How to See the content of Decompiled code

Viewed 331

I am trying to obfuscate my project. I have used Obfuscator plugin from Unity Asset store. I want to see how my obfuscated code looks like. So I did reverse engineering and got Assembly-CSharp.dll file. When I open it on DNspy I check my class name, It only shows me method name not method's content. How would I know If my code is obfuscated or not. I am using IL2CPP and .net 4. Is there any way to see method's content. enter image description here

3 Answers

I suggest you consider switching to use Telerik JustDecompile assembly browser plus Skater .Net Obfuscator for your specific purposes. It gives you ability to obfuscate some particular classes only of your Assembly-CSharp.dll. By using Skater .Net Obfuscator you don’t need to obfuscate the complete whole dll file. Then you will be able to browse the protected class in Telerik JustDecompile interface. Let’s say your Assembly-CSharp.dll contents several classes as shown below. enter image description here There is My_Class_1 class presented with few members. Let’s obfuscate that class only by using Skater Obfuscator. The obfuscator has several interface tabs that allows user to select what elements and modifiers should be protected. There are tabs like ‘Private Members’, ‘Public Members’, ‘Strings’ and so on. enter image description here Go to most of tabs and select checkboxes associated with the My_Class_1 class as shown above for ‘Strings’. When the obfuscation process complete for the Assembly-CSharp.dll open the resulted assembly in Telerik JustDecompile. Select the My_Class_1 class to browse. Actually we could not find the class by its name since that obfuscated. We can just suggest that is that class. enter image description here

IL2CPP basically is converting the c# code to c++ code to be more efficient and gain better performance so the dll you are inspecting using DNSpy is a c++ DLL, reversing c++ code is not impossible but very hard, you can dump only functions names using

IL2CPP Dumper

the only benefit from using this tool is to get the offset in memory so player can cheat in the game by changing the value of that offset

You are using Unity's "Obfuscator" plugin, but don't know if the code is right or not. You can try the methods below:

  1. Import the Unity package of obfuscator.
  2. Click the file to configure obfuscation options.

enter image description here

  1. Enable obfuscated code.

enter image description here

  1. Obfuscate all assemblies.
  2. The assembly file name that needs to be obfuscated.
  3. The parts of the code that need to be obfuscated, such as class names, method names, parameters and so on.
  4. Package the apk.
  5. Change the suffix of the apk to rar or other compressed file format that your computer can open and decompress it.
  6. Open the corresponding folder "asset>bin>data>managed" to find your obfuscated dll file. Drag it into .NET Reflector to see the obfuscated code.

enter image description here

enter image description here

Precautions:

  1. The click event of the drag assignment needs to be marked with [SkipRename] or not set the obfuscated method name because the method name will be changed. When you click the button, you will naturally not find the method you dragged up.
  2. All data classes need to be marked with [Skip], otherwise the properties inside cannot be called. The name is different from the drag event. Naturally, it cannot be called.
  3. If the third-party plug-in fails, see if it is placed in the Plugins folder. The plug-in will not obfuscate the code in the Plugins folder.
Related