web逆向学习入门(百度翻译练手)
2023-1-15 20:49:3 Author: 红蓝攻防实验室(查看原文) 阅读量:23 收藏

0x01 介绍

这里就是简单利用百度翻译来学习下简单的一个小逆向 

技术栈

pythonjs(debug主要是)谷歌浏览器

0x02 逆向开始

直接开始

这里通过谷歌浏览器观察接口 查看使用的是ajax 观察参数 发现只有 我们输入的翻译的参数,

和这个sign是可变参数

通过浏览器查询sign:在代码文件中位置

通过debug找到sign参数生成的地方

已知 b(e)参数生成的sign e查看 是我们输入的参数 red 跟进b方法

看到参数确实是输入的翻译对象

可以看到就是这个方法生成的简单粗暴 将这个方法 复制出来

实现思路就是使用 python 调用js 生成sign参数 来实现翻译

import execjs
def get_sign(param): node = execjs.get() with open('index.js', encoding='utf-8') as f: js_code = f.read() ctx = node.compile(js_code, cwd=r'/usr/local/lib/node_modules') sign = ctx.call("getSign", param) return sign
if __name__ == '__main__': get_sign("red")

说明没扣仔细代码 

进入js方法 看r是啥 继续扣代码 

添加监视多次调试 发现 r不变参数 

查看有少了个n方法 继续debug跟进 扣n

直接复制 

再次执行 查看生成成功了

接下来带入接口 开始编写

通过这个网站curl生成https://curl.iculture.cc

0x03 代码编写

python代码

import requestsimport jsonimport execjsimport sys
def get_sign(param): node = execjs.get() with open('index.js', encoding='utf-8') as f: js_code = f.read() ctx = node.compile(js_code, cwd=r'/usr/local/lib/node_modules') sign = ctx.call("getSign", param) return sign
def requests_api(query,sign): cookies = { 'BIDUPSID': '1D355A32266119AF444200DE10B5860D', 'PSTM': '1672273407', 'BAIDUID': '1D355A32266119AF30AA94745E42847A:FG=1', 'APPGUIDE_10_0_2': '1', 'REALTIME_TRANS_SWITCH': '1', 'FANYI_WORD_SWITCH': '1', 'HISTORY_SWITCH': '1', 'SOUND_SPD_SWITCH': '1', 'SOUND_PREFER_SWITCH': '1', 'BDUSS': 'zRDdVdvaFFqdTVTUk5TczlJWEs2V0ZaQUdXbFZQN2VOV2syQTBJa3JTRjM2dGhqSVFBQUFBJCQAAAAAAAAAAAEAAAAPG~Bd0KHF6NPR36Owod-jwLIAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAHddsWN3XbFjM', 'BDUSS_BFESS': 'zRDdVdvaFFqdTVTUk5TczlJWEs2V0ZaQUdXbFZQN2VOV2syQTBJa3JTRjM2dGhqSVFBQUFBJCQAAAAAAAAAAAEAAAAPG~Bd0KHF6NPR36Owod-jwLIAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAHddsWN3XbFjM', 'BDORZ': 'B490B5EBF6F3CD402E515D22BCDA1598', 'delPer': '0', 'BA_HECTOR': '808gag05a5a404250g2l8k131hs70el1k', 'ZFY': 'DdRTBG6zFyGKGBjz79iNuUWw5qIbak82G6g06Ue:A:A1o:C', 'BAIDUID_BFESS': '1D355A32266119AF30AA94745E42847A:FG=1', 'H_PS_PSSID': '36546_37973_37520_38059_36920_37989_37801_37925_37900_26350_37881', 'PSINO': '7', 'Hm_lvt_64ecd82404c51e03dc91cb9e8c025574': '1672283738,1673503444,1673703892,1673777733', 'Hm_lpvt_64ecd82404c51e03dc91cb9e8c025574': '1673784589', 'ab_sr': '1.0.1_NmE1MmUxMWM4ZDkxODk4OWQ1YTQ0YTk5ODBkNWY5MjU4MGFmM2VjZDllMjQzZDg2OTA5MGU4OTA1YTdlM2NlZjVhYjZiN2M5NzJjZTA3ZjhkZGUxOGJiOWIzMWJhMzUxZTE4NGQzNDM0MGMyZDkwY2Y0Yjk5YjVlNjc1MDkwODc4ZjJjNWQ0MzI3Y2NiZTlkMWNkYWNhM2ZiMDU5MzkyNjY3OWNiOGE4YWFlNzAyOWM2NzQ5ZWQ2YmIzOTlhYTUy', }
headers = { 'Accept': '*/*', 'Accept-Language': 'zh,zh-CN;q=0.9', 'Acs-Token': '1673769896714_1673784883811_/jNTmMdug05eaCQYNoVx1yA3nMqigRtFMSJAlz/zUNGv7RBNirJgw/ipodbRqwDEyb7KHxOiglOqG75WdKjML39btEAmYi1m0Gv2K7mVaLytJ2mtKLE9nI3/BVnebzTBhpo5ylSR/vuC1W5DnEdo1ueBFXvrbhXtQ9DptFbtkVxwKLZQvDGLm8Vde5RVN23U3q0KRuqvl4k5XBmDt98RRobHmzx8+TaTK3nSQW17Zcz3bpkICt7UxkjsMOalkSaz6sc83xzVacILeSJp8Z0djZjKH1WCIQe9I7iR8YUF4Dghz+MCZpmKW5S9Vs/oTfWT', 'Connection': 'keep-alive', 'Content-Type': 'application/x-www-form-urlencoded; charset=UTF-8', 'Origin': 'https://fanyi.baidu.com', 'Referer': 'https://fanyi.baidu.com/', 'Sec-Fetch-Dest': 'empty', 'Sec-Fetch-Mode': 'cors', 'Sec-Fetch-Site': 'same-origin', 'User-Agent': 'Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.5383.175 Safari/537.36', 'X-Requested-With': 'XMLHttpRequest', 'sec-ch-ua': '"(Not(A:Brand";v="99", "Chromium";v="110", "Google Chrome";v="110"', 'sec-ch-ua-mobile': '?0', 'sec-ch-ua-platform': '"Linux"', }
params = { 'from': 'en', 'to': 'zh', }
data = { 'from': 'en', 'to': 'zh', 'query': query, 'transtype': 'realtime', 'simple_means_flag': '3', 'sign': sign, 'token': '0c230afd3ad0ebe562d48955772dde4b', 'domain': 'common', }
response = requests.post('https://fanyi.baidu.com/v2transapi', params=params, cookies=cookies, headers=headers, data=data) json_data = json.loads(response.text) res = json_data['trans_result']['data'][0]['dst'] print("翻译结果:", res)
if __name__ == '__main__': query = sys.argv[1] if query != '': requests_api(query,get_sign(query))

js代码

 function n(t, e) {            for (var n = 0; n < e.length - 2; n += 3) {                var r = e.charAt(n + 2);                r = "a" <= r ? r.charCodeAt(0) - 87 : Number(r),                r = "+" === e.charAt(n + 1) ? t >>> r : t << r,                t = "+" === e.charAt(n) ? t + r & 4294967295 : t ^ r            }            return t        }
function getSign (t) { var o, i = t.match(/[\uD800-\uDBFF][\uDC00-\uDFFF]/g); var r = "320305.131321201" if (null === i) { var a = t.length; a > 30 && (t = "".concat(t.substr(0, 10)).concat(t.substr(Math.floor(a / 2) - 5, 10)).concat(t.substr(-10, 10))) } else { for (var s = t.split(/[\uD800-\uDBFF][\uDC00-\uDFFF]/), c = 0, u = s.length, l = []; c < u; c++) "" !== s[c] && l.push.apply(l, function(t) { if (Array.isArray(t)) return e(t) }(o = s[c].split("")) || function(t) { if ("undefined" != typeof Symbol && null != t[Symbol.iterator] || null != t["@@iterator"]) return Array.from(t) }(o) || function(t, n) { if (t) { if ("string" == typeof t) return e(t, n); var r = Object.prototype.toString.call(t).slice(8, -1); return "Object" === r && t.constructor && (r = t.constructor.name), "Map" === r || "Set" === r ? Array.from(t) : "Arguments" === r || /^(?:Ui|I)nt(?:8|16|32)(?:Clamped)?Array$/.test(r) ? e(t, n) : void 0 } }(o) || function() { throw new TypeError("Invalid attempt to spread non-iterable instance.\nIn order to be iterable, non-array objects must have a [Symbol.iterator]() method.") }()), c !== u - 1 && l.push(i[c]); var p = l.length; p > 30 && (t = l.slice(0, 10).join("") + l.slice(Math.floor(p / 2) - 5, Math.floor(p / 2) + 5).join("") + l.slice(-10).join("")) } for (var d = "".concat(String.fromCharCode(103)).concat(String.fromCharCode(116)).concat(String.fromCharCode(107)), h = (null !== r ? r : (r = window[d] || "") || "").split("."), f = Number(h[0]) || 0, m = Number(h[1]) || 0, g = [], y = 0, v = 0; v < t.length; v++) { var _ = t.charCodeAt(v); _ < 128 ? g[y++] = _ : (_ < 2048 ? g[y++] = _ >> 6 | 192 : (55296 == (64512 & _) && v + 1 < t.length && 56320 == (64512 & t.charCodeAt(v + 1)) ? (_ = 65536 + ((1023 & _) << 10) + (1023 & t.charCodeAt(++v)), g[y++] = _ >> 18 | 240, g[y++] = _ >> 12 & 63 | 128) : g[y++] = _ >> 12 | 224, g[y++] = _ >> 6 & 63 | 128), g[y++] = 63 & _ | 128) } for (var b = f, w = "".concat(String.fromCharCode(43)).concat(String.fromCharCode(45)).concat(String.fromCharCode(97)) + "".concat(String.fromCharCode(94)).concat(String.fromCharCode(43)).concat(String.fromCharCode(54)), k = "".concat(String.fromCharCode(43)).concat(String.fromCharCode(45)).concat(String.fromCharCode(51)) + "".concat(String.fromCharCode(94)).concat(String.fromCharCode(43)).concat(String.fromCharCode(98)) + "".concat(String.fromCharCode(43)).concat(String.fromCharCode(45)).concat(String.fromCharCode(102)), x = 0; x < g.length; x++) b = n(b += g[x], w); return b = n(b, k), (b ^= m) < 0 && (b = 2147483648 + (2147483647 & b)), "".concat((b %= 1e6).toString(), ".").concat(b ^ f) }

0x04 总结

就是不断的debug 合理利用浏览器 寻找我们需要的参数 然后提取出来封装成我们调用的方法来使用


文章来源: http://mp.weixin.qq.com/s?__biz=MzU2OTkwNzIxOA==&mid=2247484067&idx=1&sn=dc99e096db2a9262247270b43f31940f&chksm=fcf6c3decb814ac846397a5e7ad914ecf17675e23344ffc4f76149b356e1412c0bd2f7d4811c#rd
如有侵权请联系:admin#unsafe.sh