptUtils.hideString(domainsString, domainsString.length * 3);
- testFunc = () => getFunctionFromTemplate({
- domainLockFunctionName: 'domainLockFunction',
- diff: diff,
- domains: hiddenDomainsString,
- globalVariableTemplate: GlobalVariableTemplate1(),
- singleCallControllerFunctionName
- },
- singleCallControllerFunctionName,
- getDocumentDomainTemplate(currentDomain)
- );
- });
- it('should throw an error', () => {
- assert.throws(testFunc);
- });
- });
- describe('Variant #3', () => {
- const domainsString: string = ['www.example.com', '.example.com', 'sub.test.com'].join(';');
- const currentDomain: string = 'www.test.com';
- let testFunc: () => void;
- before(() => {
- const [
- hiddenDomainsString,
- diff
- ] = cryptUtils.hideString(domainsString, domainsString.length * 3);
- testFunc = () => getFunctionFromTemplate(
- {
- domainLockFunctionName: 'domainLockFunction',
- diff: diff,
- domains: hiddenDomainsString,
- globalVariableTemplate: GlobalVariableTemplate1(),
- singleCallControllerFunctionName
- },
- singleCallControllerFunctionName,
- getDocumentDomainTemplate(currentDomain)
- );
- });
- it('should throw an error', () => {
- assert.throws(testFunc);
- });
- });
- describe('Variant #4', () => {
- const domainsString: string = ['.example.com'].join(';');
- const currentDomain: string = 'example1.com';
- let testFunc: () => void;
- before(() => {
- const [
- hiddenDomainsString,
- diff
- ] = cryptUtils.hideString(domainsString, domainsString.length * 3);
- testFunc = () => getFunctionFromTemplate(
- {
- domainLockFunctionName: 'domainLockFunction',
- diff: diff,
- domains: hiddenDomainsString,
- globalVariableTemplate: GlobalVariableTemplate1(),
- singleCallControllerFunctionName
- },
- singleCallControllerFunctionName,
- getDocumentDomainTemplate(currentDomain)
- );
- });
- it('should throw an error', () => {
- assert.throws(testFunc);
- });
- });
- describe('Variant #4', () => {
- const domainsString: string = ['example.com'].join(';');
- const currentDomain: string = 'sub.example.com';
- let testFunc: () => void;
- before(() => {
- const [
- hiddenDomainsString,
- diff
- ] = cryptUtils.hideString(domainsString, domainsString.length * 3);
- testFunc = () => getFunctionFromTemplate(
- {
- domainLockFunctionName: 'domainLockFunction',
- diff: diff,
- domains: hiddenDomainsString,
- globalVariableTemplate: GlobalVariableTemplate1(),
- singleCallControllerFunctionName
- },
- singleCallControllerFunctionName,
- getDocumentDomainTemplate(currentDomain)
- );
- });
- it('should throw an error', () => {
- assert.throws(testFunc);
- });
- });
- });
- describe('Variant #7: location.hostname', () => {
- describe('Variant #1: current location.hostname matches with `domainsString`', () => {
- const domainsString: string = ['www.example.com'].join(';');
- const currentHostName: string = 'www.example.com';
- let testFunc: () => void;
- before(() => {
- const [
- hiddenDomainsString,
- diff
- ] = cryptUtils.hideString(domainsString, domainsString.length * 3);
- testFunc = () => getFunctionFromTemplate(
- {
- domainLockFunctionName: 'domainLockFunction',
- diff: diff,
- domains: hiddenDomainsString,
- globalVariableTemplate: GlobalVariableTemplate1(),
- singleCallControllerFunctionName
- },
- singleCallControllerFunctionName,
- getDocumentLocationTemplate(currentHostName)
- );
- });
- it('should correctly run code inside template', () => {
- assert.doesNotThrow(testFunc);
- });
- });
- describe('Variant #2: current location.hostname doesn\'t match with `domainsString`', () => {
- const domainsString: string = ['www.example.com'].join(';');
- const currentHostName: string = 'www.test.com';
- let testFunc: () => void;
- before(() => {
- const [
- hiddenDomainsString,
- diff
- ] = cryptUtils.hideString(domainsString, domainsString.length * 3);
- testFunc = () => getFunctionFromTemplate(
- {
- domainLockFunctionName: 'domainLockFunction',
- diff: diff,
- domains: hiddenDomainsString,
- globalVariableTemplate: GlobalVariableTemplate1(),
- singleCallControllerFunctionName
- },
- singleCallControllerFunctionName,
- getDocumentLocationTemplate(currentHostName)
- );
- });
- it('should throw an error', () => {
- assert.throws(testFunc);
- });
- });
- });
- describe('Variant #8: domain and location.hostname presented', () => {
- describe('Variant #1: current domain matches with `domainsString`', () => {
- const domainsString: string = ['www.example.com'].join(';');
- const currentHostName: string = 'www.example.com';
- let testFunc: () => void;
- before(() => {
- const [
- hiddenDomainsString,
- diff
- ] = cryptUtils.hideString(domainsString, domainsString.length * 3);
- testFunc = () => getFunctionFromTemplate(
- {
- domainLockFunctionName: 'domainLockFunction',
- diff: diff,
- domains: hiddenDomainsString,
- globalVariableTemplate: GlobalVariableTemplate1(),
- singleCallControllerFunctionName
- },
- singleCallControllerFunctionName,
- getDocumentDomainAndLocationTemplate(currentHostName)
- );
- });
- it('should correctly run code inside template', () => {
- assert.doesNotThrow(testFunc);
- });
- });
- describe('Variant #2: current domain doesn\'t match with `domainsString`', () => {
- const domainsString: string = ['www.example.com'].join(';');
- const currentHostName: string = 'www.test.com';
- let testFunc: () => void;
- before(() => {
- const [
- hiddenDomainsString,
- diff
- ] = cryptUtils.hideString(domainsString, domainsString.length * 3);
- testFunc = () => getFunctionFromTemplate(
- {
- domainLockFunctionName: 'domainLockFunction',
- diff: diff,
- domains: hiddenDomainsString,
- globalVariableTemplate: GlobalVariableTemplate1(),
- singleCallControllerFunctionName
- },
- singleCallControllerFunctionName,
- getDocumentDomainAndLocationTemplate(currentHostName)
- );
- });
- it('should throw an error', () => {
- assert.throws(testFunc);
- });
- });
- });
- describe('Prevailing kind of variables', () => {
- const getCodeTemplate = (obfuscatedCode: string) => `
- global.document = {
- domain: 'obfuscator.io'
- };
- ${obfuscatedCode}
- `;
- describe('`var` kind', () => {
- let obfuscatedCode: string,
- domainLockVariableRegExp: RegExp = /var _0x([a-f0-9]){4,6} *= *new *RegExp/;
- beforeEach(() => {
- const code: string = readFileAsString(__dirname + '/fixtures/prevailing-kind-of-variables-var.js');
- const obfuscationResult: IObfuscationResult = JavaScriptObfuscator.obfuscate(
- code,
- {
- ...NO_ADDITIONAL_NODES_PRESET,
- domainLock: ['obfuscator.io'],
- stringArray: true,
- stringArrayThreshold: 1
- }
- );
- obfuscatedCode = obfuscationResult.getObfuscatedCode();
- });
- it('Should return correct kind of variables for domain lock code', () => {
- assert.match(obfuscatedCode, domainLockVariableRegExp);
- });
- it('Should does not break on obfuscating', () => {
- assert.doesNotThrow(() => eval(getCodeTemplate(obfuscatedCode)));
- });
- });
- describe('`const` kind', () => {
- let obfuscatedCode: string,
- domainLockVariableRegExp: RegExp = /const _0x([a-f0-9]){4,6} *= *new *RegExp/;
- beforeEach(() => {
- const code: string = readFileAsString(__dirname + '/fixtures/prevailing-kind-of-variables-const.js');
- const obfuscationResult: IObfuscationResult = JavaScriptObfuscator.obfuscate(
- code,
- {
- ...NO_ADDITIONAL_NODES_PRESET,
- domainLock: ['obfuscator.io'],
- stringArray: true,
- stringArrayThreshold: 1
- }
- );
- obfuscatedCode = obfuscationResult.getObfuscatedCode();
- });
- it('Should return correct kind of variables for domain lock code', () => {
- assert.match(obfuscatedCode, domainLockVariableRegExp);
- });
- it('Should does not break on obfuscating', () => {
- assert.doesNotThrow(() => eval(getCodeTemplate(obfuscatedCode)));
- });
- });
- describe('`let` kind', () => {
- let obfuscatedCode: string,
- domainLockVariableRegExp: RegExp = /const _0x([a-f0-9]){4,6} *= *new *RegExp/;
- beforeEach(() => {
- const code: string = readFileAsString(__dirname + '/fixtures/prevailing-kind-of-variables-let.js');
- const obfuscationResult: IObfuscationResult = JavaScriptObfuscator.obfuscate(
- code,
- {
- ...NO_ADDITIONAL_NODES_PRESET,
- domainLock: ['obfuscator.io'],
- stringArray: true,
- stringArrayThreshold: 1
- }
- );
- obfuscatedCode = obfuscationResult.getObfuscatedCode();
- });
- it('Should return correct kind of variables for domain lock code', () => {
- assert.match(obfuscatedCode, domainLockVariableRegExp);
- });
- it('Should does not break on obfuscating', () => {
- assert.doesNotThrow(() => eval(getCodeTemplate(obfuscatedCode)));
- });
- });
- });
- });
|