You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Frida Hook函数无输出求助:确认函数执行但无响应

Frida Hook静态函数无输出问题解决

问题概述

Hook com.che168.autotradercloud.util.SPUtils类的saveDeviceId静态函数正常输出,但同类的getDeviceId静态函数确认被应用执行,却无任何日志输出,全程无报错。环境:Frida 16.0.1,Python 3.7.9。

相关代码

Hook脚本:

import frida
import sys

rdev = frida.get_remote_device()
session = rdev.attach("com.che168.autotradercloud")

scr = """
Java.perform(function () {
    var SPUtils = Java.use("com.che168.autotradercloud.util.SPUtils");

    SPUtils.saveDeviceId.implementation = function(str){
        console.log("set device_id",str);
        this.saveDeviceId(str);
    }
    
    SPUtils.getDeviceId.implementation = function(){
        var res = this.getDeviceId();
        console.log("get id",res);
        return res;
    }
});
"""

script = session.create_script(scr)
def on_message(message, data):
    print(message, data)
script.on("message", on_message)
script.load()
sys.stdin.read()

反编译源码片段:

public static void saveDeviceId(String str) {
       getSpUtil().saveString(KEY_DEVICE_ID, str);
}

public static String getDeviceId() {
       return getSpUtil().getString(KEY_DEVICE_ID, "");
}

解决方案

1. 修正静态函数的原方法调用逻辑

getDeviceId是静态函数,Frida中Hook静态函数时,this并非指向类实例,用this.getDeviceId()调用原方法会导致逻辑静默失败,需通过类本身调用:

SPUtils.getDeviceId.implementation = function(){
    var res = SPUtils.getDeviceId.call(this);
    console.log("get id", res);
    return res;
}

或简化写法:

SPUtils.getDeviceId.implementation = function(){
    var res = SPUtils.getDeviceId();
    console.log("get id", res);
    return res;
}

2. 排查函数内联优化

如果修正后仍无输出,可能是getDeviceId被编译器内联优化,Frida无法通过常规方式拦截,可直接Hook函数内存地址:

Java.perform(function () {
    var SPUtils = Java.use("com.che168.autotradercloud.util.SPUtils");
    Interceptor.attach(SPUtils.getDeviceId.handle, {
        onEnter: function(args) {
            console.log("getDeviceId invoked");
        },
        onLeave: function(retval) {
            console.log("getDeviceId result:", retval.readUtf8String());
        }
    });
});

3. 验证类加载器唯一性

若应用使用自定义类加载器,可能存在多个同名类实例,可枚举类加载器并Hook对应类:

Java.perform(function () {
    Java.enumerateClassLoaders({
        onMatch: function(loader) {
            try {
                var cls = loader.loadClass("com.che168.autotradercloud.util.SPUtils");
                var SPUtils = Java.use(cls);
                SPUtils.getDeviceId.implementation = function(){
                    var res = SPUtils.getDeviceId();
                    console.log("get id (from loader)", res);
                    return res;
                }
            } catch(e) {}
        },
        onComplete: function() {}
    });
});

内容的提问来源于stack exchange,提问作者guidingg

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.07 22:10:05