• unidbg-最右之白龙分析


    frida:

    function printApplication(){
        Java.perform(function (){
            var BaseApplication = Java.use("com/izuiyou/common/base/BaseApplication");
            var application = BaseApplication.getAppContext();
            console.log(application);
        })
    }
    
    • 1
    • 2
    • 3
    • 4
    • 5
    • 6
    • 7

    unidbg:

    package com.jniunidbg.part5;
    
    import com.github.unidbg.Emulator;
    import com.github.unidbg.arm.context.RegisterContext;
    import com.github.unidbg.debugger.BreakPointCallback;
    import com.github.unidbg.hook.hookzz.*;
    import com.github.unidbg.linux.android.dvm.AbstractJni;
    import com.github.unidbg.AndroidEmulator;
    import com.github.unidbg.Module;
    import com.github.unidbg.linux.android.AndroidEmulatorBuilder;
    import com.github.unidbg.linux.android.AndroidResolver;
    import com.github.unidbg.linux.android.dvm.*;
    import com.github.unidbg.linux.android.dvm.array.ByteArray;
    import com.github.unidbg.memory.Memory;
    import com.github.unidbg.memory.MemoryBlock;
    import com.github.unidbg.pointer.UnidbgPointer;
    import com.github.unidbg.utils.Inspector;
    import com.sun.jna.Pointer;
    
    import java.io.File;
    import java.nio.charset.StandardCharsets;
    
    
    public class zuiyou extends AbstractJni{
        private final AndroidEmulator emulator;
        private final VM vm;
        private final Module module;
        private final DvmClass NativeClass;
    
        zuiyou() {
            emulator = AndroidEmulatorBuilder.for32Bit().build(); // 创建模拟器实例
            final Memory memory = emulator.getMemory(); // 模拟器的内存操作接口
            memory.setLibraryResolver(new AndroidResolver(23)); // 设置系统类库解析
            vm = emulator.createDalvikVM(new File("unidbg-android/src/test/resources/lession2/part5/zuiyou/right573.apk")); // 创建Android虚拟机
            DalvikModule dm = vm.loadLibrary("net_crypto", true); // 加载so到虚拟内存
            module = dm.getModule(); //获取本SO模块的句柄
    
            vm.setJni(this);
            vm.setVerbose(true);
            dm.callJNI_OnLoad(emulator);
    
            NativeClass = vm.resolveClass("com/izuiyou/network/NetCrypto");
    
    //        emulator.traceRead(0x40358000,0x40358000+7);
            emulator.traceRead(0xbffff54cL,0xbffff54cL+0x7L);
            emulator.traceRead(0xbffff63cL,0xbffff63cL+0x7L);
        };
    
    
        public void callInit(){
            String methodSign = "native_init()V";
            NativeClass.callStaticJniMethodObject(emulator, methodSign);
        }
    
        private void callSign(){
            String methodSign = "sign(Ljava/lang/String;[B)Ljava/lang/String;";
            StringObject ret = NativeClass.callStaticJniMethodObject(emulator, methodSign, "12345", "lilac".getBytes(StandardCharsets.UTF_8));
            System.out.println(ret);
        };
    
        public static void main(String[] args) throws Exception {
            zuiyou test = new zuiyou();
            test.hookMemcpy();
            test.HookMemcmp();
            test.callInit();
            test.callSign();
        }
    
        public void hookMemcpy(){
    //        void *memcpy(void *str1, const void *str2, size_t n)
    //        str1 -- 指向用于存储复制内容的目标数组,类型强制转换为 void* 指针。
    //        str2 -- 指向要复制的数据源,类型强制转换为 void* 指针。
    //        n -- 要被复制的字节数。
            emulator.attach().addBreakPoint(module.findSymbolByName("memcpy").getAddress(), new BreakPointCallback() {
                // onEnter
                @Override
                public boolean onHit(Emulator<?> emulator, long address) {
                    RegisterContext registerContext = emulator.getContext();
                    UnidbgPointer str1 = registerContext.getPointerArg(0);
                    UnidbgPointer str2 = registerContext.getPointerArg(1);
                    int length = registerContext.getIntArg(2);
                    Inspector.inspect(str2.getByteArray(0, length), "要复制的数据源");
                    System.out.println("复制到的地方:"+str1.toString());
                    return true;
                }
            });
        }
    
        // hook C 库函数
        // int memcmp(const void *str1, const void *str2, size_t n)) 把存储区 str1 和存储区 str2 的前 n 个字节进行比较。
        public void HookMemcmp(){
            emulator.attach().addBreakPoint(module.findSymbolByName("memcmp").getAddress(), new BreakPointCallback() {
                @Override
                public boolean onHit(Emulator<?> emulator, long address) {
                    System.out.println("call memcmp 作比较");
                    RegisterContext registerContext = emulator.getContext();
                    UnidbgPointer arg1 = registerContext.getPointerArg(0);
                    UnidbgPointer arg2 = registerContext.getPointerArg(1);
                    int size = registerContext.getIntArg(2);
                    Inspector.inspect(arg1.getByteArray(0, size), "arg1");
                    Inspector.inspect(arg2.getByteArray(0, size), "arg2");
    
                    if(arg1.getString(0).equals("Context")){
                        emulator.attach().debug();
                    }
                    return true;
                }
            });
        }
    
        @Override
        public DvmObject<?> callStaticObjectMethodV(BaseVM vm, DvmClass dvmClass, String signature, VaList vaList) {
            switch (signature) {
                // cn.xiaochuankeji.tieba.AppController@1793a3b
                case "com/izuiyou/common/base/BaseApplication->getAppContext()Landroid/content/Context;":{
                    return vm.resolveClass("android/content/Context").newObject(null);
                }
            }
            return super.callStaticObjectMethodV(vm, dvmClass, signature, vaList);
        }
    
        @Override
        public DvmObject<?> callObjectMethodV(BaseVM vm, DvmObject<?> dvmObject, String signature, VaList vaList) {
            switch (signature){
                case "android/content/Context->getClass()Ljava/lang/Class;":{
                    return dvmObject.getObjectType();
                }
                // OK
                case "java/lang/Class->getSimpleName()Ljava/lang/String;":{
                    return new StringObject(vm, "Context");
                }
                case "android/content/Context->getFilesDir()Ljava/io/File;":{
                    return vm.resolveClass("java/io/File").newObject(signature);
                }
                case "java/io/File->getAbsolutePath()Ljava/lang/String;":{
                    String tag = dvmObject.getValue().toString();
                    if(tag.equals("android/content/Context->getFilesDir()Ljava/io/File;")){
                        return new StringObject(vm, "/data/data/"+vm.getPackageName()+"/files");
                    }
                }
            }
            return super.callObjectMethodV(vm, dvmObject, signature, vaList);
        }
    
        @Override
        public boolean callStaticBooleanMethodV(BaseVM vm, DvmClass dvmClass, String signature, VaList vaList) {
            switch (signature){
                case "android/os/Debug->isDebuggerConnected()Z":{
                    return false;
                }
            }
            return super.callStaticBooleanMethodV(vm, dvmClass, signature, vaList);
        }
    
    
    
        @Override
        public int callStaticIntMethodV(BaseVM vm, DvmClass dvmClass, String signature, VaList vaList) {
            switch (signature){
                case "android/os/Process->myPid()I":{
                    return emulator.getPid();
                }
            }
            return super.callStaticIntMethodV(vm, dvmClass, signature, vaList);
        }
    }
    
    
    • 1
    • 2
    • 3
    • 4
    • 5
    • 6
    • 7
    • 8
    • 9
    • 10
    • 11
    • 12
    • 13
    • 14
    • 15
    • 16
    • 17
    • 18
    • 19
    • 20
    • 21
    • 22
    • 23
    • 24
    • 25
    • 26
    • 27
    • 28
    • 29
    • 30
    • 31
    • 32
    • 33
    • 34
    • 35
    • 36
    • 37
    • 38
    • 39
    • 40
    • 41
    • 42
    • 43
    • 44
    • 45
    • 46
    • 47
    • 48
    • 49
    • 50
    • 51
    • 52
    • 53
    • 54
    • 55
    • 56
    • 57
    • 58
    • 59
    • 60
    • 61
    • 62
    • 63
    • 64
    • 65
    • 66
    • 67
    • 68
    • 69
    • 70
    • 71
    • 72
    • 73
    • 74
    • 75
    • 76
    • 77
    • 78
    • 79
    • 80
    • 81
    • 82
    • 83
    • 84
    • 85
    • 86
    • 87
    • 88
    • 89
    • 90
    • 91
    • 92
    • 93
    • 94
    • 95
    • 96
    • 97
    • 98
    • 99
    • 100
    • 101
    • 102
    • 103
    • 104
    • 105
    • 106
    • 107
    • 108
    • 109
    • 110
    • 111
    • 112
    • 113
    • 114
    • 115
    • 116
    • 117
    • 118
    • 119
    • 120
    • 121
    • 122
    • 123
    • 124
    • 125
    • 126
    • 127
    • 128
    • 129
    • 130
    • 131
    • 132
    • 133
    • 134
    • 135
    • 136
    • 137
    • 138
    • 139
    • 140
    • 141
    • 142
    • 143
    • 144
    • 145
    • 146
    • 147
    • 148
    • 149
    • 150
    • 151
    • 152
    • 153
    • 154
    • 155
    • 156
    • 157
    • 158
    • 159
    • 160
    • 161
    • 162
    • 163
    • 164
    • 165
    • 166
    • 167
  • 相关阅读:
    经典web开发工程师面试题
    Makefile 初期学习笔记
    西瓜书-2.5偏差与方差
    【selenium自动化过程中的api抓包】browsermobproxy的安装和配置
    Linux grep 文本搜索工具
    Python接口自动化测试 —— Selenium+pytest+数据驱动
    Docker部署深度学习模型
    面试官问我 “A + B” 算法,我懵了
    【GBASE培训】GBase数据库2022年第6期培训圆满结束
    一次想不到的 Bootstrap 类加载器带来的 Native 内存泄露分析
  • 原文地址:https://blog.csdn.net/weixin_38927522/article/details/128083182