🎮ArcadeLab

拦截器 v2

by EpicCoder88
399 lines12.7 KB
▶ Play
<!DOCTYPE html>
<html lang="zh-CN">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=no">
<title>拦截器 v2</title>
<style>
  * { box-sizing: border-box; }
  body {
    margin: 0;
    min-height: 100vh;
    display: flex;
    flex-direction: column;
    align-items: center;
    justify-content: center;
    font-family: system-ui, -apple-system, "PingFang SC", "Microsoft YaHei", sans-serif;
    background: #f5f5f5;
    color: #333;
    gap: 12px;
    padding: 20px;
    text-align: center;
  }
  button {
    padding: 12px 22px;
    font-size: 15px;
    border: none;
    border-radius: 10px;
    background: #007aff;
    color: #fff;
    font-weight: 600;
    cursor: pointer;
    max-width: 90vw;
  }
  button.danger { background: #ff3b30; }
  button.purple { background: #af52de; }
  #block-notice {
    position: fixed;
    top: 20px;
    left: 50%;
    transform: translateX(-50%);
    background: #34c759;
    color: #fff;
    padding: 12px 24px;
    border-radius: 999px;
    font-weight: 600;
    box-shadow: 0 4px 20px rgba(0,0,0,.15);
    opacity: 0;
    transition: opacity .3s;
    z-index: 2147483647;
    pointer-events: none;
    font-size: 14px;
    white-space: nowrap;
  }
  #block-notice.show { opacity: 1; }
</style>
</head>
<body>
  <h1>拦截器 v2</h1>
  <p>能拦:直接插入、iframe 绕过、Shadow DOM 绕过。</p>

  <button id="testOriginal">测试 1:原始弹窗</button>
  <button id="testIframe" class="danger">测试 2:iframe 绕过</button>
  <button id="testShadow" class="purple">测试 3:Shadow DOM 绕过</button>

  <div id="block-notice">已阻止</div>

  <script>
    // ============ 拦截器 v2 开始 ============
    (function () {
      'use strict';

      const NOTICE_ID = 'block-notice';
      let noticeTimer = null;

      function showNotice(msg) {
        const el = document.getElementById(NOTICE_ID);
        if (!el) return;
        el.textContent = msg || '已阻止';
        el.classList.add('show');
        clearTimeout(noticeTimer);
        noticeTimer = setTimeout(() => el.classList.remove('show'), 2000);
      }

      // ---------- 特征库 ----------
      const DANGER_KEYWORDS = [
        'fake-virus', '无害弹窗', '绕过演示', 'overlay',
        '倒计时', '遮罩', '全屏覆盖'
      ];

      function containsDanger(text) {
        if (!text) return false;
        const s = String(text).toLowerCase();
        return DANGER_KEYWORDS.some(k => s.includes(k.toLowerCase()));
      }

      // 从 HTML 字符串判断可疑
      function htmlLooksSuspicious(html) {
        if (!html) return false;
        const s = String(html);

        if (containsDanger(s)) return true;

        // 全屏固定遮罩 + 高 z-index 组合
        const fixed = /position\s*:\s*fixed/i.test(s);
        const fullscreen = /inset\s*:\s*0/i.test(s) ||
                           (/top\s*:\s*0/i.test(s) && /left\s*:\s*0/i.test(s));
        const highZ = /z-index\s*:\s*\d{4,}/i.test(s);
        if (fixed && fullscreen && highZ) return true;

        // 倒计时 + 覆盖层
        if (/(setInterval|倒计时|count)/i.test(s) &&
            /(overlay|遮罩|覆盖)/i.test(s)) return true;

        return false;
      }

      // 从 DOM 节点判断可疑
      function nodeLooksSuspicious(node) {
        if (!node || node.nodeType !== 1) return false;

        // 自身 id / class
        if (node.id && containsDanger(node.id)) return true;
        if (node.className && typeof node.className === 'string' &&
            containsDanger(node.className)) return true;

        // 文本内容
        try {
          if (node.textContent && containsDanger(node.textContent)) return true;
        } catch (e) {}

        // iframe 的 srcdoc / src
        if (node.tagName === 'IFRAME') {
          const srcdoc = node.getAttribute && node.getAttribute('srcdoc');
          if (srcdoc && htmlLooksSuspicious(srcdoc)) return true;
          const src = node.getAttribute && node.getAttribute('src');
          if (src && containsDanger(src)) return true;
        }

        // 内部查询
        if (node.querySelector) {
          if (node.querySelector('#fake-virus')) return true;
          const iframes = node.querySelectorAll ? node.querySelectorAll('iframe') : [];
          for (const ifr of iframes) {
            const srcdoc = ifr.getAttribute && ifr.getAttribute('srcdoc');
            if (srcdoc && htmlLooksSuspicious(srcdoc)) return true;
          }
        }

        return false;
      }

      // 递归扫描(含 Shadow DOM)
      function scanTree(root, depth) {
        if (!root || depth > 8) return null;
        if (nodeLooksSuspicious(root)) return root;

        if (root.children) {
          for (const child of root.children) {
            const hit = scanTree(child, depth + 1);
            if (hit) return hit;
          }
        }

        if (root.shadowRoot) {
          const hit = scanTree(root.shadowRoot, depth + 1);
          if (hit) return hit;
        }

        return null;
      }

      // ---------- iframe 内部监控 ----------
      const watchedIframes = new WeakSet();

      function watchIframe(iframe) {
        if (!iframe || watchedIframes.has(iframe)) return;
        watchedIframes.add(iframe);

        function attach() {
          let doc = null;
          try {
            doc = iframe.contentDocument ||
                  (iframe.contentWindow && iframe.contentWindow.document);
          } catch (e) {
            return; // 跨域就放弃
          }
          if (!doc || !doc.documentElement) return;

          // 立即扫一遍
          const hit = scanTree(doc.documentElement, 0);
          if (hit) {
            killNode(iframe, '已阻止:iframe 内弹窗');
            return;
          }

          // 持续监控
          const obs = new MutationObserver(() => {
            const h = scanTree(doc.documentElement, 0);
            if (h) {
              killNode(iframe, '已阻止:iframe 内弹窗');
              obs.disconnect();
            }
          });
          obs.observe(doc.documentElement, {
            childList: true,
            subtree: true,
            attributes: true,
            attributeFilter: ['srcdoc', 'src', 'style', 'class', 'id']
          });
        }

        // srcdoc 可能瞬间就绪,多次尝试
        attach();
        iframe.addEventListener('load', attach);
        setTimeout(attach, 50);
        setTimeout(attach, 200);
        setTimeout(attach, 600);
      }

      // ---------- 移除节点 ----------
      function killNode(node, msg) {
        if (!node) return;
        try {
          if (node.parentNode) node.parentNode.removeChild(node);
        } catch (e) {}
        showNotice(msg || '已阻止:检测到可疑弹窗');
      }

      // ---------- 劫持原生插入方法 ----------
      const origAppend = Node.prototype.appendChild;
      const origInsert = Node.prototype.insertBefore;
      const origAppendToShadow = null; // ShadowRoot 也走 appendChild,无需单独劫持

      Node.prototype.appendChild = function (node) {
        if (nodeLooksSuspicious(node)) {
          showNotice('已阻止:检测到可疑弹窗');
          return node;
        }
        const result = origAppend.call(this, node);
        if (node && node.tagName === 'IFRAME') watchIframe(node);
        if (node && node.querySelectorAll) {
          node.querySelectorAll('iframe').forEach(watchIframe);
        }
        return result;
      };

      Node.prototype.insertBefore = function (node, ref) {
        if (nodeLooksSuspicious(node)) {
          showNotice('已阻止:检测到可疑弹窗');
          return node;
        }
        const result = origInsert.call(this, node, ref);
        if (node && node.tagName === 'IFRAME') watchIframe(node);
        return result;
      };

      // ---------- 全局 MutationObserver ----------
      function startGlobalObserver() {
        const observer = new MutationObserver(mutations => {
          for (const m of mutations) {
            for (const node of m.addedNodes) {
              if (nodeLooksSuspicious(node)) {
                killNode(node, '已阻止:检测到可疑弹窗');
                continue;
              }
              if (node.tagName === 'IFRAME') watchIframe(node);
              if (node.querySelectorAll) {
                node.querySelectorAll('iframe').forEach(watchIframe);
              }
            }
          }
        });
        observer.observe(document.documentElement, {
          childList: true,
          subtree: true,
          attributes: true,
          attributeFilter: ['srcdoc', 'src', 'style', 'class', 'id']
        });
      }

      // ---------- 定期兜底扫描 ----------
      let scanTimer = null;
      function periodicScan() {
        // 扫普通 DOM
        const hit = scanTree(document.documentElement, 0);
        if (hit && hit !== document.documentElement) {
          // 只要命中的不是最外层根节点,就尝试移除
          if (hit.parentNode) {
            killNode(hit, '已阻止:检测到可疑弹窗');
            return;
          }
        }
        // 单独扫 iframe
        document.querySelectorAll('iframe').forEach(ifr => {
          watchIframe(ifr);
        });
      }

      // ---------- 启动 ----------
      function boot() {
        startGlobalObserver();
        if (!scanTimer) scanTimer = setInterval(periodicScan, 400);
      }

      if (document.documentElement) boot();
      else document.addEventListener('DOMContentLoaded', boot);

      // ---------- 提前注入 CSS 隐藏(父文档) ----------
      function injectCSS() {
        const style = document.createElement('style');
        style.textContent = `
          #fake-virus,
          [id*="fake-virus"],
          .fake-virus-overlay { display: none !important; }
        `;
        (document.head || document.documentElement).appendChild(style);
      }
      if (document.head) injectCSS();
      else document.addEventListener('DOMContentLoaded', injectCSS);

    })();
    // ============ 拦截器 v2 结束 ============


    // ============ 测试代码 ============

    // 测试 1:原始弹窗
    document.getElementById('testOriginal').onclick = function () {
      const overlay = document.createElement('div');
      overlay.id = 'fake-virus';
      overlay.innerHTML = `
        <div class="box">
          <div class="title">⚠ 无害弹窗演示</div>
          <div class="count">3</div>
          <div class="tip">这不是病毒</div>
        </div>
      `;
      document.body.appendChild(overlay);
    };

    // 测试 2:iframe 绕过
    document.getElementById('testIframe').onclick = function () {
      const iframe = document.createElement('iframe');
      iframe.style.cssText = 'position:fixed;inset:0;width:100%;height:100%;border:0;z-index:999999;';
      iframe.srcdoc = `<!DOCTYPE html>
<html><head><style>
  html,body{margin:0;height:100%;background:transparent;}
  .overlay{position:fixed;inset:0;display:flex;align-items:center;justify-content:center;background:rgba(0,0,0,.78);}
  .box{padding:26px;border-radius:18px;background:#101010;color:#fff;text-align:center;}
  .title{color:#00ff88;font-weight:700;font-size:20px;}
  .count{font-size:56px;font-weight:800;}
  .tip{color:#aaa;font-size:13px;}
</style></head><body>
  <div class="overlay">
    <div class="box">
      <div class="title">⚠ 绕过演示</div>
      <div class="count" id="count">3</div>
      <div class="tip">iframe 隔离</div>
    </div>
  </div>
  <script>
    (function(){
      var el=document.getElementById('count');
      var n=3;
      var t=setInterval(function(){
        n--; if(n>0){el.textContent=n;} else {clearInterval(t);}
      },1000);
    })();
  <\/script>
</body></html>`;
      document.body.appendChild(iframe);
    };

    // 测试 3:Shadow DOM 绕过
    document.getElementById('testShadow').onclick = function () {
      const host = document.createElement('div');
      host.id = 'shadow-host';
      document.body.appendChild(host);
      const shadow = host.attachShadow({ mode: 'open' });
      shadow.innerHTML = `
        <style>
          .overlay{position:fixed;inset:0;display:flex;align-items:center;justify-content:center;background:rgba(0,0,0,.78);z-index:999999;}
          .box{padding:26px;border-radius:18px;background:#101010;color:#fff;text-align:center;font-family:sans-serif;}
          .title{color:#af52de;font-weight:700;font-size:20px;}
          .count{font-size:56px;font-weight:800;}
          .tip{color:#aaa;font-size:13px;}
        </style>
        <div class="overlay">
          <div class="box">
            <div class="title">⚠ Shadow DOM 绕过</div>
            <div class="count">3</div>
            <div class="tip">隔离样式与 DOM</div>
          </div>
        </div>
      `;
    };
  </script>
</body>
</html>

Game Source: 拦截器 v2

Creator: EpicCoder88

Libraries: none

Complexity: complex (399 lines, 12.7 KB)

The full source code is displayed above on this page.

Remix Instructions

To remix this game, copy the source code above and modify it. Add a ARCADELAB header at the top with "remix_of: v2-epiccoder88" to link back to the original. Then publish at arcadelab.ai/publish.