8 ms·
JSFuck – esoteric JavaScript
- kenrick95 11y agowith eval checked, alert(1) will produce 1227 chars while alert(1); will produce 9535 chars. Interesting.
- Tloewald 11y agoWell ; produces 8307 chars on its own (without eval checked) -- which seems kind of inefficient (for such a common character in idiomatic javascript). Looking that their encoder, ';' actually has a specific encoding (which itself has to be encoded) so it looks like there's some inefficient expansion taking place (e.g. '.' has a specified encoding that does not require recursive encoding). Encoding the string "link" in the expansion of ';' appears to be very expensive -- alert is cheap in comparison because you can obtain its letters from Javascript return values (e.g. "l" is pulled out of "false" which is obtained by (![]+"")[2]) I'd imagine that if you were serious about this, you'd implement, say, e=String.fromCharCode (12k chars) and use that to dig yourself out of a lot of this expensive stuff if you need more than one hard-to-encode character.
- userbinator 11y agoGreat abuse of the implicit type conversion system. Amazing that a simple alert("Hello world!") expands to over 16KB.
- haddr 11y agoAmazing! I wonder if it's difficult to "disassemble" the JSFuck code?
- rsuelzer 11y agoThis article is pretty good on piecing it stuff like this together: https://blog.korelogic.com/blog/2015/01/12/javascript_deobfuscation https://blog.korelogic.com/blog/2015/01/12/javascript_deobfu...
- m1el 11y agoOnce you have partial evaluation, it's really easy. I've done this (and with jsfuck too!) http://m1el.github.io/jsdeobfuscate/ http://m1el.github.io/jsdeobfuscate/
- csomar 11y agoJust remove the () and you'll get the code in a string.
- yyhhsj0521 11y agohah. I tried to, eh, encrypt the source code of JSFuck itself at https://raw.githubusercontent.com/aemkei/jsfuck/master/jsfuck.js https://raw.githubusercontent.com/aemkei/jsfuck/master/jsfuc...
- thomasfoster96 11y agoFor those wondering how you get numbers, strings and other primitives from a whole bunch of empty arrays and objects in JavaScript, here's what happens when you do arithmetic and other operations on arrays and objects: > [] + [] "" (An empty string) > {} + [] 0 (The number zero) > [] + {} "[object Object]" (.toString() called on a plain object). > ![] false (!{} is the same) > !![] true (not false) > +[] 0 (the number zero) > -[] -0 (negative zero) > +{} NaN (Not a number, same goes for -{}) > "" + [] "" (empty string) > "" - [] 0 (number zero, not empty string) And the one that gets more people than the previous list: > typeof [] === typeof {} true Incidentally, some of these things can be useful. For example, +(x) will always evaluate to a double (unless it is preceded by a string), while (x|0) will always evaluate to a 32bit integer. asm.js abuses (to an extent) this to have more control over types, and most JavaScript engines would now store the result of (x|0) as an integer internally instead of a double.
- jaseemabid 11y agoDoes knowing any of this make you a better programmer? I'd say no. Should you be using any of this in production code? No The next programmer even if he is a really good one might not know that particular esoteric trick. I'm not trying to vote down or anything, but what is the point? Most of it look like language design warts to me. Most of them should have thrown exceptions and errored out. Now I'm loving the idea of static typing a lot more.
- xanderjanz 11y agoUseful for obfuscating executable JS for security reasons.
- thomasfoster96 11y agoIt'd have to be something that really had to be hidden, because most of these edge cases are very very slow to run.
- berbc 11y agoWhy? I believe you have more sophisticated ways of obfuscating code. Those tricks seem to be easy to reverse.
- soheil 11y agoI know this will most likely come as a surprise to most Javascript programmers but all code is represented using only two "characters" deep inside your little computers!
- woah 11y agoMost JavaScript developers have tiny computers.
- leppr 11y agoWhat do you mean two characters? What are they exactly? I'm guessing $ and ; because it's like jQuery but some operations seem impossible, like how does it even assign variables?
- Retr0spectrum 11y agoIts quite simple. The "$" and ";" are used in groups of three to signify other characters. "$$$" = "[" "$$;" = "]" "$;$" = "(" "$;;" = ")" ";$$" = "+" ";$;" = "!"
- Xophmeister 11y agoI think he meant 1 and 0
- soheil 11y agoyes
- homakov 11y agoNot useful for obfuscation :( Just remove last ()
- BinaryIdiot 11y agoFor shits and giggles I tried to use the minified version of my open source library. After about 30 minutes of Chrome being frozen I gave up, lol. I was curious how large it would balloon 17kb of JavaScript.
- frik 11y agoIt was on HN 2 years ago with some interesting comments: "JSFuck – Write any JavaScript with 6 Characters: []()!+": https://news.ycombinator.com/item?id=6379732 https://news.ycombinator.com/item?id=6379732 One interesting question was about the "performance impact"? One reply was: "Vanilla I got 225k ops/sec. JSFuck, 4.5 ops/sec. So about 50000 times slower."
- devsquid 11y agoWow, its amazing that you developed this. A healthy mixture of too much free time and being clever.
- dxcqcv 11y agoso js is a cipher code.
- _random_ 11y agoJust like vanilla JS: http://wtfjs.com http://wtfjs.com
- pluma 11y agoThat's the joke. It's a strict subset of JS, not a transpiled language.
- lol768 11y agoI seem to remember CloudFlare using this approach (for obfuscation purposes) when users enable the 'under attack' mode on their sites. I was pretty surprised something like this was possible when I first saw the code.