Conversation
Adds scripts/uniquify.sh: a seeded, one-per-environment setup script that
rewrites ConfuserExx's own source-level fingerprints so a build is not
recognizable as ConfuserEx (Level 1 of the identity work).
It rewrites, deterministically from --seed:
- the runtime namespace Confuser.Runtime -> a seed-derived name, kept in
sync across both sides of the coupling: the runtime `namespace`
declarations and every obfuscator "Confuser.Runtime.<Type>" string
literal used by GetRuntimeType/Find. The assembly file name
(Confuser.Runtime.dll) and the runtime-service id are left intact, so
the runtime still loads by file name and its types still resolve by
their new full name.
- the watermark default attribute name ConfusedByAttribute.
Runtime TYPE/METHOD names (Constant, Resolve, Get, Value, ...) are ordinary
words that also occur in unrelated code, so they need a semantic (Roslyn)
rename rather than text substitution and are left for a follow-up, together
with the runtime DLL rename and the anti-debug process-name checks.
Flags: --seed, --dry-run, --test (build + dotnet test), --restore (reverts
every touched file via git, tracked through a manifest under .git/).
Validated: applied with a sample seed, built Runtime + Protections, ran the
runtime-injection tests (CompressorWithResx 12/12, AntiTamper normal+anti)
to prove GetRuntimeType still resolves the renamed types, then --restore
returned the tree to HEAD cleanly.
Owner
Author
|
Closing: this is Level-1 tool-binary identity only and does not change the protected output — the renamer already gives injected helper types random names + blank namespace per build, so the runtime namespace/type names never reach a finished assembly. Output uniqueness is covered by the Level-2 constant randomization (#106/#107/#108). Not worth carrying for output security. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Level 1 — source identity (
uniquify.sh) (#69)Adds
scripts/uniquify.sh, the Level-1 setup script: run once per environment with a--seed, it rewrites ConfuserExx's own source-level fingerprints so a rebuilt tool is not recognizable as ConfuserEx. Deterministic — the same seed always yields the same identifiers.What it rewrites (kept in sync)
Confuser.Runtimenamespacedeclarations and every obfuscator"Confuser.Runtime.<Type>"string literal (GetRuntimeType/Find)ConfusedByAttributeThe assembly file name (
Confuser.Runtime.dll) and the"Confuser.Runtime"service id are left intact on purpose:RuntimeServiceloads the runtime by file name and then resolves each type by its (now seed-derived) full name, so both still line up. The namespace is the primary Level-1 fingerprint (per the issue's own correction: it'sConfuser.Runtime, notSystem.Core.Internal).Deliberately deferred (not safe as text substitution)
Runtime type/method names (
Constant,Resolve,Get,Value, …) are ordinary English words that also appear in unrelated code — renaming them safely needs a semantic/Roslyn rename, notsed. The runtime DLL rename and the anti-debug process-name checks are also left as follow-ups. Documented in the script header.Flags
--seed <phrase>·--dry-run(preview, writes nothing) ·--test(build +dotnet test) ·--restore(reverts every touched file viagit, tracked through a manifest kept under.git/so it never pollutes the tree).Validation
Applied with a sample seed → 0 stray
Confuser.Runtimenamespace decls / obfuscator strings → built Runtime + Protections → ran the runtime-injection tests (CompressorWithResx12/12,AntiTampernormal+anti) provingGetRuntimeTypestill resolves the renamed types →--restorereturned the tree to HEAD cleanly. The committed tree is unchanged; only the script is added.Remaining on #69
0x3dbb2819).Part of #69. Related: #106, #107, #108.