Frida Hook函数无输出求助:确认函数执行但无响应
Frida Hook静态函数无输出问题解决
问题概述
Hook com.che168.autotradercloud.util.SPUtils类的saveDeviceId静态函数正常输出,但同类的getDeviceId静态函数确认被应用执行,却无任何日志输出,全程无报错。环境:Frida 16.0.1,Python 3.7.9。
相关代码
Hook脚本:
import frida import sys rdev = frida.get_remote_device() session = rdev.attach("com.che168.autotradercloud") scr = """ Java.perform(function () { var SPUtils = Java.use("com.che168.autotradercloud.util.SPUtils"); SPUtils.saveDeviceId.implementation = function(str){ console.log("set device_id",str); this.saveDeviceId(str); } SPUtils.getDeviceId.implementation = function(){ var res = this.getDeviceId(); console.log("get id",res); return res; } }); """ script = session.create_script(scr) def on_message(message, data): print(message, data) script.on("message", on_message) script.load() sys.stdin.read()
反编译源码片段:
public static void saveDeviceId(String str) { getSpUtil().saveString(KEY_DEVICE_ID, str); } public static String getDeviceId() { return getSpUtil().getString(KEY_DEVICE_ID, ""); }
解决方案
1. 修正静态函数的原方法调用逻辑
getDeviceId是静态函数,Frida中Hook静态函数时,this并非指向类实例,用this.getDeviceId()调用原方法会导致逻辑静默失败,需通过类本身调用:
SPUtils.getDeviceId.implementation = function(){ var res = SPUtils.getDeviceId.call(this); console.log("get id", res); return res; }
或简化写法:
SPUtils.getDeviceId.implementation = function(){ var res = SPUtils.getDeviceId(); console.log("get id", res); return res; }
2. 排查函数内联优化
如果修正后仍无输出,可能是getDeviceId被编译器内联优化,Frida无法通过常规方式拦截,可直接Hook函数内存地址:
Java.perform(function () { var SPUtils = Java.use("com.che168.autotradercloud.util.SPUtils"); Interceptor.attach(SPUtils.getDeviceId.handle, { onEnter: function(args) { console.log("getDeviceId invoked"); }, onLeave: function(retval) { console.log("getDeviceId result:", retval.readUtf8String()); } }); });
3. 验证类加载器唯一性
若应用使用自定义类加载器,可能存在多个同名类实例,可枚举类加载器并Hook对应类:
Java.perform(function () { Java.enumerateClassLoaders({ onMatch: function(loader) { try { var cls = loader.loadClass("com.che168.autotradercloud.util.SPUtils"); var SPUtils = Java.use(cls); SPUtils.getDeviceId.implementation = function(){ var res = SPUtils.getDeviceId(); console.log("get id (from loader)", res); return res; } } catch(e) {} }, onComplete: function() {} }); });
内容的提问来源于stack exchange,提问作者guidingg
相关产品推荐
相关产品推荐

