如何实现后台向指定网站提交代码并获取混淆结果?
How to Automate JavaScript Obfuscation via cleancss.com (Headless, No Browser)
Hey there! Don't stress about the language barrier at all—totally get it. Let's figure out how to send your JS code to that obfuscation tool and grab the result without popping open a browser. The key here is mimicking the form submission your browser does using HTTP requests in code. Here's a step-by-step breakdown:
Step 1: Inspect the Site's Form Submission
First, we need to know exactly what data the browser sends when you click "Obfuscate":
- Open the site in your browser, hit F12 to open DevTools, then switch to the Network tab.
- Paste a test snippet of JS code, click the obfuscate button, and look for the POST request (it'll probably be to the same
/index.phpURL). - Click into that request, check the Form Data section—you'll see parameters like
input(your raw JS code) and maybe checkboxes for obfuscation settings (likecompactorself-defending). Jot these down; we'll need them for our code.
Step 2: Use a HTTP Client to Send the Request Programmatically
Python is a great choice for this because it's straightforward with libraries like requests and BeautifulSoup (for parsing the response). Here's a working example:
First, install the required packages:
pip install requests beautifulsoup4
Then, the code:
import requests from bs4 import BeautifulSoup def obfuscate_javascript(raw_js): target_url = "https://www.cleancss.com/javascript-obfuscate/index.php" # Match the form parameters you saw in DevTools form_data = { "input": raw_js, "obfuscate": "Obfuscate", # Uncomment and adjust these if you want specific obfuscation options # "compact": "on", # "self-defending": "on", # "debug-protection": "on" } # Mimic a browser's headers to avoid being blocked browser_headers = { "User-Agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0 Safari/537.36", "Referer": target_url } # Send the POST request response = requests.post(target_url, data=form_data, headers=browser_headers) if response.status_code != 200: raise RuntimeError(f"Failed to send request. Status code: {response.status_code}") # Parse the HTML response to extract the obfuscated code soup = BeautifulSoup(response.text, "html.parser") # The obfuscated code is usually in a textarea with id "output" obfuscated_code = soup.find("textarea", id="output").get_text(strip=False) return obfuscated_code # Example usage if __name__ == "__main__": my_code = "function greet(name) { alert(`Hello, ${name}!`); }" result = obfuscate_javascript(my_code) print("Obfuscated code:\n", result)
Step 3: Important Notes
- Check the site's Terms of Service: Some sites don't allow automated requests, so make sure you're not violating any rules.
- Handle changes: The site's form structure or parameters might update over time. If your code stops working, re-inspect the request in DevTools to adjust the parameters.
- Avoid being blocked: If you get 403 or other errors, try adding more headers (like
AcceptorCookie, though cookies might expire) or spacing out your requests to avoid triggering anti-bot measures.
内容的提问来源于stack exchange,提问作者Jorge Gill
相关产品推荐
相关产品推荐

