JS逆向练习-某微公众号平台登录

今天我们来练习模拟实现登录

网址: https://mp.weixin.qq.com

老规矩按F12进行抓包,发现pwd进行加密,发现长度好像是32位,那几乎可以确定是md5加密了。
在这里插入图片描述
在这里插入图片描述

点击启动器点击login进去或者直接搜索pwd都可

在这里插入图片描述
下断点发现pwd是m这个函数方法进行加密的,里面的参数就是我们输入的明文密码,js中的substr函数类似于python中的slice切片,具体用法如下:
在这里插入图片描述
JavaScript中的substr()函数用于提取字符串中的一部分,并返回提取后的子字符串。它有两个参数:起始索引和子字符串长度。

语法:string.substr(start, length)

参数:

  • start:必需。要提取的子字符串的起始索引位置。如果是负数,则从字符串末尾开始计算。
  • length:可选。提取的子字符串的长度。如果省略,则提取从起始位置到字符串末尾的所有字符。
  • 返回值:substr()函数返回提取后的子字符串。

示例:

var str = "Hello World!";
var res = str.substr(1, 4);
console.log(res); // "ello"

在这个例子中,从字符串的第二个字符开始提取长度为4的子字符串,因此返回"ello"。

这时为了检验是不是标准的MD5算法,我们用1进行试验,果然很biu准,没有进行任何加盐(指除了明文密码外,还掺杂了其他参数。常见的就是加时间戳)。注:怎么判断是否biu准,你可以在网页上找个在线的MD5加密网站对1加密两者进行对比。
在这里插入图片描述
知道了它是个标准的算法后,你有两种选择,一种拿网页的js代码算法进行模拟登录,第二种直接py导包模拟登录。今天我就直接扣代码,也不复杂。
在这里插入图片描述
这个t ? n ? i(t, e) : o(i(t, e)) : n ? r(e) : o(r(e)) 表达式是一个 JavaScript 的三元运算符,它可以写成如下的代码块:

if (t) {
    
    
    if (n) {
    
    
        return i(t, e);
    } else {
    
    
        return o(i(t, e));
    }
} else {
    
    
    if (n) {
    
    
        return r(e);
    } else {
    
    
        return o(r(e));
    }
}

具体来说,它的含义是:

如果 t 为真(即非 false 值),则判断 n 是否为真:

  • 如果 n 为真,则返回 i(t, e);
  • 如果 n 为假,则返回 o(i(t, e))。

如果 t 为假,则判断 n 是否为真:

  • 如果 n 为真,则返回 r(e);
  • 如果 n 为假,则返回 o(r(e))。
    其实算法就在这一个函数当中,直接扣下来!
    代码如下:
e = '123456'

function get_pwd(e, t, n) {
    
    
    function l(e, t) {
    
    
        var n = (65535 & e) + (65535 & t);
        return (e >> 16) + (t >> 16) + (n >> 16) << 16 | 65535 & n
    }
    
    function a(e, t, n, o, r, i) {
    
    
        return l((t = l(l(t, e), l(o, i))) << r | t >>> 32 - r, n)
    }
    
    function p(e, t, n, o, r, i, s) {
    
    
        return a(t & n | ~t & o, e, t, r, i, s)
    }
    
    function f(e, t, n, o, r, i, s) {
    
    
        return a(t & o | n & ~o, e, t, r, i, s)
    }
    
    function m(e, t, n, o, r, i, s) {
    
    
        return a(t ^ n ^ o, e, t, r, i, s)
    }
    
    function g(e, t, n, o, r, i, s) {
    
    
        return a(n ^ (t | ~o), e, t, r, i, s)
    }
    
    function s(e, t) {
    
    
        e[t >> 5] |= 128 << t % 32,
            e[14 + (t + 64 >>> 9 << 4)] = t;
        for (var n, o, r, d, i = 1732584193, s = -271733879, a = -1732584194, c = 271733878, u = 0; u < e.length; u += 16)
            i = p(n = i, o = s, r = a, d = c, e[u], 7, -680876936),
                c = p(c, i, s, a, e[u + 1], 12, -389564586),
                a = p(a, c, i, s, e[u + 2], 17, 606105819),
                s = p(s, a, c, i, e[u + 3], 22, -1044525330),
                i = p(i, s, a, c, e[u + 4], 7, -176418897),
                c = p(c, i, s, a, e[u + 5], 12, 1200080426),
                a = p(a, c, i, s, e[u + 6], 17, -1473231341),
                s = p(s, a, c, i, e[u + 7], 22, -45705983),
                i = p(i, s, a, c, e[u + 8], 7, 1770035416),
                c = p(c, i, s, a, e[u + 9], 12, -1958414417),
                a = p(a, c, i, s, e[u + 10], 17, -42063),
                s = p(s, a, c, i, e[u + 11], 22, -1990404162),
                i = p(i, s, a, c, e[u + 12], 7, 1804603682),
                c = p(c, i, s, a, e[u + 13], 12, -40341101),
                a = p(a, c, i, s, e[u + 14], 17, -1502002290),
                i = f(i, s = p(s, a, c, i, e[u + 15], 22, 1236535329), a, c, e[u + 1], 5, -165796510),
                c = f(c, i, s, a, e[u + 6], 9, -1069501632),
                a = f(a, c, i, s, e[u + 11], 14, 643717713),
                s = f(s, a, c, i, e[u], 20, -373897302),
                i = f(i, s, a, c, e[u + 5], 5, -701558691),
                c = f(c, i, s, a, e[u + 10], 9, 38016083),
                a = f(a, c, i, s, e[u + 15], 14, -660478335),
                s = f(s, a, c, i, e[u + 4], 20, -405537848),
                i = f(i, s, a, c, e[u + 9], 5, 568446438),
                c = f(c, i, s, a, e[u + 14], 9, -1019803690),
                a = f(a, c, i, s, e[u + 3], 14, -187363961),
                s = f(s, a, c, i, e[u + 8], 20, 1163531501),
                i = f(i, s, a, c, e[u + 13], 5, -1444681467),
                c = f(c, i, s, a, e[u + 2], 9, -51403784),
                a = f(a, c, i, s, e[u + 7], 14, 1735328473),
                i = m(i, s = f(s, a, c, i, e[u + 12], 20, -1926607734), a, c, e[u + 5], 4, -378558),
                c = m(c, i, s, a, e[u + 8], 11, -2022574463),
                a = m(a, c, i, s, e[u + 11], 16, 1839030562),
                s = m(s, a, c, i, e[u + 14], 23, -35309556),
                i = m(i, s, a, c, e[u + 1], 4, -1530992060),
                c = m(c, i, s, a, e[u + 4], 11, 1272893353),
                a = m(a, c, i, s, e[u + 7], 16, -155497632),
                s = m(s, a, c, i, e[u + 10], 23, -1094730640),
                i = m(i, s, a, c, e[u + 13], 4, 681279174),
                c = m(c, i, s, a, e[u], 11, -358537222),
                a = m(a, c, i, s, e[u + 3], 16, -722521979),
                s = m(s, a, c, i, e[u + 6], 23, 76029189),
                i = m(i, s, a, c, e[u + 9], 4, -640364487),
                c = m(c, i, s, a, e[u + 12], 11, -421815835),
                a = m(a, c, i, s, e[u + 15], 16, 530742520),
                i = g(i, s = m(s, a, c, i, e[u + 2], 23, -995338651), a, c, e[u], 6, -198630844),
                c = g(c, i, s, a, e[u + 7], 10, 1126891415),
                a = g(a, c, i, s, e[u + 14], 15, -1416354905),
                s = g(s, a, c, i, e[u + 5], 21, -57434055),
                i = g(i, s, a, c, e[u + 12], 6, 1700485571),
                c = g(c, i, s, a, e[u + 3], 10, -1894986606),
                a = g(a, c, i, s, e[u + 10], 15, -1051523),
                s = g(s, a, c, i, e[u + 1], 21, -2054922799),
                i = g(i, s, a, c, e[u + 8], 6, 1873313359),
                c = g(c, i, s, a, e[u + 15], 10, -30611744),
                a = g(a, c, i, s, e[u + 6], 15, -1560198380),
                s = g(s, a, c, i, e[u + 13], 21, 1309151649),
                i = g(i, s, a, c, e[u + 4], 6, -145523070),
                c = g(c, i, s, a, e[u + 11], 10, -1120210379),
                a = g(a, c, i, s, e[u + 2], 15, 718787259),
                s = g(s, a, c, i, e[u + 9], 21, -343485551),
                i = l(i, n),
                s = l(s, o),
                a = l(a, r),
                c = l(c, d);
        return [i, s, a, c]
    }
    
    function c(e) {
    
    
        for (var t = "", n = 0; n < 32 * e.length; n += 8)
            t += String.fromCharCode(e[n >> 5] >>> n % 32 & 255);
        return t
    }
    
    function u(e) {
    
    
        var t, n = [];
        for (n[(e.length >> 2) - 1] = void 0,
                 t = 0; t < n.length; t += 1)
            n[t] = 0;
        for (t = 0; t < 8 * e.length; t += 8)
            n[t >> 5] |= (255 & e.charCodeAt(t / 8)) << t % 32;
        return n
    }
    
    function o(e) {
    
    
        for (var t, n = "0123456789abcdef", o = "", r = 0; r < e.length; r += 1)
            t = e.charCodeAt(r),
                o += n.charAt(t >>> 4 & 15) + n.charAt(15 & t);
        return o
    }
    
    function d(e) {
    
    
        return unescape(encodeURIComponent(e))
    }
    
    function r(e) {
    
    
        return c(s(u(e = d(e)), 8 * e.length))
    }
    
    function i(e, t) {
    
    
        var n, e = d(e), t = d(t), o = u(e), r = [], i = [];
        for (r[15] = i[15] = void 0,
             16 < o.length && (o = s(o, 8 * e.length)),
                 n = 0; n < 16; n += 1)
            r[n] = 909522486 ^ o[n],
                i[n] = 1549556828 ^ o[n];
        return e = s(r.concat(u(t)), 512 + 8 * t.length),
            c(s(i.concat(e), 640))
    }
    
    return t ? n ? i(t, e) : o(i(t, e)) : n ? r(e) : o(r(e))
}

console.log(get_pwd(e.substr(0,16)))

结果如下:是不是跟之前一样
在这里插入图片描述
写py对于大家那不是手到擒来!
py模拟结果如下:
在这里插入图片描述
网页返回结果如下:如果两者一样说明模拟成功!
在这里插入图片描述

注:这个再给大家一个思路,这个也可以用webpack来扣算法
今天的练习就到这里

//webpack
window=global
var xixi;
!function (c) {
    
    
    function e(e) {
    
    
        for (var t, n, o = e[0], r = e[1], i = e[2], s = 0, a = []; s < o.length; s++)
            n = o[s],
            Object.prototype.hasOwnProperty.call(d, n) && d[n] && a.push(d[n][0]),
                d[n] = 0;
        for (t in r)
            Object.prototype.hasOwnProperty.call(r, t) && (c[t] = r[t]);
        for (p && p(e); a.length;)
            a.shift()();
        return l.push.apply(l, i || []),
            u()
    }

    function u() {
    
    
        for (var e, t = 0; t < l.length; t++) {
    
    
            for (var n = l[t], o = !0, r = 1; r < n.length; r++) {
    
    
                var i = n[r];
                0 !== d[i] && (o = !1)
            }
            o && (l.splice(t--, 1),
                e = s(s.s = n[0]))
        }
        return e
    }

    var n = {
    
    }
        , d = {
    
    
        "login/loginpage/loginpage": 0
    }
        , l = [];

    function s(e) {
    
    
        if (n[e])
            return n[e].exports;
        var t = n[e] = {
    
    
            i: e,
            l: !1,
            exports: {
    
    }
        };
        return c[e].call(t.exports, t, t.exports, s),
            t.l = !0,
            t.exports
    }

    s.m = c,
        s.c = n,
        s.d = function (e, t, n) {
    
    
            s.o(e, t) || Object.defineProperty(e, t, {
    
    
                enumerable: !0,
                get: n
            })
        }
        ,
        s.r = function (e) {
    
    
            "undefined" != typeof Symbol && Symbol.toStringTag && Object.defineProperty(e, Symbol.toStringTag, {
    
    
                value: "Module"
            }),
                Object.defineProperty(e, "__esModule", {
    
    
                    value: !0
                })
        }
        ,
        s.t = function (t, e) {
    
    
            if (1 & e && (t = s(t)),
            8 & e)
                return t;
            if (4 & e && "object" == typeof t && t && t.__esModule)
                return t;
            var n = Object.create(null);
            if (s.r(n),
                Object.defineProperty(n, "default", {
    
    
                    enumerable: !0,
                    value: t
                }),
            2 & e && "string" != typeof t)
                for (var o in t)
                    s.d(n, o, function (e) {
    
    
                        return t[e]
                    }
                        .bind(null, o));
            return n
        }
        ,
        s.n = function (e) {
    
    
            var t = e && e.__esModule ? function () {
    
    
                        return e.default
                    }
                    : function () {
    
    
                        return e
                    }
            ;
            return s.d(t, "a", t),
                t
        }
        ,
        s.o = function (e, t) {
    
    
            return Object.prototype.hasOwnProperty.call(e, t)
        }
        ,
        s.p = "/mpres/zh_CN/htmledition/";
    var r = (t = window.webpackJsonp = window.webpackJsonp || []).push.bind(t);
    t.push = e;
    for (var t = t.slice(), o = 0; o < t.length; o++)
        e(t[o]);
    var p = r;
    l.push([39, "pages/modules~advanced/menusetting/menusetting~advanced/menusetting4Web1~album/edit/edit~album/list/list~b~modules", "pages/vendors~advanced/components/switchGroup/switchGroup~advanced/menusetting/menusetting~advanced/menuse~vendors", "pages/vendors~advanced/menusetting/menusetting~advanced/menusetting4Web1~album/edit/edit~album/list/list~b~vendors", "pages/threerd~advanced/menusetting/menusetting~advanced/menusetting4Web1~album/edit/edit~album/list/list~b~threerd", "pages/threerd~advanced/menusetting/menusetting~advanced/menusetting4Web1~album/edit/edit~cardticket/member~threerd"]),
        //u()
    xixi=s
}(
    {
    
    
        md5:function(e, t, n) {
    
    
            "use strict";
            function l(e, t) {
    
    
                var n = (65535 & e) + (65535 & t);
                return (e >> 16) + (t >> 16) + (n >> 16) << 16 | 65535 & n
            }
            function a(e, t, n, o, r, i) {
    
    
                return l((t = l(l(t, e), l(o, i))) << r | t >>> 32 - r, n)
            }
            function p(e, t, n, o, r, i, s) {
    
    
                return a(t & n | ~t & o, e, t, r, i, s)
            }
            function f(e, t, n, o, r, i, s) {
    
    
                return a(t & o | n & ~o, e, t, r, i, s)
            }
            function m(e, t, n, o, r, i, s) {
    
    
                return a(t ^ n ^ o, e, t, r, i, s)
            }
            function g(e, t, n, o, r, i, s) {
    
    
                return a(n ^ (t | ~o), e, t, r, i, s)
            }
            function s(e, t) {
    
    
                e[t >> 5] |= 128 << t % 32,
                e[14 + (t + 64 >>> 9 << 4)] = t;
                for (var n, o, r, d, i = 1732584193, s = -271733879, a = -1732584194, c = 271733878, u = 0; u < e.length; u += 16)
                    i = p(n = i, o = s, r = a, d = c, e[u], 7, -680876936),
                    c = p(c, i, s, a, e[u + 1], 12, -389564586),
                    a = p(a, c, i, s, e[u + 2], 17, 606105819),
                    s = p(s, a, c, i, e[u + 3], 22, -1044525330),
                    i = p(i, s, a, c, e[u + 4], 7, -176418897),
                    c = p(c, i, s, a, e[u + 5], 12, 1200080426),
                    a = p(a, c, i, s, e[u + 6], 17, -1473231341),
                    s = p(s, a, c, i, e[u + 7], 22, -45705983),
                    i = p(i, s, a, c, e[u + 8], 7, 1770035416),
                    c = p(c, i, s, a, e[u + 9], 12, -1958414417),
                    a = p(a, c, i, s, e[u + 10], 17, -42063),
                    s = p(s, a, c, i, e[u + 11], 22, -1990404162),
                    i = p(i, s, a, c, e[u + 12], 7, 1804603682),
                    c = p(c, i, s, a, e[u + 13], 12, -40341101),
                    a = p(a, c, i, s, e[u + 14], 17, -1502002290),
                    i = f(i, s = p(s, a, c, i, e[u + 15], 22, 1236535329), a, c, e[u + 1], 5, -165796510),
                    c = f(c, i, s, a, e[u + 6], 9, -1069501632),
                    a = f(a, c, i, s, e[u + 11], 14, 643717713),
                    s = f(s, a, c, i, e[u], 20, -373897302),
                    i = f(i, s, a, c, e[u + 5], 5, -701558691),
                    c = f(c, i, s, a, e[u + 10], 9, 38016083),
                    a = f(a, c, i, s, e[u + 15], 14, -660478335),
                    s = f(s, a, c, i, e[u + 4], 20, -405537848),
                    i = f(i, s, a, c, e[u + 9], 5, 568446438),
                    c = f(c, i, s, a, e[u + 14], 9, -1019803690),
                    a = f(a, c, i, s, e[u + 3], 14, -187363961),
                    s = f(s, a, c, i, e[u + 8], 20, 1163531501),
                    i = f(i, s, a, c, e[u + 13], 5, -1444681467),
                    c = f(c, i, s, a, e[u + 2], 9, -51403784),
                    a = f(a, c, i, s, e[u + 7], 14, 1735328473),
                    i = m(i, s = f(s, a, c, i, e[u + 12], 20, -1926607734), a, c, e[u + 5], 4, -378558),
                    c = m(c, i, s, a, e[u + 8], 11, -2022574463),
                    a = m(a, c, i, s, e[u + 11], 16, 1839030562),
                    s = m(s, a, c, i, e[u + 14], 23, -35309556),
                    i = m(i, s, a, c, e[u + 1], 4, -1530992060),
                    c = m(c, i, s, a, e[u + 4], 11, 1272893353),
                    a = m(a, c, i, s, e[u + 7], 16, -155497632),
                    s = m(s, a, c, i, e[u + 10], 23, -1094730640),
                    i = m(i, s, a, c, e[u + 13], 4, 681279174),
                    c = m(c, i, s, a, e[u], 11, -358537222),
                    a = m(a, c, i, s, e[u + 3], 16, -722521979),
                    s = m(s, a, c, i, e[u + 6], 23, 76029189),
                    i = m(i, s, a, c, e[u + 9], 4, -640364487),
                    c = m(c, i, s, a, e[u + 12], 11, -421815835),
                    a = m(a, c, i, s, e[u + 15], 16, 530742520),
                    i = g(i, s = m(s, a, c, i, e[u + 2], 23, -995338651), a, c, e[u], 6, -198630844),
                    c = g(c, i, s, a, e[u + 7], 10, 1126891415),
                    a = g(a, c, i, s, e[u + 14], 15, -1416354905),
                    s = g(s, a, c, i, e[u + 5], 21, -57434055),
                    i = g(i, s, a, c, e[u + 12], 6, 1700485571),
                    c = g(c, i, s, a, e[u + 3], 10, -1894986606),
                    a = g(a, c, i, s, e[u + 10], 15, -1051523),
                    s = g(s, a, c, i, e[u + 1], 21, -2054922799),
                    i = g(i, s, a, c, e[u + 8], 6, 1873313359),
                    c = g(c, i, s, a, e[u + 15], 10, -30611744),
                    a = g(a, c, i, s, e[u + 6], 15, -1560198380),
                    s = g(s, a, c, i, e[u + 13], 21, 1309151649),
                    i = g(i, s, a, c, e[u + 4], 6, -145523070),
                    c = g(c, i, s, a, e[u + 11], 10, -1120210379),
                    a = g(a, c, i, s, e[u + 2], 15, 718787259),
                    s = g(s, a, c, i, e[u + 9], 21, -343485551),
                    i = l(i, n),
                    s = l(s, o),
                    a = l(a, r),
                    c = l(c, d);
                return [i, s, a, c]
            }
            function c(e) {
    
    
                for (var t = "", n = 0; n < 32 * e.length; n += 8)
                    t += String.fromCharCode(e[n >> 5] >>> n % 32 & 255);
                return t
            }
            function u(e) {
    
    
                var t, n = [];
                for (n[(e.length >> 2) - 1] = void 0,
                t = 0; t < n.length; t += 1)
                    n[t] = 0;
                for (t = 0; t < 8 * e.length; t += 8)
                    n[t >> 5] |= (255 & e.charCodeAt(t / 8)) << t % 32;
                return n
            }
            function o(e) {
    
    
                for (var t, n = "0123456789abcdef", o = "", r = 0; r < e.length; r += 1)
                    t = e.charCodeAt(r),
                    o += n.charAt(t >>> 4 & 15) + n.charAt(15 & t);
                return o
            }
            function d(e) {
    
    
                return unescape(encodeURIComponent(e))
            }
            function r(e) {
    
    
                return c(s(u(e = d(e)), 8 * e.length))
            }
            function i(e, t) {
    
    
                var n, e = d(e), t = d(t), o = u(e), r = [], i = [];
                for (r[15] = i[15] = void 0,
                16 < o.length && (o = s(o, 8 * e.length)),
                n = 0; n < 16; n += 1)
                    r[n] = 909522486 ^ o[n],
                    i[n] = 1549556828 ^ o[n];
                return e = s(r.concat(u(t)), 512 + 8 * t.length),
                c(s(i.concat(e), 640))
            }
            return t ? n ? i(t, e) : o(i(t, e)) : n ? r(e) : o(r(e))
        }
    }

)
console.log(xixi.m.md5(e.substr(0,16)))

猜你喜欢

转载自blog.csdn.net/qq_69218005/article/details/129974351