Java使用ASM反转Jar中的所有字符串

时间:2016-04-10 17:53:13

标签: java reverse-engineering bytecode java-bytecode-asm

我试图创建一个程序来反转jar中的每个字符串,然后再次执行相同的操作,使其像字符串混淆一样。 例如

普通代码:new String("example");

运行后:new String(new StringBuilder().append("elpmaxe").reverse().toString()

我的代码:

public class Main {
static String obfuscationFile;

public static void main(String[] args) throws IOException {
    obfuscationFile = "C:\\Users\\Leonhard\\Desktop\\CrackingTools-v1.0.jar"; // TODO:
                                                                                // args[0]
    File jar = new File(obfuscationFile);
    Map<String, byte[]> out = JarUtil.loadNonClassEntries(jar);
    Map<String, ClassNode> nodes = JarUtil.loadClasses(jar);
    for (ClassNode cn : nodes.values()) {
        for (Object mn : cn.methods) {
            MethodNode mnode = (MethodNode) mn;
            ClassWriter cw = new ClassWriter(ClassWriter.COMPUTE_MAXS);
            cn.accept(cw);
            if (mnode.name.startsWith("")) {
                for (Integer i : reverse(mnode, cw)) {
                    // TODO: Not needed..
                }
            }
            out.put(cn.name, cw.toByteArray());
        }
    }
    JarUtil.saveAsJarAndClasses(out, nodes, jar.getAbsolutePath().replace(".jar", "") + "_Reverse" + ".jar");
}

private static ArrayList<Integer> reverse(MethodNode method, ClassWriter cw) {
    ArrayList<Integer> i = new ArrayList<Integer>();
    int e = 0;
    for (AbstractInsnNode ain : method.instructions.toArray()) {
        e++;
        if (ain.getOpcode() == Opcodes.LDC) {
            if (ain instanceof LdcInsnNode) {
                LdcInsnNode ldc = (LdcInsnNode) ain;
                if (ldc.cst instanceof String) {
                    i.add(e);
                    ldc.cst = new StringBuilder().append(ldc.cst).reverse().toString();
                    MethodVisitor mv = null;
                    mv = cw.visitMethod(method.access, method.name, method.desc, method.signature,
                            (String[]) method.exceptions.toArray(new String[method.exceptions.size()]));
                    if (mv != null) {
                        // mv.visitLineNumber(e, new Label());
                        mv.visitMethodInsn(Opcodes.INVOKEVIRTUAL, "java/lang/StringBuilder", "append",
                                "(Ljava/lang/String;)Ljava/lang/StringBuilder;", true);
                        mv.visitMethodInsn(Opcodes.INVOKEVIRTUAL, "java/lang/StringBuilder", "reverse",
                                "()Ljava/lang/StringBuilder;", true);
                        mv.visitMethodInsn(Opcodes.INVOKEVIRTUAL, "java/lang/StringBuilder", "toString",
                                "()Ljava/lang/String;", true);
                        mv.visitMaxs(0, 0);
                        mv.visitEnd();
                        // System.out.println(method.name + " " +
                        // method.desc);
                    }
                }
            }
        }
    }
    return i;
}

(使用ASM 5.0.4)

我的错误/ mv.visitMethodInsn()我做错了什么?

编辑:我注意到,它正在使用-noverify(但所有字符串都是相反的)。如果没有它,我该怎么办?

1 个答案:

答案 0 :(得分:2)

如果没有关于您遇到的错误或问题的任何信息,很难确切地说出错误。但是,我注意到有一个错误:

                mv.visitMethodInsn(Opcodes.INVOKEVIRTUAL, "java/lang/StringBuilder", "append",
                        "(Ljava/lang/String;)Ljava/lang/StringBuilder;", true);
                mv.visitMethodInsn(Opcodes.INVOKEVIRTUAL, "java/lang/StringBuilder", "reverse",
                        "()Ljava/lang/StringBuilder;", true);
                mv.visitMethodInsn(Opcodes.INVOKEVIRTUAL, "java/lang/StringBuilder", "toString",
                        "()Ljava/lang/String;", true);

在此代码中,您忘记实际创建正在使用的StringBuilder。您需要插入newinvokespecial指令来创建新的StringBuilder。

另一方面,附加电话是不必要的。您可以将字符串直接传递给StringBuilder的ctor。