Show HN: Online C/C++ obfuscator
picheta.me
picheta.me
I think a proper obfuscation tool for C should work at lower level than C source code.
But for the use case that my dissertation supervisor had in mind it works very well (gravypod outlines this use case well[2]).
Most of the work in this project was the creation of the underlying architecture for parsing and transforming C and C++ code. Now that this is done, implementing more sophisticated transformations should be fairly trivial.
edit: I misunderstood your use case, still I dont think obfusicated code is source code by definition
that explains a lot.
To give a bit more context: this is a C/C++ obfuscator I have built for my BSc Computer Science dissertation. It's built on the clang parser and while it doesn't implement any fancy obfuscations right now, it does offer a solid base for further obfuscations to be implemented. I figured I would submit it here to see what you guys think of it and to figure out whether I should pursue developing it further.
For those interested in the details, I have uploaded my dissertation here: https://picheta.me/c_cpp_obfuscator.pdf.
Edit: It is done :)
edit: Ah, so the algorithm is deterministic (compare is always mapped to o_9277c6cd6b1431c4622b3bb03df7c6ef) and the assumption is that all compilation units are subject to the same obfuscation mechanism? Doesn't really match the use case where you give the obfuscated code to someone else to build into their program.
How does it decide whether a call to compare should be replaced by a call to o_9277c6cd6b1431c4622b3bb03df7c6ef or whether compare is defined in some external library to be resolved at runtime? At the moment, it is unconditionally replaced, probably with some whitelist for libc functions?
edit2: nope, "memcmp(a, b, 42)" is also name-mangled into something else that won't result in a call to memcmp. What's keeping the qsort in the original GenFizzBuzz example?
I'd probably restrict the name mangling to local variables, functions without external linkage and possibly struct field names. Everything else is likely just too hard to do automatically and will require whole-program analysis which you almost certainly can't do if you're handing out obfuscated source code.
One example of this is `printf`, it would be obfuscated if it wasn't for the fact that it's defined in `stdio.h`. You can try removing that `include` and you'll see that it is then renamed.
The name it creates for each identifier is the md5 of the identifier.
Speaking practically this strikes me as one of "this shouldn't be an online tool" things.
It sends the source code to the server and presumably if you are obfuscating your code you want it to be kept secret. So, I'm not saying this site would do this, but sounds like a great way to harvest code people think is sensitive.
I have now graduated and so I'm wondering what I should do with this project. Two options: open source it or try to sell it. Mainly I'm wondering whether there is actually a big enough market for something like this, I thought HN might help me answer that question so I submitted it :)
Again if you're in need of a source code obfuscation tool you're already in a pretty strange place.
template <typename T> T add(T a, T b) { return a + b; }
Is there a list of C++ features it supports?
#include <stdio.h>
int main() { return [](){return 5;}(); }
Results in unhandled exceptions.
#include <stdio.h>
#include <stdlib.h>
#include <iostream>
int main() {
int someNum = 52;
printf("Whale exists that does %d hz\n", someNum);
std::cout << "Out";
return 0;
}/var/obfuscator/code_624952c3a4d4ebc7df41c830d3572272.c:3:10: fatal error: 'iostream' file not found
Stopping due to parsing error of severity Fatal
-----
Removing the include for iostream yields:
-----
/var/obfuscator/code_c963503bab4beb00483856ecd675548d.c:7:9: error: expected expression
Stopping due to parsing error of severity Error