Debugging stuff.

This commit is contained in:
Adam
2015-07-12 21:43:40 -04:00
parent ec50303962
commit b7d4d4981f
16 changed files with 113 additions and 54 deletions

View File

@@ -14,12 +14,12 @@ import info.sigterm.deob.execution.Frame;
import info.sigterm.deob.pool.NameAndType; import info.sigterm.deob.pool.NameAndType;
import info.sigterm.deob.signature.Signature; import info.sigterm.deob.signature.Signature;
import info.sigterm.deob.attributes.Code; import info.sigterm.deob.attributes.Code;
import info.sigterm.deob.attributes.code.Block;
import info.sigterm.deob.attributes.code.Instruction; import info.sigterm.deob.attributes.code.Instruction;
import info.sigterm.deob.attributes.code.Instructions; import info.sigterm.deob.attributes.code.Instructions;
import info.sigterm.deob.attributes.code.instructions.Goto; import info.sigterm.deob.attributes.code.instructions.Goto;
import info.sigterm.deob.attributes.code.instructions.GotoW; import info.sigterm.deob.attributes.code.instructions.GotoW;
import info.sigterm.deob.attributes.code.instructions.Return; import info.sigterm.deob.attributes.code.instructions.Return;
import info.sigterm.deob.block.Block;
import java.io.ByteArrayOutputStream; import java.io.ByteArrayOutputStream;
import java.io.DataInputStream; import java.io.DataInputStream;
@@ -47,29 +47,29 @@ public class Deob
new RuntimeExceptions().run(group); new RuntimeExceptions().run(group);
// the blocks of runtime exceptions may contain interesting things like other obfuscations we identify later, but now that // the blocks of runtime exceptions may contain interesting things like other obfuscations we identify later, but now that
// it can't be reached by the execution phase, those things become confused. so remove blocks here. // it can't be reached by the execution phase, those things become confused. so remove blocks here.
//new UnusedBlocks().run(group); new UnusedBlocks().run(group);
// remove unused methods // remove unused methods
//new UnusedMethods().run(group); new UnusedMethods().run(group);
// remove illegal state exceptions, frees up some parameters // remove illegal state exceptions, frees up some parameters
//new IllegalStateExceptions().run(group); new IllegalStateExceptions().run(group);
// remove unhit blocks // remove unhit blocks
//new UnusedBlocks().run(group); new UnusedBlocks().run(group);
// remove unused parameters // remove unused parameters
//new UnusedParameters().run(group); new UnusedParameters().run(group);
// remove jump obfuscation // remove jump obfuscation
new Jumps().run(group); new Jumps().run(group);
// remove unused fields // remove unused fields
//new UnusedFields().run(group); new UnusedFields().run(group);
//new ModularArithmeticDeobfuscation().run(group); //new ModularArithmeticDeobfuscation().run(group);
//new RenameUnique().run(group); new RenameUnique().run(group);
saveJar(group, args[1]); saveJar(group, args[1]);

View File

@@ -78,6 +78,11 @@ public class Field
return type; return type;
} }
public void setType(Type type)
{
this.type = type;
}
public Attributes getAttributes() public Attributes getAttributes()
{ {
return attributes; return attributes;

View File

@@ -35,13 +35,6 @@ public class Exception
assert start != null; assert start != null;
assert end != null; assert end != null;
assert handler != null; assert handler != null;
handler.exce.add(this);
}
protected void remove()
{
handler.exce.remove(this);
} }
public void write(DataOutputStream out) throws IOException public void write(DataOutputStream out) throws IOException
@@ -83,11 +76,7 @@ public class Exception
end = newi; end = newi;
if (handler == oldi) if (handler == oldi)
{
handler.exce.remove(this);
handler = newi; handler = newi;
handler.exce.add(this);
}
} }
public Class getCatchType() public Class getCatchType()

View File

@@ -28,7 +28,6 @@ public class Exceptions
public void remove(Exception e) public void remove(Exception e)
{ {
e.remove();
exceptions.remove(e); exceptions.remove(e);
} }

View File

@@ -4,6 +4,7 @@ import info.sigterm.deob.ClassFile;
import info.sigterm.deob.ConstantPool; import info.sigterm.deob.ConstantPool;
import info.sigterm.deob.Field; import info.sigterm.deob.Field;
import info.sigterm.deob.Method; import info.sigterm.deob.Method;
import info.sigterm.deob.block.Block;
import info.sigterm.deob.execution.Frame; import info.sigterm.deob.execution.Frame;
import java.io.DataOutputStream; import java.io.DataOutputStream;
@@ -22,7 +23,6 @@ public abstract class Instruction
public List<Instruction> jump = new ArrayList<>(), // instructions which this instruction jumps to public List<Instruction> jump = new ArrayList<>(), // instructions which this instruction jumps to
from = new ArrayList<>(); // instructions which jump to this instruction from = new ArrayList<>(); // instructions which jump to this instruction
public List<Exception> exce = new ArrayList<>(); // exception handlers which start here
public Instruction(Instructions instructions, InstructionType type, int pc) public Instruction(Instructions instructions, InstructionType type, int pc)
{ {
@@ -48,7 +48,6 @@ public abstract class Instruction
} }
assert from.isEmpty(); // because this is empty no jumping instructions point here assert from.isEmpty(); // because this is empty no jumping instructions point here
assert exce.isEmpty();
} }
public void replace(Instruction other) public void replace(Instruction other)
@@ -97,7 +96,6 @@ public abstract class Instruction
{ {
e.replace(this, other); e.replace(this, other);
} }
assert exce.isEmpty();
// replace ins // replace ins
int index = ins.indexOf(this); int index = ins.indexOf(this);

View File

@@ -5,6 +5,7 @@ import info.sigterm.deob.Field;
import info.sigterm.deob.Method; import info.sigterm.deob.Method;
import info.sigterm.deob.attributes.Code; import info.sigterm.deob.attributes.Code;
import info.sigterm.deob.attributes.code.instruction.types.JumpingInstruction; import info.sigterm.deob.attributes.code.instruction.types.JumpingInstruction;
import info.sigterm.deob.block.Block;
import java.io.ByteArrayOutputStream; import java.io.ByteArrayOutputStream;
import java.io.DataInputStream; import java.io.DataInputStream;

View File

@@ -66,16 +66,25 @@ public class GetField extends Instruction implements GetFieldInstruction
{ {
if (field.getClassEntry().getName().equals(cf.getName())) if (field.getClassEntry().getName().equals(cf.getName()))
field = new Field(new Class(name), field.getNameAndType()); field = new Field(new Class(name), field.getNameAndType());
if (field.getNameAndType().getDescriptorType().getType().equals("L" + cf.getName() + ";"))
field = new Field(field.getClassEntry(), new NameAndType(field.getNameAndType().getName(), new info.sigterm.deob.signature.Type("L" + name + ";", field.getNameAndType().getDescriptorType().getArrayDims())));
} }
@Override @Override
public void renameField(info.sigterm.deob.Field f, String name) public void renameField(info.sigterm.deob.Field f, String name)
{ {
if (field.getNameAndType().getName().equals(f.getName()) && field.getClassEntry().getName().equals(f.getFields().getClassFile().getName())) Class clazz = field.getClassEntry();
{ NameAndType nat = field.getNameAndType();
Class clazz = field.getClassEntry();
NameAndType nat = field.getNameAndType();
ClassFile cf = this.getInstructions().getCode().getAttributes().getClassFile().getGroup().findClass(clazz.getName());
if (cf == null)
return;
info.sigterm.deob.Field f2 = cf.findFieldDeep(nat);
if (f2 == f)
{
NameAndType newNat = new NameAndType(name, nat.getDescriptorType()); NameAndType newNat = new NameAndType(name, nat.getDescriptorType());
field = new Field(clazz, newNat); field = new Field(clazz, newNat);
} }

View File

@@ -79,16 +79,25 @@ public class GetStatic extends Instruction implements GetFieldInstruction
{ {
if (field.getClassEntry().getName().equals(cf.getName())) if (field.getClassEntry().getName().equals(cf.getName()))
field = new Field(new Class(name), field.getNameAndType()); field = new Field(new Class(name), field.getNameAndType());
if (field.getNameAndType().getDescriptorType().getType().equals("L" + cf.getName() + ";"))
field = new Field(field.getClassEntry(), new NameAndType(field.getNameAndType().getName(), new info.sigterm.deob.signature.Type("L" + name + ";", field.getNameAndType().getDescriptorType().getArrayDims())));
} }
@Override @Override
public void renameField(info.sigterm.deob.Field f, String name) public void renameField(info.sigterm.deob.Field f, String name)
{ {
if (field.getNameAndType().getName().equals(f.getName()) && field.getClassEntry().getName().equals(f.getFields().getClassFile().getName())) Class clazz = field.getClassEntry();
{ NameAndType nat = field.getNameAndType();
Class clazz = field.getClassEntry();
NameAndType nat = field.getNameAndType();
ClassFile cf = this.getInstructions().getCode().getAttributes().getClassFile().getGroup().findClass(clazz.getName());
if (cf == null)
return;
info.sigterm.deob.Field f2 = cf.findFieldDeep(nat);
if (f2 == f)
{
NameAndType newNat = new NameAndType(name, nat.getDescriptorType()); NameAndType newNat = new NameAndType(name, nat.getDescriptorType());
field = new Field(clazz, newNat); field = new Field(clazz, newNat);
} }

View File

@@ -62,7 +62,9 @@ public class MultiANewArray extends Instruction
@Override @Override
public void renameClass(ClassFile cf, String name) public void renameClass(ClassFile cf, String name)
{ {
if (clazz.getName().equals(cf.getName())) // class is an array type, ugh.
clazz = new Class(name); info.sigterm.deob.signature.Type t = new info.sigterm.deob.signature.Type(cf.getName());
if (t.getType().equals(cf.getName()))
clazz = new Class(name, t.getArrayDims());
} }
} }

View File

@@ -61,16 +61,25 @@ public class PutField extends Instruction implements SetFieldInstruction
{ {
if (field.getClassEntry().getName().equals(cf.getName())) if (field.getClassEntry().getName().equals(cf.getName()))
field = new Field(new Class(name), field.getNameAndType()); field = new Field(new Class(name), field.getNameAndType());
if (field.getNameAndType().getDescriptorType().getType().equals("L" + cf.getName() + ";"))
field = new Field(field.getClassEntry(), new NameAndType(field.getNameAndType().getName(), new info.sigterm.deob.signature.Type("L" + name + ";", field.getNameAndType().getDescriptorType().getArrayDims())));
} }
@Override @Override
public void renameField(info.sigterm.deob.Field f, String name) public void renameField(info.sigterm.deob.Field f, String name)
{ {
if (field.getNameAndType().getName().equals(f.getName()) && field.getClassEntry().getName().equals(f.getFields().getClassFile().getName())) Class clazz = field.getClassEntry();
{ NameAndType nat = field.getNameAndType();
Class clazz = field.getClassEntry();
NameAndType nat = field.getNameAndType();
ClassFile cf = this.getInstructions().getCode().getAttributes().getClassFile().getGroup().findClass(clazz.getName());
if (cf == null)
return;
info.sigterm.deob.Field f2 = cf.findFieldDeep(nat);
if (f2 == f)
{
NameAndType newNat = new NameAndType(name, nat.getDescriptorType()); NameAndType newNat = new NameAndType(name, nat.getDescriptorType());
field = new Field(clazz, newNat); field = new Field(clazz, newNat);
} }

View File

@@ -60,16 +60,25 @@ public class PutStatic extends Instruction implements SetFieldInstruction
{ {
if (field.getClassEntry().getName().equals(cf.getName())) if (field.getClassEntry().getName().equals(cf.getName()))
field = new Field(new Class(name), field.getNameAndType()); field = new Field(new Class(name), field.getNameAndType());
if (field.getNameAndType().getDescriptorType().getType().equals("L" + cf.getName() + ";"))
field = new Field(field.getClassEntry(), new NameAndType(field.getNameAndType().getName(), new info.sigterm.deob.signature.Type("L" + name + ";", field.getNameAndType().getDescriptorType().getArrayDims())));
} }
@Override @Override
public void renameField(info.sigterm.deob.Field f, String name) public void renameField(info.sigterm.deob.Field f, String name)
{ {
if (field.getNameAndType().getName().equals(f.getName()) && field.getClassEntry().getName().equals(f.getFields().getClassFile().getName())) Class clazz = field.getClassEntry();
{ NameAndType nat = field.getNameAndType();
Class clazz = field.getClassEntry();
NameAndType nat = field.getNameAndType();
ClassFile cf = this.getInstructions().getCode().getAttributes().getClassFile().getGroup().findClass(clazz.getName());
if (cf == null)
return;
info.sigterm.deob.Field f2 = cf.findFieldDeep(nat);
if (f2 == f)
{
NameAndType newNat = new NameAndType(name, nat.getDescriptorType()); NameAndType newNat = new NameAndType(name, nat.getDescriptorType());
field = new Field(clazz, newNat); field = new Field(clazz, newNat);
} }

View File

@@ -1,4 +1,7 @@
package info.sigterm.deob.attributes.code; package info.sigterm.deob.block;
import info.sigterm.deob.attributes.code.Exception;
import info.sigterm.deob.attributes.code.Instruction;
import java.util.ArrayList; import java.util.ArrayList;
import java.util.List; import java.util.List;

View File

@@ -4,11 +4,11 @@ import info.sigterm.deob.ClassFile;
import info.sigterm.deob.ClassGroup; import info.sigterm.deob.ClassGroup;
import info.sigterm.deob.Deobfuscator; import info.sigterm.deob.Deobfuscator;
import info.sigterm.deob.Method; import info.sigterm.deob.Method;
import info.sigterm.deob.attributes.code.Block;
import info.sigterm.deob.attributes.code.Instruction; import info.sigterm.deob.attributes.code.Instruction;
import info.sigterm.deob.attributes.code.Instructions; import info.sigterm.deob.attributes.code.Instructions;
import info.sigterm.deob.attributes.code.instructions.Goto; import info.sigterm.deob.attributes.code.instructions.Goto;
import info.sigterm.deob.attributes.code.instructions.GotoW; import info.sigterm.deob.attributes.code.instructions.GotoW;
import info.sigterm.deob.block.Block;
import java.util.ArrayList; import java.util.ArrayList;
import java.util.List; import java.util.List;

View File

@@ -72,6 +72,11 @@ public class RenameUnique implements Deobfuscator
if (method.getExceptions() != null) if (method.getExceptions() != null)
method.getExceptions().renameClass(cf, name); method.getExceptions().renameClass(cf, name);
} }
// rename on fields
for (Field field : c.getFields().getFields())
if (field.getType().getType().equals("L" + cf.getName() + ";"))
field.setType(new Type("L" + name + ";", field.getType().getArrayDims()));
} }
cf.setName(name); cf.setName(name);

View File

@@ -4,17 +4,16 @@ import info.sigterm.deob.ClassFile;
import info.sigterm.deob.ClassGroup; import info.sigterm.deob.ClassGroup;
import info.sigterm.deob.Deobfuscator; import info.sigterm.deob.Deobfuscator;
import info.sigterm.deob.Method; import info.sigterm.deob.Method;
import info.sigterm.deob.attributes.code.Block;
import info.sigterm.deob.attributes.code.Instructions; import info.sigterm.deob.attributes.code.Instructions;
import info.sigterm.deob.block.Block;
import java.util.ArrayList; import java.util.ArrayList;
public class UnusedBlocks implements Deobfuscator public class UnusedBlocks implements Deobfuscator
{ {
@Override public int pass(ClassGroup group)
public void run(ClassGroup group)
{ {
int i = 0; int removed = 0;
for (ClassFile cf : group.getClasses()) for (ClassFile cf : group.getClasses())
{ {
for (Method m : new ArrayList<>(cf.getMethods().getMethods())) for (Method m : new ArrayList<>(cf.getMethods().getMethods()))
@@ -25,21 +24,33 @@ public class UnusedBlocks implements Deobfuscator
Instructions ins = m.getCode().getInstructions(); Instructions ins = m.getCode().getInstructions();
ins.buildBlocks(); ins.buildBlocks();
int count = 0; for (int i = 0; i < ins.getBlocks().size(); ++i)
for (Block b : new ArrayList<>(ins.getBlocks()))
{ {
Block block = ins.getBlocks().get(i);
// first block is the entrypoint, so its always used // first block is the entrypoint, so its always used
if (count++ == 0) if (i == 0)
continue; continue;
if (b.begin.from.isEmpty() && b.begin.exce.isEmpty()) Block prev = ins.getBlocks().get(i - 1);
if (prev.end.isTerminal() && block.begin.from.isEmpty() && block.handlers.isEmpty())
{ {
ins.remove(b); ins.remove(block);
++i; ++removed;
break;
} }
} }
} }
} }
System.out.println("Removed " + i + " unused blocks");
System.out.println("Removed " + removed + " unused blocks");
return removed;
}
@Override
public void run(ClassGroup group)
{
while (pass(group) > 0);
} }
} }

View File

@@ -27,6 +27,16 @@ public class Class extends PoolEntry
this.name = name; this.name = name;
} }
public Class(java.lang.String name, int dimms)
{
super(ConstantType.CLASS);
while (dimms-- > 0)
name = "[" + name;
this.name = name;
}
@Override @Override
public void resolve(ConstantPool pool) public void resolve(ConstantPool pool)
{ {