RE: HideMyAss Proxy obfuscation/ encoding 02-15-2014, 08:50 AM
#5
It's pretty easy (but boring).
first create a httpwebrequest specific to request a list of proxy's.
then you'll notice all IP/ports segments are generated/obfuscarated like the following:
step1, create a blacklist of the classes that are hidden (display:none) in the initial list.
so blacklist = {so6d, WHPt, PDtg}
now loop through every element:
1. contains: display:none? -> don't use number/dot
2. contains blacklisted class? -> don't use number/dot
sometimes there are numbers between the elements, always add those.
I think there were some exceptions but this will solve 90% of them (if you want 100% refresh the page and the obfusceration works in your favour..) You can add additional dots "." after every inserted number, and in the end just trim all exessive dots.
The exersize is mainly string manipulation. (or htmlelements but that could take some time to get use to).
first create a httpwebrequest specific to request a list of proxy's.
then you'll notice all IP/ports segments are generated/obfuscarated like the following:
Code:
<td><span><style>
.so6d{display:none}
.ehy-{display:inline}
.WHPt{display:none}
.UsLX{display:inline}
.PDtg{display:none}
.Q-C3{display:inline}
</style><span style="display:none">17</span><span class="PDtg">17</span><div style="display:none">17</div><span style="display:none">84</span><div style="display:none">84</div>94<span style="display:none">137</span><span></span>.<span class="so6d">13</span><span></span><span style="display:none">97</span><div style="display:none">97</div><span class="WHPt">157</span><div style="display:none">157</div><span style="display:none">179</span><div style="display:none">179</div><span class="UsLX">202</span><span class="so6d">214</span><span class="UsLX">.</span><span style="display:none">2</span><span class="so6d">2</span><div style="display:none">2</div><span style="display:none">8</span><span style="display:none">122</span><span class="WHPt">122</span><div style="display:none">122</div><span style="display:none">136</span><span class="PDtg">136</span><span></span><span class="31">187</span><span class="70">.</span><span class="so6d">91</span><div style="display:none">91</div><span class="WHPt">94</span><div style="display:none">94</div><span style="display:none">98</span><span class="UsLX">241</span></span></td>
<td>80</td>Code:
.so6d{display:none} <- this one
.ehy-{display:inline}
.WHPt{display:none} <- this one
.UsLX{display:inline}
.PDtg{display:none} <- this one
.Q-C3{display:inline}now loop through every element:
Code:
<span class="PDtg">17</span>
<span style="display:none">17</span>
<div style="display:none">17</div>2. contains blacklisted class? -> don't use number/dot
sometimes there are numbers between the elements, always add those.
I think there were some exceptions but this will solve 90% of them (if you want 100% refresh the page and the obfusceration works in your favour..) You can add additional dots "." after every inserted number, and in the end just trim all exessive dots.
The exersize is mainly string manipulation. (or htmlelements but that could take some time to get use to).


![[+]](https://sinister.li/images/modern/collapse_collapsed.png)