I’m trying to take a look at a scamming website, but it’s using the debugger spamming to make reverse engineering difficult. Is there a way to just disable the debugger keyword? I don’t really like to give the websites control over whatever I want to view.

  • eirik@lemmy.ml
    link
    fedilink
    arrow-up
    11
    ·
    1 year ago

    Try the icon next to the cog, right hand, middle of the screen. It should disable all breakpoints

    • tkperson@lemm.eeOP
      link
      fedilink
      arrow-up
      3
      ·
      edit-2
      1 year ago

      That icon did skip over the debugger keyword, but it didn’t solve my issue because it still prevented me from viewing that website’s source. Now the websites just becomes super laggy. I’m assuming that there’s a forever loop that does nothing running in the background now that the debugger keyword constantly gets skipped over.

      Can there be a solution where I can replace debugger to something that can cause the thread to sleep for like half a second?

      • bennyp@kbin.social
        link
        fedilink
        arrow-up
        1
        ·
        1 year ago

        How about a browser extention which replaces the debugger keyword in all downloaded js source with void 0 or something?

    • tkperson@lemm.eeOP
      link
      fedilink
      arrow-up
      1
      ·
      edit-2
      1 year ago

      I used the greasymonkey script with tampermonkey without any modification. And it seems like that script magically worked even though the code doesn’t look like it applies to all of the cases. Thanks, this helped a lot.

      Update: After further testing, the script doesn’t really help a lot, because it broke all the JavaScript used on that website all together, which explains why the debugger stopped spamming. Disabling all the JavaScript is not what I want; I want to be able to use the browser tools to trace certain functions.

  • niartenyaw@midwest.social
    link
    fedilink
    English
    arrow-up
    6
    ·
    1 year ago

    would it help to curl down the source html and scripts? I’m no professional at dealing with malicious code, but i would definitely recommend doing it inside a clean VM or docker container or something

    • tkperson@lemm.eeOP
      link
      fedilink
      arrow-up
      4
      ·
      edit-2
      1 year ago

      curl the source down works, but it makes things more complicated. The source code is obfuscated making it incredibly hard to read. This is where using the web debugging tools shine. If I want to figure out which code is trigger what, I can just look at the call stack. I also wanted to look at the internet traffic to see how things work from there. I could intercept all the HTTP requests but that wouldn’t give things like the call stack. I think it would be much easier if there’s a way stopping the debugger spamming trick.

      • niartenyaw@midwest.social
        link
        fedilink
        English
        arrow-up
        2
        ·
        edit-2
        1 year ago

        ah ok makes sense. maybe after curling you can delete the debuggers/infinite loops in the scripts and then load all that locally into the browser for the tools? will just need to change the script sources go be your local copies

  • 1rre
    link
    fedilink
    arrow-up
    5
    arrow-down
    2
    ·
    1 year ago

    You can at least disable it per-occurance by right clicking the line number and telling it not to break on that line

    • tkperson@lemm.eeOP
      link
      fedilink
      arrow-up
      6
      ·
      1 year ago

      that doesn’t work because the debugger spam spawns a new console/thread or whatever; making a “new file” every time the spam started. There’s no fixed line number to skip over.

  • Phen@lemmy.eco.br
    link
    fedilink
    arrow-up
    2
    ·
    1 year ago

    Did you find a way to do it?

    The last time I ran into this problem I did manage to find a way to disable the debugger spam, but I don’t remember how I did it.