js逆向之百度翻译

百度翻译参数逆向分析

分析思路:

在这里插入图片描述

在这里插入图片描述

我们多发几次请求会发现这个token是写死的,至于那个ts 13位数的数字一定是时间戳,时间戳的生成我们使用python,代码如下:

import time
print(time.time())
# 获取js的时间戳
r = int(time.time()*1000)
print(r)# r就是对应的13位数时间戳

技巧:一般先分析 index*.js 或者main.js等等

在这里插入图片描述
在这里插入图片描述

有点像

在这里插入图片描述

我们点击 那个b函发现到这里了,然后我们打一个断点,然后再结束的地方打一个断点
在这里插入图片描述

因为我们这个函数没有完全执行,又想看看这个函数向下执行 会发生什么所以打断点。

代码:

sign的js代码如下:

    function n(t, e) {
            for (var n = 0; n < e.length - 2; n += 3) {
                var r = e.charAt(n + 2);
                r = "a" <= r ? r.charCodeAt(0) - 87 : Number(r),
                r = "+" === e.charAt(n + 1) ? t >>> r : t << r,
                t = "+" === e.charAt(n) ? t + r & 4294967295 : t ^ r
            }
            return t
        }
function s(t) {
    var r="320305.131321201"
            var o, i = t.match(/[\uD800-\uDBFF][\uDC00-\uDFFF]/g);
            if (null === i) {
                var a = t.length;
                a > 30 && (t = "".concat(t.substr(0, 10)).concat(t.substr(Math.floor(a / 2) - 5, 10)).concat(t.substr(-10, 10)))
            } else {
                for (var s = t.split(/[\uD800-\uDBFF][\uDC00-\uDFFF]/), c = 0, u = s.length, l = []; c < u; c++)
                    "" !== s[c] && l.push.apply(l, function(t) {
                        if (Array.isArray(t))
                            return e(t)
                    }(o = s[c].split("")) || function(t) {
                        if ("undefined" != typeof Symbol && null != t[Symbol.iterator] || null != t["@@iterator"])
                            return Array.from(t)
                    }(o) || function(t, n) {
                        if (t) {
                            if ("string" == typeof t)
                                return e(t, n);
                            var r = Object.prototype.toString.call(t).slice(8, -1);
                            return "Object" === r && t.constructor && (r = t.constructor.name),
                            "Map" === r || "Set" === r ? Array.from(t) : "Arguments" === r || /^(?:Ui|I)nt(?:8|16|32)(?:Clamped)?Array$/.test(r) ? e(t, n) : void 0
                        }
                    }(o) || function() {
                        throw new TypeError("Invalid attempt to spread non-iterable instance.\nIn order to be iterable, non-array objects must have a [Symbol.iterator]() method.")
                    }()),
                    c !== u - 1 && l.push(i[c]);
                var p = l.length;
                p > 30 && (t = l.slice(0, 10).join("") + l.slice(Math.floor(p / 2) - 5, Math.floor(p / 2) + 5).join("") + l.slice(-10).join(""))
            }
            for (var d = "".concat(String.fromCharCode(103)).concat(String.fromCharCode(116)).concat(String.fromCharCode(107)), h = (null !== r ? r : (r = window[d] || "") || "").split("."), f = Number(h[0]) || 0, m = Number(h[1]) || 0, g = [], y = 0, v = 0; v < t.length; v++) {
                var _ = t.charCodeAt(v);
                _ < 128 ? g[y++] = _ : (_ < 2048 ? g[y++] = _ >> 6 | 192 : (55296 == (64512 & _) && v + 1 < t.length && 56320 == (64512 & t.charCodeAt(v + 1)) ? (_ = 65536 + ((1023 & _) << 10) + (1023 & t.charCodeAt(++v)),
                g[y++] = _ >> 18 | 240,
                g[y++] = _ >> 12 & 63 | 128) : g[y++] = _ >> 12 | 224,
                g[y++] = _ >> 6 & 63 | 128),
                g[y++] = 63 & _ | 128)
            }
            for (var b = f, w = "".concat(String.fromCharCode(43)).concat(String.fromCharCode(45)).concat(String.fromCharCode(97)) + "".concat(String.fromCharCode(94)).concat(String.fromCharCode(43)).concat(String.fromCharCode(54)), k = "".concat(String.fromCharCode(43)).concat(String.fromCharCode(45)).concat(String.fromCharCode(51)) + "".concat(String.fromCharCode(94)).concat(String.fromCharCode(43)).concat(String.fromCharCode(98)) + "".concat(String.fromCharCode(43)).concat(String.fromCharCode(45)).concat(String.fromCharCode(102)), x = 0; x < g.length; x++)
                b = n(b += g[x], w);
            return b = n(b, k),
            (b ^= m) < 0 && (b = 2147483648 + (2147483647 & b)),
            "".concat((b %= 1e6).toString(), ".").concat(b ^ f)
        }

注意: var r=“320305.131321201” 这个是写死的,如果不写的话,会缺少一个r ,大家运行的时候缺少什么补充什么即可。

python代码:

import time
import requests
from fake_useragent import  UserAgent
import execjs
ua=UserAgent()


def get_sign(word):
    ctx = execjs.compile(open("./01.js", "r", encoding='utf-8').read())
    result = ctx.call("getsign",word)
    return result

def spider1(word,sign,r):
    headers = {
        "Accept": "*/*",
        "Accept-Language": "zh-CN,zh;q=0.9",
        "Acs-Token": "1699024432045_1699024322679_3vTRGst0ZjpisCbqNGlHPF0rmCWchtpv24QkkGZEvdHSBjOq8xux+4/Xbd3jqyxJGVUZFgWfkkdtbn5vgghjoZAeyMRzovVUwM/Y1Hn7c61jdtNRgfe0lxFOaW5c8Z2XB+llMbnRLZ5HBWaOKmRyM4xX0RK9CAXfRF1lipmeDl48JFlZPWhK4altrBt0qs2Dmf0ZK1Hs8o66IcYl5Qx5TS8/GDlbL6cIuAQV/fM2jnxk/RqahChTkbZrC9bQbjIovs3e8iHOYBGlqJL/OfuDMLyDTf1ghLMAsPKla0BQ6LwQKH7Y/QmCHRZezjCUv4aNXEn+seiQZMlHmXBlWCUeLv0habepSwrUHipQwzfikVq8BXusBN26ObXNAm02d/0Ii8UUhfaHfTj9osYCKktnDvRa9boiotcykVM0EeqB6g9lAXwsH8iEyf0L64Np8rAiEo0nbbSZdN2fT0rp7hICR0tfOoMwlX5xdtS32FkCUwO++JxL6Le9Xc/hQMiwLQGM",
        "Connection": "keep-alive",
        "Content-Type": "application/x-www-form-urlencoded; charset=UTF-8",
        "Origin": "https://fanyi.baidu.com",
        "Referer": "https://fanyi.baidu.com/translate?query=&keyfrom=baidu&smartresult=dict&lang=auto2zh",
        "Sec-Fetch-Dest": "empty",
        "Sec-Fetch-Mode": "cors",
        "Sec-Fetch-Site": "same-origin",
        "User-Agent":ua.chrome,
        "X-Requested-With": "XMLHttpRequest",
        "sec-ch-ua": "\"Chromium\";v=\"118\", \"Google Chrome\";v=\"118\", \"Not=A?Brand\";v=\"99\"",
        "sec-ch-ua-mobile": "?0",
        "sec-ch-ua-platform": "\"Windows\""
    }
    cookies = {
        "Hm_lvt_64ecd82404c51e03dc91cb9e8c025574": "1691744464",
        "REALTIME_TRANS_SWITCH": "1",
        "FANYI_WORD_SWITCH": "1",
        "HISTORY_SWITCH": "1",
        "SOUND_SPD_SWITCH": "1",
        "SOUND_PREFER_SWITCH": "1",
        "APPGUIDE_10_6_6": "1",
        "xxoo-tmp": "zhHans",
        "BIDUPSID": "8D184EE92836662F861F28BFAA7BBE3A",
        "PSTM": "1698838392",
        "BAIDUID": "8D184EE92836662FDB579DBB98CBD735:FG=1",
        "H_PS_PSSID": "26350",
        "BAIDUID_BFESS": "8D184EE92836662FDB579DBB98CBD735:FG=1",
        "ab_sr": "1.0.1_OGU1YzRiNDUwYWJlM2NhODJkZTZiYjAyOWY1NTQ4OGE4MTA3ODc2YTQ5YjljNjlhOWM2ODYyZWJlOWY2ZDI4MWFlODJkMTQ5MjM0Mzc3ODc4ZTZjMWMzYjQwNDMzYTMzNGJlZDA2ODVmMWNhOTc2NDcwZjQxMGM1ZmE5YzYwZTc5MTYwMWExOTA4ZWE1ZTAzZTE3ODI5ZWMzNzg5ZTg2ZQ=="
    }
    url = "https://fanyi.baidu.com/v2transapi"
    params = {
        "from": "en",
        "to": "zh"
    }
    data = {
        "from": "en",
        "to": "zh",
        "query": word,
        "transtype": "enter",
        "simple_means_flag": "3",
        "sign": sign,
        "token": "1b2b0c0f3e76a808070312a0785f57d4",
        "domain": "common",
        "ts": str(r)
    }
    response = requests.post(url, headers=headers, cookies=cookies, params=params, data=data)

    return response


if __name__ == '__main__':
    word = input("输入翻译元素")
    tt = time.time()
    # 获取js的时间戳
    r = int(time.time() * 1000)

    sign=get_sign(word)
    response=spider1(word,sign,r)
    # print(sign)
    print(response.json())
    print(response.encoding)

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包

打赏作者

acmakb

你的鼓励将是我创作的最大动力

¥1 ¥2 ¥4 ¥6 ¥10 ¥20
扫码支付:¥1
获取中
扫码支付

您的余额不足,请更换扫码支付或充值

打赏作者

实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值