JSNice: Statistical renaming, type inference, and deobfuscation
jsnice.org
jsnice.org
Yes, we all know that it's pointless to obfuscate client side code, but this serves as a simple deterrent. I've had games copied/pasted on some Chinese website and this seems to avoid that.
I used this [0] to obfuscate, which is free and open-source. You can also try it online here [1] if you don't feel like installing the Node.js package just for playing with it.
disclosure: I built the web interface [1] to the obfuscator, which is also open source.
[0]: https://github.com/javascript-obfuscator/javascript-obfuscat... [1]: https://javascriptobfuscator.herokuapp.com/
They do nice stuff, like hiding some of your strings, other literals and random predicates inside an encrypted string. This is decrypted and eval'd at runtime using the text of the decrypt function as a parameter i.e, you can't beautify it otherwise it stop working. The random predicates are merged within your code for instance: it appends a `&& somePredicateThatReturnsTrue(someOtherRandomValue)` to ifs conditions. It makes it really hard to figure out what is happening.
So no webpack plugin, I guess :)
[1] I'm assuming it's written in JS. It might not, of course.
This is decrypted and eval'd at runtime
Most(all?) string-based obfuscators can be bypassed by simply replacing eval with a logging eval implementation.
var oldEval = eval; eval = function(str){console.log(str);oldEval(str)};
A similar patch to the Function constructor can bypass the other easy dynamic code generation code path.If at some point, a string needs to be evaluated as code, then it's possible to intercept that code and output it.