Skip to main content
GameDev.net gamedev.net
🔒 Locked

Hiding easter eggs in web scripts

Started by Boris Karloff Mar 4, 2005 at 4:16 AM 13 replies 2.7k views
Original Post
Boris Karloff
Boris Karloff
I'm currently writing a web application in PHP for my script at work, and I figured it would be amusing to add in an easter egg in some way, like for example the legendary Dopefish. Unfortunately, however, the scripts aren't being compiled, so the code will be in plain view for whoever glances over it. Also, adding an image of a large green fish would be curious at least. Does anyone have any tips or ideas as how to effectively code like that from inquisitive eyes?
Nein heer du smign. ah open up the nine im heer du shmine
smart_idiot
smart_idiot
Blatantly wrong comments and variables names are the key to everything.
Chess is played by three people. Two people play the game; the third provides moral support for the pawns. The object of the game is to kill your opponent by flinging captured pieces at his head. Since the only piece that can be killed is a pawn, the two armies agree to meet in a pawn-infested area (or even a pawn shop) and kill as many pawns as possible in the crossfire. If the game goes on for an hour, one player may legally attempt to gouge out the other
cozman
cozman
if it's in php why not stick it in another file, then require that file and call the code from the other file

I can see two advantages:

1) that makes it easy to remove if for some reason someone gets mad about it
2) it takes it out of plain view

As far as the image thing, I can't think of a good way to do that, I'd stick with text-based.
Boris Karloff
Boris Karloff
Sticking it in another file wouldn't help. They'd just go "hey, what's this here file for? WTF? Dopefish?"

I guess I'll have to use wrong function and variable names, as smart_idiot mentioned. Maybe I'll stick it in the user rights module. That's so entangled and scary that nobody will notice it nor dare touch it for years to come.

I'd still like to be able to use images, though. Isn't there a way to encode 8-bit images in text, or something?
Nein heer du smign. ah open up the nine im heer du shmine
PnP Bios
PnP Bios
Quote:
Original post by Boris Karloff
Sticking it in another file wouldn't help. They'd just go "hey, what's this here file for? WTF? Dopefish?"

I guess I'll have to use wrong function and variable names, as smart_idiot mentioned. Maybe I'll stick it in the user rights module. That's so entangled and scary that nobody will notice it nor dare touch it for years to come.

I'd still like to be able to use images, though. Isn't there a way to encode 8-bit images in text, or something?


The magic of &#106avascript.<br/><br/>What me and a friend were going to do was make a java breakout applet and stick it on our 404 page.
Boris Karloff
Boris Karloff
How does one generate 8-bit images with &#106avascript?
Nein heer du smign. ah open up the nine im heer du shmine
Witchcraven
Witchcraven
load 256 1x1 sprites?
--------------------------I present for tribute this haiku:Inane Ravings OfThe Haunting JubilationA Mad Engineer©Copyright 2005 ExtrariusAll Rights Reserved
Boris Karloff
Boris Karloff
And 256 1x1 sprites wouldn't be suspicious?
Nein heer du smign. ah open up the nine im heer du shmine
Extrarius
Extrarius
8 bit? You might as well just generate tables with 1 pixel cells (or use tableless CSS if you're going to be correct about it) and set the color appropriately to get full 24 bit color (no alpha unless you get really fancy). You could make a MONSTEROUS section of code to generate a small X*Y 'image' =-P
"Walk not the trodden path, for it has borne it's burden." -John, Flying Monk
Wan
Wan
Why not just generate a picture using php and add it to the response stream?
ApochPiQ
ApochPiQ
You need obfuscation. I've hidden eggs in all kinds of things, including heavily peer-reviewed projects, without problems. If you play it right, it takes so long for the egg to even be discovered that by the time someone finds it, the original client doesn't care. Usually you can even get a laugh or three.

Start with very wrong comments and symbols, as suggested - but make the thing as complicated as possible to discourage reverse-engineering. One of my favorite eggs is just a simple text-injection that prints "Apoch was here" into a text stream at a strategic time. It was controlled by four separate functions and the actual text was "encoded" in the form of several constants and constant arrays that were combined mathematically to produce the final string. Even better, the formula that decoded the constants made use of other perfectly legitimate constants, so it blended in with the surrounding code and looked innocent.
Boris Karloff
Boris Karloff
I'm definitely going for this obfuscation thing. I have the perfect place for it to... I just need to figure out a clever way of composing it from innocent-looking constants.

Quote:
Original post by WanMaster
Why not just generate a picture using php and add it to the response stream?


Yes, why not? But how?
Nein heer du smign. ah open up the nine im heer du shmine
benryves
benryves
Quote:
Original post by Boris Karloff
I'm definitely going for this obfuscation thing. I have the perfect place for it to... I just need to figure out a clever way of composing it from innocent-looking constants.

Quote:
Original post by WanMaster
Why not just generate a picture using php and add it to the response stream?


Yes, why not? But how?


Well, you could always use the PHP image generation functions (look in the PHP manual extended CHM for details) - a few "circle" commands are all that are needed.
[Website] [+++ Divide By Cucumber Error. Please Reinstall Universe And Reboot +++]
Nice Coder
Nice Coder
Place in something like

document.writein("")

Then in adds.js, you do the adds and the easter eggs (or one easter egg).

In adds, you go and you store an encrypted script, which you then writein (and decrypt) when the time comes (But you need to make sure that noone stumbles upon it.

From,
Nice coder
Click here to patch the mozilla IDN exploit, or click Here then type in Network.enableidn and set its value to false. Restart the browser for the patches to work.
CWizard
CWizard
Quote:
Original post by Boris Karloff
Quote:
Original post by WanMaster
Why not just generate a picture using php and add it to the response stream?


Yes, why not? But how?

http://www.php.net/manual/en/ref.image.php

It is really simple.

EDIT: Note: you cannot just send out the image when generating the document. In the document, you must create an object which URI invokes some PHP code that may generate the image under certain conditions.

Topic Locked

This topic has been locked by a moderator. New replies are not allowed.

Sign in to reply to this topic.