如何在 iOS 的 React-Native 中混淆代码

Hal*_*ğan 5 javascript obfuscation react-native

我一直在尝试使用react-native-obfuscating-transformer来混淆代码一段时间。一切看起来都很好,但是当我检查bundle.js 时。我看不到任何混淆的代码。

PS:目前我只尝试IOS。

这是我的配置文件。

地铁配置.js


module.exports = {
    transformer: {
        babelTransformerPath: require.resolve('./transformer'),
        getTransformOptions: async () => ({
            transform: {
                experimentalImportSupport: false,
                inlineRequires: false,
            },
        }),
    },
};

Run Code Online (Sandbox Code Playgroud)

变压器.js

const obfuscatingTransformer = require('react-native-obfuscating-transformer');

module.exports = obfuscatingTransformer({
    upstreamTransformer: require('metro-react-native-babel-transformer'),
    enableInDevelopment: true,
    obfuscatorOptions: {
        compact: true,
        controlFlowFlattening: true,
        controlFlowFlatteningThreshold: 0.75,
        deadCodeInjection: true,
        deadCodeInjectionThreshold: 0.4,
        debugProtection: false,
        debugProtectionInterval: false,
        disableConsoleOutput: true,
        identifierNamesGenerator: 'hexadecimal',
        log: false,
        numbersToExpressions: true,
        renameGlobals: false,
        rotateStringArray: true,
        selfDefending: true,
        shuffleStringArray: true,
        simplify: true,
        splitStrings: true,
        splitStringsChunkLength: 10,
        stringArray: true,
        stringArrayEncoding: ['base64'],
        stringArrayWrappersCount: 2,
        stringArrayWrappersChainedCalls: true,
        stringArrayWrappersType: 'variable',
        stringArrayThreshold: 0.75,
        transformObjectKeys: true,
        unicodeEscapeSequence: false,
    },
});

Run Code Online (Sandbox Code Playgroud)

Muh*_*man 4

经过多次测试,我终于弄清楚了如何让它发挥作用。

我的反应和反应本机版本:

 "react": "16.9.0",
 "react-native": "0.61.5",
Run Code Online (Sandbox Code Playgroud)

安装所需的其他依赖项:

npm install babylon --save
npm install --save babel-traverse
Run Code Online (Sandbox Code Playgroud)

变压器.js

const obfuscatingTransformer = require("react-native-obfuscating-transformer")
const filter = filename => { 
  return filename.startsWith("src");
};

module.exports = obfuscatingTransformer({
// this configuration is based on https://github.com/javascript-obfuscator/javascript-obfuscator
  obfuscatorOptions:{
    compact: true,
    controlFlowFlattening: false,
    deadCodeInjection: false,
    debugProtection: false,
    debugProtectionInterval: false,
    disableConsoleOutput: true,
    identifierNamesGenerator: 'hexadecimal',
    log: false,
    renameGlobals: false,
    rotateStringArray: true,
    selfDefending: true,
    shuffleStringArray: true,
    splitStrings: false,
    stringArray: true,
    stringArrayEncoding: ['base64'],
    stringArrayThreshold: 0.75,
    unicodeEscapeSequence: false
  },
  upstreamTransformer: require('metro-react-native-babel-transformer'),
  emitObfuscatedFiles: false,
  enableInDevelopment: true,
  filter: filter,
  trace: true
})
Run Code Online (Sandbox Code Playgroud)

地铁配置.js

module.exports = {
  transformer: {
    getTransformOptions: async () => ({
      transform: {
        experimentalImportSupport: false,
        inlineRequires: false,
      },
    }),
    babelTransformerPath: require.resolve("./transformer")   // add here the transformer.js
  },
};
Run Code Online (Sandbox Code Playgroud)

笔记:

在obfuscatorOptions中将emitObfuscatedFiles设置为true,以将文件的混淆版本与原始文件一起发出,以进行比较。

如果您在发布版本中构建,您还可以使用和不使用react-native-obfuscating-transformer来比较生成的index.android.bundle (位于\android\app\build\ generated\assets\react\release)在线 diff 工具查看差异