您现在的位置是: 网站首页> 学习笔记> JS逆向 JS逆向

猿人学-第一届Web端爬虫攻防大赛第二题

2021-01-21 [JS逆向] [猿人学刷题] 3756人已围观

刷题地址:http://match.yuanrenxue.com/match/2

这道题就是找cookie生成的地方。 先F12打开调试工具,点Application-->Clear storage-->Clear site data清空数据

请求网页抓包,可以发现要抓的连接请求头中已经带有cookie了, 那肯定是在这之前生成的,但是前面的连接中又没有生成相应的cookie;

使用fiddler抓包看一下,可以发现在正确请求到数据的页面之前还发了一次请求; 点进去看一下,这个请求响应了一堆混淆过的JS代码。

把代码复制出来格式化一下;

混淆过的看不懂,直接复制到猿人学刷题平台的OB解混淆工具中解混淆; 在解混淆的代码中搜一下cookie,可以发现cookie的生成地方;

剩下的就是扣代码,这里有个M函数,仔细看假设没有global函数,那么就会执行catch中的代码,

把navigator['vendorSub']拿到浏览器控制台中看一下,可以发现是一个空值, 如果这里是一个空值,结合m生成的地方看,还是比较符合预期的, 那这里尝试直接返回空值;

接下来就是把不需要的代码删除,把入口函数改一下。

python代码

import execjs
import requests
import json

base_url = 'http://match.yuanrenxue.com/api/match/2?page={}'
headers = {
    'User-Agent': 'yuanrenxue.project',
}


def get_data(page, cookies):

    # 获取当前页数据并返回
    res = requests.get(base_url.format(page), headers=headers, cookies=cookies)
    print(res.text)
    datas = json.loads(res.text)['data']

    return [data['value'] for data in datas]


if __name__ == '__main__':
    datas = []

    with open('./test02.js') as f:
        js_text = f.read()

    # 调用js计算m的值
    m = execjs.compile(js_text).call('get_m')
    print(m)

    for page in range(1, 6):
        datas.extend(get_data(page,  {'m': m}))

    print(datas)
    print(sum(datas))

JS代码(为了突个方便,没有仔细扣代码,就是把执行时有问题的一些没用的代码注释掉了)

//(function $c(k) {
  var B = function () {
    var Y = true;
    return function (Z, a0) {
      var a1 = Y ? function () {
        if (a0) {
          var a2 = a0["apply"](Z, arguments);
          a0 = null;
          return a2;
        }
      } : function () {};
      Y = false;
      return a1;
    };
  }();

  function C(Y, Z) {
    var a0 = (65535 & Y) + (65535 & Z);
    return (Y >> 16) + (Z >> 16) + (a0 >> 16) << 16 | 65535 & a0;
  }

  function D(Y, Z) {
    return Y << Z | Y >>> 32 - Z;
  }

  function E(Y, Z, a0, a1, a2, a3) {
    return C(D(C(C(Z, Y), C(a1, a3)), a2), a0);
  }

  function F(Y, Z, a0, a1, a2, a3, a4) {
    return E(Z & a0 | ~Z & a1, Y, Z, a2, a3, a4);
  }

  function G(Y, Z, a0, a1, a2, a3, a4) {
    return E(Z & a1 | a0 & ~a1, Y, Z, a2, a3, a4);
  }

  function H(Y, Z) {
    let a0 = [99, 111, 110, 115, 111, 108, 101];
    let a1 = "";

    for (let a2 = 0; a2 < a0["length"]; a2++) {
      a1 += String["fromCharCode"](a0[a2]);
    }

    return a1;
  }

  function I(Y, Z, a0, a1, a2, a3, a4) {
    return E(Z ^ a0 ^ a1, Y, Z, a2, a3, a4);
  }

  function J(Y, Z, a0, a1, a2, a3, a4) {
    return E(a0 ^ (Z | ~a1), Y, Z, a2, a3, a4);
  }

  function K(Y, Z) {
    if (Z) {
      return J(Y);
    }

    return H(Y);
  }

  function L(Y, Z) {
    let a0 = "";

    for (let a1 = 0; a1 < Y["length"]; a1++) {
      a0 += String["fromCharCode"](Y[a1]);
    }

    return a0;
  }

  function M(Y, Z) {
    // var a2 = B(this, function () {
    //   var a5 = {
    //     "omHuj": "return /\" + this + \"/"
    //   };
    //
    //   var a7 = function () {
    //     var a8 = a7["constructor"](a5["omHuj"])()["compile"]("^([^ ]+( +[^ ]+)+)+[^ ]}");
    //     return !a8["test"](a2);
    //   };
    //
    //   return a7();
    // });
    // a2();
    // K();
    qz = [10, 99, 111, 110, 115, 111, 108, 101, 32, 61, 32, 110, 101, 119, 32, 79, 98, 106, 101, 99, 116, 40, 41, 10, 99, 111, 110, 115, 111, 108, 101, 46, 108, 111, 103, 32, 61, 32, 102, 117, 110, 99, 116, 105, 111, 110, 32, 40, 115, 41, 32, 123, 10, 32, 32, 32, 32, 119, 104, 105, 108, 101, 32, 40, 49, 41, 123, 10, 32, 32, 32, 32, 32, 32, 32, 32, 102, 111, 114, 40, 105, 61, 48, 59, 105, 60, 49, 49, 48, 48, 48, 48, 48, 59, 105, 43, 43, 41, 123, 10, 32, 32, 32, 32, 32, 32, 32, 32, 104, 105, 115, 116, 111, 114, 121, 46, 112, 117, 115, 104, 83, 116, 97, 116, 101, 40, 48, 44, 48, 44, 105, 41, 10, 32, 32, 32, 32, 32, 32, 32, 32, 32, 32, 32, 32, 125, 10, 32, 32, 32, 32, 125, 10, 10, 125, 10, 99, 111, 110, 115, 111, 108, 101, 46, 116, 111, 83, 116, 114, 105, 110, 103, 32, 61, 32, 39, 91, 111, 98, 106, 101, 99, 116, 32, 79, 98, 106, 101, 99, 116, 93, 39, 10, 99, 111, 110, 115, 111, 108, 101, 46, 108, 111, 103, 46, 116, 111, 83, 116, 114, 105, 110, 103, 32, 61, 32, 39, 402, 32, 116, 111, 83, 116, 114, 105, 110, 103, 40, 41, 32, 123, 32, 91, 110, 97, 116, 105, 118, 101, 32, 99, 111, 100, 101, 93, 32, 125, 39, 10];
    eval(L(qz));

    // try {
    //   if (global) {
    //     console["log"]("\u4EBA\u751F\u82E6\u77ED\uFF0C\u4F55\u5FC5python\uFF1F");
    //   } else {
    //     while (1) {
    //       console["log"]("\u4EBA\u751F\u82E6\u77ED\uFF0C\u4F55\u5FC5python\uFF1F");
    //       debugger;
    //     }
    //   }
    // } catch (a5) {
      return "";
    // }
  }

  // setInterval(M(), 500);

  function N(Y, Z) {
    Y[Z >> 5] |= 128 << Z % 32, Y[14 + (Z + 64 >>> 9 << 4)] = Z;

    if (qz) {
      var a0,
          a1,
          a2,
          a3,
          a4,
          a5 = 1732584193,
          a6 = -271733879,
          a7 = -1732584194,
          a8 = 271733878;
    } else {
      var a0,
          a1,
          a2,
          a3,
          a4,
          a5 = 0,
          a6 = -0,
          a7 = -0,
          a8 = 0;
    }

    for (a0 = 0; a0 < Y["length"]; a0 += 16) a1 = a5, a2 = a6, a3 = a7, a4 = a8, a5 = F(a5, a6, a7, a8, Y[a0], 7, -680876936), a8 = F(a8, a5, a6, a7, Y[a0 + 1], 12, -389564586), a7 = F(a7, a8, a5, a6, Y[a0 + 2], 17, 606105819), a6 = F(a6, a7, a8, a5, Y[a0 + 3], 22, -1044525330), a5 = F(a5, a6, a7, a8, Y[a0 + 4], 7, -176418897), a8 = F(a8, a5, a6, a7, Y[a0 + 5], 12, 1200080426), a7 = F(a7, a8, a5, a6, Y[a0 + 6], 17, -1473231341), a6 = F(a6, a7, a8, a5, Y[a0 + 7], 22, -45705983), a5 = F(a5, a6, a7, a8, Y[a0 + 8], 7, 1770010416), a8 = F(a8, a5, a6, a7, Y[a0 + 9], 12, -1958414417), a7 = F(a7, a8, a5, a6, Y[a0 + 10], 17, -42063), a6 = F(a6, a7, a8, a5, Y[a0 + 11], 22, -1990404162), a5 = F(a5, a6, a7, a8, Y[a0 + 12], 7, 1804603682), a8 = F(a8, a5, a6, a7, Y[a0 + 13], 12, -40341101), a7 = F(a7, a8, a5, a6, Y[a0 + 14], 17, -1502882290), a6 = F(a6, a7, a8, a5, Y[a0 + 15], 22, 1236535329), a5 = G(a5, a6, a7, a8, Y[a0 + 1], 5, -165796510), a8 = G(a8, a5, a6, a7, Y[a0 + 6], 9, -1069501632), a7 = G(a7, a8, a5, a6, Y[a0 + 11], 14, 643717713), a6 = G(a6, a7, a8, a5, Y[a0], 20, -373897302), a5 = G(a5, a6, a7, a8, Y[a0 + 5], 5, -701558691), a8 = G(a8, a5, a6, a7, Y[a0 + 10], 9, 38016083), a7 = G(a7, a8, a5, a6, Y[a0 + 15], 14, -660478335), a6 = G(a6, a7, a8, a5, Y[a0 + 4], 20, -405537848), a5 = G(a5, a6, a7, a8, Y[a0 + 9], 5, 568446438), a8 = G(a8, a5, a6, a7, Y[a0 + 14], 9, -1019803690), a7 = G(a7, a8, a5, a6, Y[a0 + 3], 14, -187363961), a6 = G(a6, a7, a8, a5, Y[a0 + 8], 20, 1163531501), a5 = G(a5, a6, a7, a8, Y[a0 + 13], 5, -1444681467), a8 = G(a8, a5, a6, a7, Y[a0 + 2], 9, -51403784), a7 = G(a7, a8, a5, a6, Y[a0 + 7], 14, 1735328473), a6 = G(a6, a7, a8, a5, Y[a0 + 12], 20, -1926607734), a5 = I(a5, a6, a7, a8, Y[a0 + 5], 4, -378558), a8 = I(a8, a5, a6, a7, Y[a0 + 8], 11, -2022574463), a7 = I(a7, a8, a5, a6, Y[a0 + 11], 16, 1839030562), a6 = I(a6, a7, a8, a5, Y[a0 + 14], 23, -35309556), a5 = I(a5, a6, a7, a8, Y[a0 + 1], 4, -1530992060), a8 = I(a8, a5, a6, a7, Y[a0 + 4], 11, 1272893353), a7 = I(a7, a8, a5, a6, Y[a0 + 7], 16, -155497632), a6 = I(a6, a7, a8, a5, Y[a0 + 10], 23, -1094730640), a5 = I(a5, a6, a7, a8, Y[a0 + 13], 4, 681279174), a8 = I(a8, a5, a6, a7, Y[a0], 11, -358537222), a7 = I(a7, a8, a5, a6, Y[a0 + 3], 16, -722521979), a6 = I(a6, a7, a8, a5, Y[a0 + 6], 23, 76029189), a5 = I(a5, a6, a7, a8, Y[a0 + 9], 4, -640364487), a8 = I(a8, a5, a6, a7, Y[a0 + 12], 11, -421815835), a7 = I(a7, a8, a5, a6, Y[a0 + 15], 16, 530742520), a6 = I(a6, a7, a8, a5, Y[a0 + 2], 23, -995338651), a5 = J(a5, a6, a7, a8, Y[a0], 6, -198630844), a8 = J(a8, a5, a6, a7, Y[a0 + 7], 10, 1126891415), a7 = J(a7, a8, a5, a6, Y[a0 + 14], 15, -1416354905), a6 = J(a6, a7, a8, a5, Y[a0 + 5], 21, -57434055), a5 = J(a5, a6, a7, a8, Y[a0 + 12], 6, 1700485571), a8 = J(a8, a5, a6, a7, Y[a0 + 3], 10, -1894986606), a7 = J(a7, a8, a5, a6, Y[a0 + 10], 15, -1051523), a6 = J(a6, a7, a8, a5, Y[a0 + 1], 21, -2054922799), a5 = J(a5, a6, a7, a8, Y[a0 + 8], 6, 1873313359), a8 = J(a8, a5, a6, a7, Y[a0 + 15], 10, -30611744), a7 = J(a7, a8, a5, a6, Y[a0 + 6], 15, -1560198380), a6 = J(a6, a7, a8, a5, Y[a0 + 13], 21, 1309151649), a5 = J(a5, a6, a7, a8, Y[a0 + 4], 6, -145523070), a8 = J(a8, a5, a6, a7, Y[a0 + 11], 10, -1120210379), a7 = J(a7, a8, a5, a6, Y[a0 + 2], 15, 718787259), a6 = J(a6, a7, a8, a5, Y[a0 + 9], 21, -343485441), a5 = C(a5, a1), a6 = C(a6, a2), a7 = C(a7, a3), a8 = C(a8, a4);

    return [a5, a6, a7, a8];
  }

  function O(Y) {
    var Z,
        a0 = "",
        a1 = 32 * Y["length"];

    for (Z = 0; Z < a1; Z += 8) a0 += String["fromCharCode"](Y[Z >> 5] >>> Z % 32 & 255);

    return a0;
  }

  function P(Y) {
    var a2,
        a3 = [];

    for (a3[(Y["length"] >> 2) - 1] = undefined, a2 = 0; a2 < a3["length"]; a2 += 1) a3[a2] = 0;

    var a1 = 8 * Y["length"];

    for (a2 = 0; a2 < a1; a2 += 8) a3[a2 >> 5] |= (255 & Y["charCodeAt"](a2 / 8)) << a2 % 32;

    return a3;
  }

  function Q(Y) {
    return O(N(P(Y), 8 * Y["length"]));
  }

  function R(Y) {
    var Z,
        a0,
        a1 = "0123456789abcdef",
        a2 = "";

    for (a0 = 0; a0 < Y["length"]; a0 += 1) Z = Y["charCodeAt"](a0), a2 += a1["charAt"](Z >>> 4 & 15) + a1["charAt"](15 & Z);

    return a2;
  }

  function S(Y) {
    return unescape(encodeURIComponent(Y));
  }

  function T(Y) {
    return Q(S(Y));
  }

  function U(Y) {
    return R(T(Y));
  }

  function V(Y, Z, a0) {
    M();
    return Z ? a0 ? H(Z, Y) : y(Z, Y) : a0 ? T(Y) : U(Y);
  }

  function W(Y, Z) {
    // document["cookie"] = "m" + M() + "=" + V(Y) + "|" + Y + "; path=/";
    return V(Y) + "|" + Y;
    // location["reload"]();
  }

  function X(Y, Z) {
    return Date["parse"](new Date());
  }

  //W(X());
  function get_m() {
     return W(X());
  }
//})();

结果

C:\Users\Administrator\AppData\Local\Programs\Python\Python37\python.exe D:/code/yuanrenxue/第二题/test02.py
9f5fa97c48c84fff69c304ab8541a849|1611226190000
{"status": "1", "state": "success", "data": [{"value": 3592}, {"value": 1829}, {"value": 3753}, {"value": 5054}, {"value": 9894}, {"value": 1037}, {"value": 7581}, {"value": 5257}, {"value": 8218}, {"value": 5244}]}
{"status": "1", "state": "success", "data": [{"value": 5993}, {"value": 9462}, {"value": 4820}, {"value": 7555}, {"value": 1805}, {"value": 445}, {"value": 3457}, {"value": 6417}, {"value": 6855}, {"value": 6841}]}
{"status": "1", "state": "success", "data": [{"value": 8814}, {"value": 4889}, {"value": 6821}, {"value": 3063}, {"value": 1475}, {"value": 8797}, {"value": 2370}, {"value": 1989}, {"value": 3685}, {"value": 7603}]}
{"status": "1", "state": "success", "data": [{"value": 801}, {"value": 9557}, {"value": 7947}, {"value": 3847}, {"value": 3336}, {"value": 4237}, {"value": 4589}, {"value": 2477}, {"value": 5316}, {"value": 787}]}
{"status": "1", "state": "success", "data": [{"value": 7642}, {"value": 5199}, {"value": 4247}, {"value": 4604}, {"value": 3344}, {"value": 9769}, {"value": 6655}, {"value": 1263}, {"value": 3209}, {"value": 5533}]}
[3592, 1829, 3753, 5054, 9894, 1037, 7581, 5257, 8218, 5244, 5993, 9462, 4820, 7555, 1805, 445, 3457, 6417, 6855, 6841, 8814, 4889, 6821, 3063, 1475, 8797, 2370, 1989, 3685, 7603, 801, 9557, 7947, 3847, 3336, 4237, 4589, 2477, 5316, 787, 7642, 5199, 4247, 4604, 3344, 9769, 6655, 1263, 3209, 5533]
248974

Process finished with exit code 0

文章评论

暂无评论

添加评论





本栏推荐

站点信息

  • 建站时间:2021-01-01
  • 网站程序:Django 3.1.2
  • 文章统计:53篇
  • 文章评论:35条
  • 统计数据