如何用Frida JS代码Hook获取com.n.a.w应用的md生成值
Hey there! Let's tackle this Frida hooking problem step by step. You've already made great progress narrowing down the md parameter's origin to the com.n.a.a package—now let's build a script to expose its generation logic.
Step 1: Frida JS Script to Monitor the Target Package
Below is a Frida script that enumerates all classes in com.n.a.a, hooks their methods, and logs arguments/return values. This will help you pinpoint exactly which method generates the md string:
Java.perform(function() { // Enumerate all classes in the target package var classNames = Java.enumerateClassNamesSync(); var targetPackage = "com.n.a.a"; classNames.forEach(function(className) { if (className.startsWith(targetPackage)) { try { var clazz = Java.use(className); // Hook all non-constructor methods of the class clazz.$methods.forEach(function(method) { var methodName = method.name; if (methodName !== "<init>") { // Handle no-argument methods if (clazz[methodName].overload) { clazz[methodName].overload().implementation = function() { console.log(`[+] Called ${className}.${methodName}()`); var result = this[methodName](); // Log string returns (since md is a string) if (typeof result === 'string') { console.log(` Returned: ${result}`); // Check if the return matches md's pattern (adjust regex if needed) if (result.match(/^[0-9a-fs]+$/)) { console.log(" [!] Potential md parameter found!"); } } return result; }; } // Handle overloaded methods with parameters var overloads = clazz[methodName].overloads; overloads.forEach(function(overload) { overload.implementation = function() { var args = Array.from(arguments); console.log(`[+] Called ${className}.${methodName} with args: ${JSON.stringify(args)}`); var result = this[methodName].apply(this, args); if (typeof result === 'string') { console.log(` Returned: ${result}`); if (result.match(/^[0-9a-fs]+$/)) { console.log(" [!] Potential md parameter found!"); } } return result; }; }); } }); } catch (e) { // Skip unhookable classes (like abstract ones) console.log(`[-] Failed to hook ${className}: ${e.message}`); } } }); // Optional: Hook network requests to confirm when md is sent try { var OkHttpClient = Java.use("okhttp3.OkHttpClient"); OkHttpClient.newCall.implementation = function(request) { var url = request.url().toString(); console.log(`[*] Outgoing Request URL: ${url}`); // Extract md parameter if present if (url.includes("md=")) { var mdValue = url.split("md=")[1].split("&")[0]; console.log(`[!] md parameter detected: ${mdValue}`); } return this.newCall(request); }; } catch (e) { console.log(`[-] OkHttpClient not found, skipping network hook: ${e.message}`); } });
Step 2: Integrate with Your Python Framework
Replace the empty jscode in your existing Python script with the above JS code. Here's the complete working script:
import sys,frida Hook_package = "com.n.a.w" def on_message(message,data): if message['type'] == 'send': print(f"[Frida] {message['payload']}") elif message['type'] == 'error': print(f"[Frida Error] {message['stack']}") jscode = """ Java.perform(function() { // Enumerate all classes in the target package var classNames = Java.enumerateClassNamesSync(); var targetPackage = "com.n.a.a"; classNames.forEach(function(className) { if (className.startsWith(targetPackage)) { try { var clazz = Java.use(className); // Hook all non-constructor methods of the class clazz.$methods.forEach(function(method) { var methodName = method.name; if (methodName !== "<init>") { // Handle no-argument methods if (clazz[methodName].overload) { clazz[methodName].overload().implementation = function() { console.log(`[+] Called ${className}.${methodName}()`); var result = this[methodName](); // Log string returns (since md is a string) if (typeof result === 'string') { console.log(` Returned: ${result}`); // Check if the return matches md's pattern (adjust regex if needed) if (result.match(/^[0-9a-fs]+$/)) { console.log(" [!] Potential md parameter found!"); } } return result; }; } // Handle overloaded methods with parameters var overloads = clazz[methodName].overloads; overloads.forEach(function(overload) { overload.implementation = function() { var args = Array.from(arguments); console.log(`[+] Called ${className}.${methodName} with args: ${JSON.stringify(args)}`); var result = this[methodName].apply(this, args); if (typeof result === 'string') { console.log(` Returned: ${result}`); if (result.match(/^[0-9a-fs]+$/)) { console.log(" [!] Potential md parameter found!"); } } return result; }; }); } }); } catch (e) { // Skip unhookable classes (like abstract ones) console.log(`[-] Failed to hook ${className}: ${e.message}`); } } }); // Optional: Hook network requests to confirm when md is sent try { var OkHttpClient = Java.use("okhttp3.OkHttpClient"); OkHttpClient.newCall.implementation = function(request) { var url = request.url().toString(); console.log(`[*] Outgoing Request URL: ${url}`); // Extract md parameter if present if (url.includes("md=")) { var mdValue = url.split("md=")[1].split("&")[0]; console.log(`[!] md parameter detected: ${mdValue}`); } return this.newCall(request); }; } catch (e) { console.log(`[-] OkHttpClient not found, skipping network hook: ${e.message}`); } }); """ try: device = frida.get_usb_device(timeout=10) pid = device.spawn([Hook_package]) print(f"App is starting.. pid:{pid}") process = device.attach(pid) device.resume(pid) script = process.create_script(jscode) script.on('message', on_message) print('[*] Running Frida') script.load() sys.stdin.read() except Exception as e: print(e)
Step 3: How to Use
- Ensure your Android device is connected via USB with USB Debugging enabled.
- Run the Python script—it will spawn the
com.n.a.wapp and attach Frida. - Perform actions in the app that trigger server communication (the action that sends the
mdparameter). - Check the console output:
- Look for lines marked
[!] Potential md parameter found!to identify the exact method generating the value. - The network hook will log when
mdis sent in a request, helping you cross-verify.
- Look for lines marked
Step 4: Refine the Hook
Once you find the specific method (e.g., com.n.a.a.MdGenerator.generate()), simplify the script to hook only that method for cleaner output:
Java.perform(function() { var MdGenerator = Java.use("com.n.a.a.MdGenerator"); MdGenerator.generate.implementation = function() { var result = this.generate(); console.log(`[+] md value generated: ${result}`); // Uncomment below to log arguments if the method takes any // var args = Array.from(arguments); // console.log(` Args used: ${JSON.stringify(args)}`); return result; }; });
This will give you precise insight into the input arguments (if any) and generated md value, letting you reverse-engineer the generation logic.
内容的提问来源于stack exchange,提问作者JiAco

