You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

修改AOSP后如何获取Android恶意软件POST请求的明文请求体?

获取OkHttp请求体明文的可行方案

针对你在AOSP中修改OkHttp相关代码时只能拿到RequestBody对象引用的问题,以下是几种直接获取明文请求体的方法:

  • 读取RequestBody字节流并转字符串
    在sendRequest函数中拿到RequestBody实例后,按以下步骤提取明文:

    1. 调用requestBody.content()获取输入流InputStream
    2. 根据请求体长度读取字节数组,再通过内容类型指定的编码(默认UTF-8)转换为字符串
      示例代码片段:
    if (request.body() != null) {
        RequestBody body = request.body();
        InputStream inputStream = body.content();
        byte[] bytes = new byte[(int) body.contentLength()];
        inputStream.read(bytes);
        Charset charset = body.contentType() != null ? body.contentType().charset(StandardCharsets.UTF_8) : StandardCharsets.UTF_8;
        String bodyStr = new String(bytes, charset);
        Log.i("MalwareDetect", "Request Body Plaintext: " + bodyStr);
        // 注意:流读取后需重新构建RequestBody,避免原请求失败
        RequestBody newBody = RequestBody.create(body.contentType(), bytes);
    }
    
  • 针对RequestBody子类做针对性解析
    你看到的com.android.okhttp.RequestBody$2是OkHttp内部匿名子类(如FormBody、ByteStringRequestBody等),可通过类型判断直接提取内容:

    • 若为FormBody:遍历size()个name(i)和value(i)键值对,拼接成表单字符串
    • 若为ByteStringRequestBody:直接调用byteString().utf8()获取字符串
    • 若为MultipartBody:遍历各part(),提取每个分块的body内容
      示例代码片段:
    RequestBody body = request.body();
    if (body instanceof FormBody) {
        FormBody formBody = (FormBody) body;
        StringBuilder sb = new StringBuilder();
        for (int i = 0; i < formBody.size(); i++) {
            sb.append(formBody.name(i)).append("=").append(formBody.value(i)).append("&");
        }
        if (sb.length() > 0) sb.deleteCharAt(sb.length() - 1);
        Log.i("MalwareDetect", "Form Body: " + sb.toString());
    }
    
  • 解决请求体不可重复读取的问题
    RequestBody的流只能读取一次,直接读取会导致原请求失败。可使用BufferedSink缓存内容,同时用于日志和原请求:

    if (request.body() != null) {
        RequestBody originalBody = request.body();
        Buffer buffer = new Buffer();
        originalBody.writeTo(buffer);
        Charset charset = originalBody.contentType() != null ? originalBody.contentType().charset(StandardCharsets.UTF_8) : StandardCharsets.UTF_8;
        String bodyStr = buffer.readString(charset);
        Log.i("MalwareDetect", "Request Body: " + bodyStr);
        // 重新构建RequestBody用于原请求
        RequestBody newBody = RequestBody.create(originalBody.contentType(), buffer.readByteString());
        Request newRequest = request.newBuilder().method(request.method(), newBody).build();
    }
    

这些方法可直接在你修改的Request.java或HttpEngine.java的sendRequest函数中实现,能直接获取提交数据的明文内容,满足恶意软件数据泄露检测的分析需求。

内容的提问来源于stack exchange,提问作者hashar mujahid

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.16 01:22:43