1 需求
通過(guò)frida rpc調(diào)用真機(jī)獲取指定關(guān)鍵字的搜索結(jié)果數(shù)據(jù)。
本文僅供大家學(xué)習(xí)及研究使用、切勿用于各種非法用途。
2 rpc 簡(jiǎn)介
frida 提供了一種跨平臺(tái)的 rpc (遠(yuǎn)程過(guò)程調(diào)用)機(jī)制,通過(guò) frida rpc 可以在主機(jī)和目標(biāo)設(shè)備之間進(jìn)行通信,并在目標(biāo)設(shè)備上執(zhí)行代碼,可實(shí)現(xiàn)功能如下:
1、動(dòng)態(tài)地修改函數(shù)和方法的參數(shù)和返回值。
2、監(jiān)視和攔截特定函數(shù)和方法的調(diào)用。
3、修改內(nèi)存中的數(shù)據(jù)和指令。
4、與目標(biāo)設(shè)備上的應(yīng)用程序進(jìn)行交互,發(fā)送和接收數(shù)據(jù)。
5、在運(yùn)行時(shí)加載自己的 JavaScript 腳本,從而實(shí)現(xiàn)自定義的行為修改。
3 軟硬件工具
app 版本:7.4.70
設(shè)備:K40 刷 piexl 11 rom
抓包工具:Charles
反匯編工具:JEB、JADX、IDA
inject:frida
4 抓包
POST /gw/mtop.taobao.idle.search.glue/8.0/ HTTP/1.1
x-sgext: JAfKISv0W5XonL3HUeX4UiH7EfgS%2BwL4F%2FIX8wL7F%2FoC%2BQ3%2FDfoN%2Bw37DfsN%2Bw37DfsN%2Bw35E%2BYQ5hL4DfkT5hHmEeYR5hHmEeYR5hHmEeYR5hHmEOYX%2Bg38EeYT%2Bg36DfoN%2BBnpEPwW%2BBH%2FF%2FoQ%2FQL6E6lA%2BhH6EPlH%2FRWoFvMT6RD%2FGekY6RL%2BAvoR%2BhbpEukQ6RDpEOkQ6RDpE%2BkQ6RP6AvkC%2FwKpAvoC%2BgL6AvoC%2BgLpROlHrwL6AqxEr0T6FukR%2BhH6EQ%3D%3D
umid: Y6mM0d1XDnwDAAZc4d8Tk60B
x-sign: azU7Bc002xAAJzB6M9wiB4WMskX6dzB3PW%2F64QfVy78rMahh4hODtL0DoF9kmgIWRqfEkGhlFlqjHfQDYE50A5EzkuewtzB3MLcwdz
x-nettype: WIFI
x-pv: 6.3
x-nq: WIFI
EagleEye-UserData: spm-cnt=a2170.8011571.0.0&spm-url=a2170.unknown.0.0
first_open: 1
x-features: 27
x-app-conf-v: 0
x-mini-wua: HHnB_QQx7EhGYzt0aRv0%2BjcjSfSTdMh9NXopIhtlxCcIGWkyEPONy4fMU296Q4NG4PEFmdynoG21RVXefkf%2Ff8G%2Fqlkl8cahX%2BEk3JT5GB2Uh4TNEqzzblgemWV%2Bitf42AKL%2FrWZLKkzalExnviNeICDt5A%3D%3D
content-type: application/x-www-form-urlencoded;charset=UTF-8
Content-Length: 630
x-t: 1672056548
Content-Type: application/x-www-form-urlencoded;charset=UTF-8
x-bx-version: 6.5.56
f-refer: mtop
x-extdata: openappkey%3DDEFAULT_AUTH
x-ttid: 231200%40fleamarket_android_7.4.70
x-app-ver: 7.4.70
x-c-traceid: Y6mM0d1XDnwDAAZc4d8Tk60B16720565484910160126869
x-location: 0%2C0
x-umt: 2QMB7AlLPMcI7wKFTpWcJNO9Tq3ykFES
a-orange-q: appKey=21407387&appVersion=7.4.70&clientAppIndexVersion=1120221225203700833&clientVersionIndexVersion=0
x-utdid: Y6mM0d1XDnwDAAZc4d8Tk60B
x-appkey: 21407387
x-devid: AnlVbDHuTb2u0LWMPSEZxO4CdI4PNLcEAjN85BBOipB9
user-agent: MTOPSDK%2F3.1.1.7+%28Android%3B11%3BXiaomi%3BM2012K11AC%29
Host: g-acs.m.goofish.com
Accept-Encoding: gzip
Connection: Keep-Alive
data=%7B%22activeSearch%22%3Afalse%2C%22bizFrom%22%3A%22home%22%2C%22disableHierarchicalSort%22%3A0%2C%22forceUseInputKeyword%22%3Afalse%2C%22forceUseTppRepair%22%3Afalse%2C%22fromFilter%22%3Afalse%2C%22fromKits%22%3Afalse%2C%22fromLeaf%22%3Afalse%2C%22fromShade%22%3Afalse%2C%22fromSuggest%22%3Afalse%2C%22keyword%22%3A%22%E4%B8%9D%E8%A2%9C%22%2C%22pageNumber%22%3A1%2C%22resultListLastIndex%22%3A0%2C%22rowsPerPage%22%3A10%2C%22searchReqFromActivatePagePart%22%3A%22historyItem%22%2C%22searchReqFromPage%22%3A%22xyHome%22%2C%22searchTabType%22%3A%22SEARCH_TAB_MAIN%22%2C%22shadeBucketNum%22%3A-1%2C%22suggestBucketNum%22%3A27%7D
多次抓包,發(fā)現(xiàn)變化的字段有:
x-sgext、x-sign、x-mini-wua、x-c-traceid、x-t、Content-Length
5 參數(shù)分析
先從 x-sign 值入手, apk 包拖入 jadx 搜索,得到以下結(jié)果:
?一個(gè)個(gè)點(diǎn)進(jìn)去查看,發(fā)現(xiàn)并沒(méi)有有價(jià)值的東西,僅僅只是構(gòu)建字段名等操作,并且我嘗試 hook 這些點(diǎn),并沒(méi)有得到有用的信息,換 JEB 看看,反復(fù)搜索觀察,最終定位到 getUnifiedSign 這個(gè)函數(shù):
?
跟進(jìn)查看它有三處調(diào)用點(diǎn):
1 2 3 4 5 |
|
解析:
第 1 處定義了 ISign 的接口,并寫了 getUnifiedSign 方法,代碼有刪減:
1 2 3 |
|
第 2 處定義了一個(gè)抽象類 AbstractSignImpl 實(shí)現(xiàn)了 ISign 接口中的 getUnifiedSign 方法,當(dāng)類實(shí)現(xiàn)接口的時(shí)候,類要實(shí)現(xiàn)接口中所有的方法。否則,類必須聲明為抽象的類。該處聲明的為抽象類,并不需要實(shí)現(xiàn)接口,代碼有刪減:
1 2 3 4 5 6 |
|
第 3 處定義了 InnerSignImpl 類繼承 AbstractSignImpl,java中規(guī)定抽象類的子類必須給出抽象類中的抽象方法的具體實(shí)現(xiàn),除非該子類也是抽象類。InnerSignImpl 并不是抽象類,也可以看出它實(shí)現(xiàn)了 getUnifiedSign 方法,代碼有刪減:
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 |
|
從該函數(shù)中不難發(fā)現(xiàn)里面包含了許多抓包中的參數(shù)信息,有理由懷疑程序就是在此處進(jìn)行組包并請(qǐng)求信息的!
6 hook getUnifiedSign
分析到這了,先 hook 看看 getUnifiedSign 函數(shù)請(qǐng)求和返回都是些啥,hook 代碼:
1 2 3 4 5 6 7 8 9 10 11 12 |
|
搜索關(guān)鍵字:黑絲。
結(jié)果:
getUnifiedSign is called,
params:
{data={"activeSearch":false,"bizFrom":"home","disableHierarchicalSort":0,"forceUseInputKeyword":false,"forceUseTppRepair":false,"fromFilter":false,"fromKits":false,"fromLeaf":false,"fromShade":false,"fromSuggest":false,"keyword":"黑絲","pageNumber":1,"resultListLastIndex":0,"rowsPerPage":10,"searchReqFromActivatePagePart":"searchButton","searchReqFromPage":"xyHome","searchTabType":"SEARCH_TAB_MAIN","shadeBucketNum":-1,"suggestBucketNum":27}, deviceId=AnlVbDHuTb2u0LWMPSEZxO4CdI4PNLcEAjN85BBOipB9, sid=null, uid=null, x-features=27, appKey=21407387, api=mtop.taobao.idle.search.glue, lat=0, lng=0, utdid=Y6mM0d1XDnwDAAZc4d8Tk60B, extdata=openappkey=DEFAULT_AUTH, ttid=231200@fleamarket_android_7.4.70, t=1672065081, v=8.0}
ext:
{pageId=, pageName=}
appKey:
21407387
authCode:
null
useWua:
false
requestId:
r_342
getUnifiedSign ret value is
{x-sgext=JAc6QkgEOGWLbN43MhWbokILcghxC2EIdAJ0A2EJdghhCW4PbgpuC24LbgtuC24LbgtuC24MdRZzFnQNbgx1FnIWchZyFnIWchZyFnIWchZyFnIWcxZzDncWcw53FnEWchZyFnACYQt0DXAKdwxyC3UZcgghW3IKcgtxXHUOIA17CGEJdgphA2EJdhlyCnINYQlhC2ELYQthC2ELYQhhC2EOcRlxGXUZcw5hCmEKYQphCmEKYRknGSRfYQphXCdfJwInGXIKcgpy, x-umt=2QMB7AlLPMcI7wKFTpWcJNO9Tq3ykFES, x-mini-wua=HHnB_LsOm2MbDDQX8pocsAv844s/AJ3eeRpQBvQ0ruCym5E4E9z73i+wqyWX+kYoOCLjd0M+Af0hvQxs8NJyeS1/+qAd+g60eGM0Y7snvKtTeCvVhBnNESbEFrPu+orzouidZjoRxOAXN2Cpe1icpSFPKMA==, x-sign=azU7Bc002xAAJAe6xWI/sfnl+vxS1Be0CqzNIjAW/Hwc8p+i1dC0d4rAl5xTWTXVcWTzU1+mIZmU3sPAV41DwKbwpS1llAe0BZQHtA}文章來(lái)源:http://www.zghlxwxcb.cn/news/detail-729246.html
參數(shù)都在這了,這就好辦了,rpc 調(diào)用就能解決,注意這邊的 data 數(shù)據(jù)是進(jìn)行了 url 編碼的,需進(jìn)行進(jìn)一步轉(zhuǎn)化。文章來(lái)源地址http://www.zghlxwxcb.cn/news/detail-729246.html
到了這里,關(guān)于安卓協(xié)議逆向 咸魚(yú) frida rpc 調(diào)用方案的文章就介紹完了。如果您還想了解更多內(nèi)容,請(qǐng)?jiān)谟疑辖撬阉鱐OY模板網(wǎng)以前的文章或繼續(xù)瀏覽下面的相關(guān)文章,希望大家以后多多支持TOY模板網(wǎng)!