New Statistical De-minifier and De-obfuscator for JavaScript
jsnice.org
jsnice.org
So the input to js nice was the packed generateSeries function:
eval(function(p,a,c,k,e,r){e=function(c) {return(c<a?'':e(parseInt(c/a)))+((c=c%a)>35? String.fromCharCode(c+29):c.toString(36))};if(!''.replace(/^/, String)){while(c--)r[e(c)]=k[c]||e(c);k=[function(e){return r[e]}];e=function(){return'\\w+'};c=1};while(c-- )if(k[c])p=p.replace(new RegExp('\\b'+e(c)+'\\b','g'),k[c]);return p}('4 3(e){2 t=[];2 n=f+e;2 r=6+e;k(i=1;i<=6;i++){2 s=5.y(5.a()*(r- n+1)+n);t.b([i,s]);n++;r++}c t}$(d).B(4(){2 e=3(0);2 t=3(g);$.h($("#j"),[{7:"l",8:e},{7:"o",8:t}],{p:{q:{u: ["#v","#w"]}},x:{9:z},A: {9:m}})})',38,38,'||var|generateSeries|function|Math|200|label |data|ticks|random|push|return|document||100|300|plot||flotcon tainer|for|data1|10||data2|grid|backgroundColor||||colors|D1D1 D1|7A7A7A|xaxis|floor|20|yaxis|ready'.split('|'),0,{}))
Jsnice doesn't exceutes eval as it's doing statical analysis ie. without executing the programs.
I think the scope of this tool is to annotate and de-uglify js code without changing the logic, so you get a more readable version of the routine that generates the eval()'d code, that sounds right to me.
EDIT: btw, can you please put the code in a code box, it messes with the layout. Mods: this is happening frequently, is it a bug?
span.comment {
display: block;
width: 800px;
}
Of course, it should be checked on more pages, but it works here... (using FF)Apparently this is a machine learning research project.
It seems that this would be quite useful for looking at the code of closed-source webapps. Would love to see it open-sourced or available as a service (via an API perhaps). Think auto-deminifying browser extension.
I wonder how much of that 60% comes from common libraries like jQuery or Underscore. Still, a neat project.
I took the source of a sample pasted here and ran it through the heiroglyphy generator:
var expect = function(val) { return "string" == typeof val; };
which output something along the lines of (truncated):
[][(![]+[])[!+[]+!![]+!![]]+([]+{})[+!![]]+(!![]+[])[+!![]]+(!![]+[])[+[]]][([]+{})[!+[]+!![]+!![]+!![]+!![]]+([]+{})...
But JSNice was unable to deobfuscate this code. Any ideas why?
/**
* @param {string} val
* @return {?}
*/
var expect = function(val) {
return "string" == typeof val;
};
/**
* @param {boolean} deepDataAndEvents
* @return {?}
*/
var clone = function(deepDataAndEvents) {
return "boolean" == typeof deepDataAndEvents;
};
/**
* @param {(boolean|number|string)} obj
* @return {?}
*/
var isString = function(obj) {
return "number" == typeof obj;
};
Still, neat idea. Seems like there's a lot of room to train it, probably a lot of fun to try to improve things :)Could someone point me to good resources about mining code, most data mining and machine learning articles deal with points in multidimensional space and not objects with complex internal structure like programs...
but processed jQuery relatively fast.
Line 1: Parse error. missing ; before statement
Thanks for trying it out. I tried few large samples from Hulu and they seemed to work fine, e.g.:
http://static.huluim.com/huluguru/i18n/en-us/translations-9d...
But indeed, sometimes there could be issues if the code does not compile with the compiler of choice.
we will definitely soon provide more details on how the overall system works...
Hehe
Infinitely helpful in reverse engineering google stuff like www.googletagservices.com/tag/js/gpt.js
Thanks!!!