How to get arguments of a function that created a function from the created function

Viewed 80

The problem is hard to describe, so i will try my best.

I need to reverse a obfuscated javascript which is using code flow obfuscation, data transformation and some others methods. In this code, the program is saving some functions to use them in the flow. These functions are created by calling a specific function and i need to get arguments of this specific function by using the created function (these arguments are important to predict the stack flow)

Here is an example :

function createFunction(arg){
    return function(){
        'use strict';
        // Do some things with arg
        return true;
    }
}
var func = createFunction(5);
// Need to get the argument 5 of createFunction from func var
var bool = func();

NB: The returned function is in strict mode

I don't know if it's even possible, i tried a lot of things, checked every prototype or property etc..

Thanks.


Edit :

This is not possible without editing any code, closures and lexical scoping in javascript is really strict, in my case, i just made a breakpoint after the function declaration, then i overwrited the function himself by adding prototype to the returned function with parameters.

function createFunction(arg){
    var fn = function(){
        'use strict';
        // Do some things with arg
        return true;
    }
    fn.prototype.arg = [arg];
    return fn;
}
var func = createFunction(5);
var arg = func.prototype.arg; // 5 is here now
var bool = func();

Here is a good explanation : JS: Nested functions gain a copy of the outer function's parameters?

Also some docs : https://developer.mozilla.org/en-US/docs/Web/JavaScript/Closures

0 Answers
Related