如何使用Zelix KlassMaster混淆Spring Boot应用?求助解决Spring Boot场景下的混淆问题及ZKM脚本示例
我之前在给Spring Boot项目做混淆的时候,也踩过Zelix KlassMaster的坑——毕竟Spring Boot的自动配置和反射依赖太多,和标准Maven项目的混淆规则差异很大。给你分享一个我验证过的ZKM脚本示例,再讲几个关键的注意事项,应该能解决你的问题:
完整ZKM脚本示例
# 1. 指定输入输出路径(替换成你的实际Jar路径) inpath "target/your-app-1.0.0.jar"; outpath "target/your-app-obfuscated.jar"; # 2. 保留Spring Boot应用主类及main方法(必须替换成你的主类全限定名) keep class com.yourcompany.yourapp.YourApplication { public static void main(java.lang.String[]); } # 3. 保留Spring核心框架类,避免反射失效 keep class org.springframework.boot.** { *; } keep class org.springframework.context.** { *; } keep class org.springframework.beans.** { *; } # 4. 保留带有Spring注解的Bean类及公共方法 # Spring需要通过注解扫描识别这些类,不能混淆 keep class * { @org.springframework.stereotype.Controller <methods>; @org.springframework.web.bind.annotation.RestController <methods>; @org.springframework.stereotype.Service <methods>; @org.springframework.stereotype.Repository <methods>; } # 5. 保留请求映射相关的方法(@GetMapping/@PostMapping等) # 这些方法是对外API的入口,混淆后前端会找不到对应接口 keep class * { @org.springframework.web.bind.annotation.RequestMapping <methods>; @org.springframework.web.bind.annotation.GetMapping <methods>; @org.springframework.web.bind.annotation.PostMapping <methods>; } # 6. 开启字符串混淆(这正是你需要的ProGuard不具备的功能) obfuscate strings; # 7. 混淆类名、方法名、字段名(自定义命名规则,$c/$m/$f是ZKM内置变量) obfuscate classes rename: "$c"; obfuscate methods rename: "$m"; obfuscate fields rename: "$f"; # 8. 保留Spring Boot启动必需的资源文件 keep resource "META-INF/MANIFEST.MF"; keep resource "META-INF/spring.factories"; keep resource "META-INF/spring/org.springframework.boot.autoconfigure.AutoConfiguration.imports";
关键规则解释
- 主类必须保留:Spring Boot的入口main方法是启动的核心,混淆后会导致无法找到启动类
- Spring核心类不能混淆:Spring大量使用反射加载Bean、处理自动配置,混淆这些类会直接导致启动失败
- 注解相关的类/方法要保留:Spring通过注解扫描识别业务Bean和接口,混淆后扫描不到会出现BeanNotFound等错误
- 资源文件别漏了:
spring.factories和自动配置导入文件是Spring Boot自动配置的关键,删除或混淆后会丢失配置
额外排查建议
- 如果启动后出现
ClassNotFoundException或NoSuchMethodException,把报错的类/方法加入keep规则 - 如果你用了MyBatis、Redis等第三方框架,也要保留对应的核心类(比如MyBatis的Mapper接口)
- 可以在脚本开头加
print warnings;,ZKM会输出混淆过程中的警告,帮助你定位哪些类可能被误混淆
内容的提问来源于stack exchange,提问作者Danrley Brasil dos Santos
相关产品推荐
相关产品推荐

