侯体宗的博客
  • 首页
  • Hyperf版
  • beego仿版
  • 人生(杂谈)
  • 技术
  • 关于我
  • 更多分类
    • 文件下载
    • 文字修仙
    • 中国象棋ai
    • 群聊
    • 九宫格抽奖
    • 拼图
    • 消消乐
    • 相册

python 反编译exe文件为py文件的实例代码

Python  /  管理员 发布于 7年前   252

我们用pyinstaller把朋友文件打包成exe文件,但有时候我们需要还原,我们可以用pyinstxtractor.py

用法:

python pyinstxtractor.py xxx.exe

之后得到一个这样结构的文件夹

--- xxx.exe_extracted  -- out00-PYZ.pyz_extracted   - 各种.pyc文件  -- out00-PYZ.pyz  -- some  -- others  -- xxx(注意这些都是没后缀的)

然后再终端pip install uncompyle安装uncompyle,

然后就可以使用啦

uncompyle6 input.pyc > output.py

把pyc文件转换为py文件,希望对大家有帮助

最后贴上pyinstxtractor.py的代码

"""PyInstaller Extractor v1.9 (Supports pyinstaller 3.3, 3.2, 3.1, 3.0, 2.1, 2.0)Author : Extreme CodersE-mail : extremecoders(at)hotmail(dot)comWeb  : https://0xec.blogspot.comDate  : 29-November-2017Url  : https://sourceforge.net/projects/pyinstallerextractor/For any suggestions, leave a comment onhttps://forum.tuts4you.com/topic/34455-pyinstaller-extractor/This script extracts a pyinstaller generated executable file.Pyinstaller installation is not needed. The script has it all.For best results, it is recommended to run this script in thesame version of python as was used to create the executable.This is just to prevent unmarshalling errors(if any) whileextracting the PYZ archive.Usage : Just copy this script to the directory where your exe resides    and run the script with the exe file name as a parameterC:\path\to\exe\>python pyinstxtractor.py <filename>$ /path/to/exe/python pyinstxtractor.py <filename>Licensed under GNU General Public License (GPL) v3.You are free to modify this source.CHANGELOG================================================Version 1.1 (Jan 28, 2014)-------------------------------------------------- First Release- Supports only pyinstaller 2.0Version 1.2 (Sept 12, 2015)-------------------------------------------------- Added support for pyinstaller 2.1 and 3.0 dev- Cleaned up code- Script is now more verbose- Executable extracted within a dedicated sub-directory(Support for pyinstaller 3.0 dev is experimental)Version 1.3 (Dec 12, 2015)-------------------------------------------------- Added support for pyinstaller 3.0 final- Script is compatible with both python 2.x & 3.x (Thanks to Moritz Kroll @ Avira Operations GmbH & Co. KG)Version 1.4 (Jan 19, 2016)-------------------------------------------------- Fixed a bug when writing pyc files >= version 3.3 (Thanks to Daniello Alto: https://github.com/Djamana)Version 1.5 (March 1, 2016)-------------------------------------------------- Added support for pyinstaller 3.1 (Thanks to Berwyn Hoyt for reporting)Version 1.6 (Sept 5, 2016)-------------------------------------------------- Added support for pyinstaller 3.2- Extractor will use a random name while extracting unnamed files.- For encrypted pyz archives it will dump the contents as is. Previously, the tool would fail.Version 1.7 (March 13, 2017)-------------------------------------------------- Made the script compatible with python 2.6 (Thanks to Ross for reporting)Version 1.8 (April 28, 2017)-------------------------------------------------- Support for sub-directories in .pyz files (Thanks to Moritz Kroll @ Avira Operations GmbH & Co. KG)Version 1.9 (November 29, 2017)-------------------------------------------------- Added support for pyinstaller 3.3- Display the scripts which are run at entry (Thanks to Michael Gillespie @ malwarehunterteam for the feature request)"""from __future__ import print_functionimport osimport structimport marshalimport zlibimport sysimport impimport typesfrom uuid import uuid4 as uniquenameclass CTOCEntry:  def __init__(self, position, cmprsdDataSize, uncmprsdDataSize, cmprsFlag, typeCmprsData, name):    self.position = position    self.cmprsdDataSize = cmprsdDataSize    self.uncmprsdDataSize = uncmprsdDataSize    self.cmprsFlag = cmprsFlag    self.typeCmprsData = typeCmprsData    self.name = nameclass PyInstArchive:  PYINST20_COOKIE_SIZE = 24      # For pyinstaller 2.0  PYINST21_COOKIE_SIZE = 24 + 64   # For pyinstaller 2.1+  MAGIC = b'MEI\014\013\012\013\016' # Magic number which identifies pyinstaller  def __init__(self, path):    self.filePath = path  def open(self):    try:      self.fPtr = open(self.filePath, 'rb')      self.fileSize = os.stat(self.filePath).st_size    except:      print('[*] Error: Could not open {0}'.format(self.filePath))      return False    return True  def close(self):    try:      self.fPtr.close()    except:      pass  def checkFile(self):    print('[*] Processing {0}'.format(self.filePath))    # Check if it is a 2.0 archive    self.fPtr.seek(self.fileSize - self.PYINST20_COOKIE_SIZE, os.SEEK_SET)    magicFromFile = self.fPtr.read(len(self.MAGIC))    if magicFromFile == self.MAGIC:      self.pyinstVer = 20   # pyinstaller 2.0      print('[*] Pyinstaller version: 2.0')      return True    # Check for pyinstaller 2.1+ before bailing out    self.fPtr.seek(self.fileSize - self.PYINST21_COOKIE_SIZE, os.SEEK_SET)    magicFromFile = self.fPtr.read(len(self.MAGIC))    if magicFromFile == self.MAGIC:      print('[*] Pyinstaller version: 2.1+')      self.pyinstVer = 21   # pyinstaller 2.1+      return True    print('[*] Error : Unsupported pyinstaller version or not a pyinstaller archive')    return False  def getCArchiveInfo(self):    try:      if self.pyinstVer == 20:        self.fPtr.seek(self.fileSize - self.PYINST20_COOKIE_SIZE, os.SEEK_SET)        # Read CArchive cookie        (magic, lengthofPackage, toc, tocLen, self.pyver) = \        struct.unpack('!8siiii', self.fPtr.read(self.PYINST20_COOKIE_SIZE))      elif self.pyinstVer == 21:        self.fPtr.seek(self.fileSize - self.PYINST21_COOKIE_SIZE, os.SEEK_SET)        # Read CArchive cookie        (magic, lengthofPackage, toc, tocLen, self.pyver, pylibname) = \        struct.unpack('!8siiii64s', self.fPtr.read(self.PYINST21_COOKIE_SIZE))    except:      print('[*] Error : The file is not a pyinstaller archive')      return False    print('[*] Python version: {0}'.format(self.pyver))    # Overlay is the data appended at the end of the PE    self.overlaySize = lengthofPackage    self.overlayPos = self.fileSize - self.overlaySize    self.tableOfContentsPos = self.overlayPos + toc    self.tableOfContentsSize = tocLen    print('[*] Length of package: {0} bytes'.format(self.overlaySize))    return True  def parseTOC(self):    # Go to the table of contents    self.fPtr.seek(self.tableOfContentsPos, os.SEEK_SET)    self.tocList = []    parsedLen = 0    # Parse table of contents    while parsedLen < self.tableOfContentsSize:      (entrySize, ) = struct.unpack('!i', self.fPtr.read(4))      nameLen = struct.calcsize('!iiiiBc')      (entryPos, cmprsdDataSize, uncmprsdDataSize, cmprsFlag, typeCmprsData, name) = \      struct.unpack( \        '!iiiBc{0}s'.format(entrySize - nameLen), \        self.fPtr.read(entrySize - 4))      name = name.decode('utf-8').rstrip('\0')      if len(name) == 0:        name = str(uniquename())        print('[!] Warning: Found an unamed file in CArchive. Using random name {0}'.format(name))      self.tocList.append( \    CTOCEntry(           \      self.overlayPos + entryPos, \      cmprsdDataSize,       \      uncmprsdDataSize,      \      cmprsFlag,         \      typeCmprsData,       \      name\    ))      parsedLen += entrySize    print('[*] Found {0} files in CArchive'.format(len(self.tocList)))  def extractFiles(self):    print('[*] Beginning extraction...please standby')    extractionDir = os.path.join(os.getcwd(), os.path.basename(self.filePath) + '_extracted')    if not os.path.exists(extractionDir):      os.mkdir(extractionDir)    os.chdir(extractionDir)    for entry in self.tocList:      basePath = os.path.dirname(entry.name)      if basePath != '':        # Check if path exists, create if not        if not os.path.exists(basePath):          os.makedirs(basePath)      self.fPtr.seek(entry.position, os.SEEK_SET)      data = self.fPtr.read(entry.cmprsdDataSize)      if entry.cmprsFlag == 1:        data = zlib.decompress(data)        # Malware may tamper with the uncompressed size        # Comment out the assertion in such a case        assert len(data) == entry.uncmprsdDataSize # Sanity Check      with open(entry.name, 'wb') as f:        f.write(data)      if entry.typeCmprsData == b's':        print('[+] Possible entry point: {0}'.format(entry.name))      elif entry.typeCmprsData == b'z' or entry.typeCmprsData == b'Z':        self._extractPyz(entry.name)  def _extractPyz(self, name):    dirName = name + '_extracted'    # Create a directory for the contents of the pyz    if not os.path.exists(dirName):      os.mkdir(dirName)    with open(name, 'rb') as f:      pyzMagic = f.read(4)      assert pyzMagic == b'PYZ\0' # Sanity Check      pycHeader = f.read(4) # Python magic value      if imp.get_magic() != pycHeader:        print('[!] Warning: The script is running in a different python version than the one used to build the executable')        print('  Run this script in Python{0} to prevent extraction errors(if any) during unmarshalling'.format(self.pyver))      (tocPosition, ) = struct.unpack('!i', f.read(4))      f.seek(tocPosition, os.SEEK_SET)      try:        toc = marshal.load(f)      except:        print('[!] Unmarshalling FAILED. Cannot extract {0}. Extracting remaining files.'.format(name))        return      print('[*] Found {0} files in PYZ archive'.format(len(toc)))      # From pyinstaller 3.1+ toc is a list of tuples      if type(toc) == list:        toc = dict(toc)      for key in toc.keys():        (ispkg, pos, length) = toc[key]        f.seek(pos, os.SEEK_SET)        fileName = key        try:          # for Python > 3.3 some keys are bytes object some are str object          fileName = key.decode('utf-8')        except:          pass        # Make sure destination directory exists, ensuring we keep inside dirName        destName = os.path.join(dirName, fileName.replace("..", "__"))        destDirName = os.path.dirname(destName)        if not os.path.exists(destDirName):          os.makedirs(destDirName)        try:          data = f.read(length)          data = zlib.decompress(data)        except:          print('[!] Error: Failed to decompress {0}, probably encrypted. Extracting as is.'.format(fileName))          open(destName + '.pyc.encrypted', 'wb').write(data)          continue        with open(destName + '.pyc', 'wb') as pycFile:          pycFile.write(pycHeader)   # Write pyc magic          pycFile.write(b'\0' * 4)   # Write timestamp          if self.pyver >= 33:pycFile.write(b'\0' * 4) # Size parameter added in Python 3.3          pycFile.write(data)def main():  if len(sys.argv) < 2:    print('[*] Usage: pyinstxtractor.py <filename>')  else:    arch = PyInstArchive(sys.argv[1])    if arch.open():      if arch.checkFile():        if arch.getCArchiveInfo():          arch.parseTOC()          arch.extractFiles()          arch.close()          print('[*] Successfully extracted pyinstaller archive: {0}'.format(sys.argv[1]))          print('')          print('You can now use a python decompiler on the pyc files within the extracted directory')          return      arch.close()if __name__ == '__main__':  main()

总结

以上所述是小编给大家介绍的python 反编译exe文件为py文件的实例代码,希望对大家有所帮助,如果大家有任何疑问欢迎给我留言,小编会及时回复大家的!


  • 上一条:
    在Python中合并字典模块ChainMap的隐藏坑【推荐】
    下一条:
    Python 使用PyQt5 完成选择文件或目录的对话框方法
  • 昵称:

    邮箱:

    0条评论 (评论内容有缓存机制,请悉知!)
    最新最热
    • 分类目录
    • 人生(杂谈)
    • 技术
    • linux
    • Java
    • php
    • 框架(架构)
    • 前端
    • ThinkPHP
    • 数据库
    • 微信(小程序)
    • Laravel
    • Redis
    • Docker
    • Go
    • swoole
    • Windows
    • Python
    • 苹果(mac/ios)
    • 相关文章
    • 在python语言中Flask框架的学习及简单功能示例(0个评论)
    • 在Python语言中实现GUI全屏倒计时代码示例(0个评论)
    • Python + zipfile库实现zip文件解压自动化脚本示例(0个评论)
    • python爬虫BeautifulSoup快速抓取网站图片(1个评论)
    • vscode 配置 python3开发环境的方法(0个评论)
    • 近期文章
    • 在go语言中使用api.geonames.org接口实现根据国际邮政编码获取地址信息功能(1个评论)
    • 在go语言中使用github.com/signintech/gopdf实现生成pdf分页文件功能(0个评论)
    • gmail发邮件报错:534 5.7.9 Application-specific password required...解决方案(0个评论)
    • 欧盟关于强迫劳动的规定的官方举报渠道及官方举报网站(0个评论)
    • 在go语言中使用github.com/signintech/gopdf实现生成pdf文件功能(0个评论)
    • Laravel从Accel获得5700万美元A轮融资(0个评论)
    • 在go + gin中gorm实现指定搜索/区间搜索分页列表功能接口实例(0个评论)
    • 在go语言中实现IP/CIDR的ip和netmask互转及IP段形式互转及ip是否存在IP/CIDR(0个评论)
    • PHP 8.4 Alpha 1现已发布!(0个评论)
    • Laravel 11.15版本发布 - Eloquent Builder中添加的泛型(0个评论)
    • 近期评论
    • 122 在

      学历:一种延缓就业设计,生活需求下的权衡之选中评论 工作几年后,报名考研了,到现在还没认真学习备考,迷茫中。作为一名北漂互联网打工人..
    • 123 在

      Clash for Windows作者删库跑路了,github已404中评论 按理说只要你在国内,所有的流量进出都在监控范围内,不管你怎么隐藏也没用,想搞你分..
    • 原梓番博客 在

      在Laravel框架中使用模型Model分表最简单的方法中评论 好久好久都没看友情链接申请了,今天刚看,已经添加。..
    • 博主 在

      佛跳墙vpn软件不会用?上不了网?佛跳墙vpn常见问题以及解决办法中评论 @1111老铁这个不行了,可以看看近期评论的其他文章..
    • 1111 在

      佛跳墙vpn软件不会用?上不了网?佛跳墙vpn常见问题以及解决办法中评论 网站不能打开,博主百忙中能否发个APP下载链接,佛跳墙或极光..
    • 2016-10
    • 2016-11
    • 2018-04
    • 2020-03
    • 2020-04
    • 2020-05
    • 2020-06
    • 2022-01
    • 2023-07
    • 2023-10
    Top

    Copyright·© 2019 侯体宗版权所有· 粤ICP备20027696号 PHP交流群

    侯体宗的博客