You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何用Frida JS代码Hook获取com.n.a.w应用的md生成值

Hook to Capture MD Parameter Generation Logic for com.n.a.w

Hey there! Let's tackle this Frida hooking problem step by step. You've already made great progress narrowing down the md parameter's origin to the com.n.a.a package—now let's build a script to expose its generation logic.

Step 1: Frida JS Script to Monitor the Target Package

Below is a Frida script that enumerates all classes in com.n.a.a, hooks their methods, and logs arguments/return values. This will help you pinpoint exactly which method generates the md string:

Java.perform(function() {
    // Enumerate all classes in the target package
    var classNames = Java.enumerateClassNamesSync();
    var targetPackage = "com.n.a.a";

    classNames.forEach(function(className) {
        if (className.startsWith(targetPackage)) {
            try {
                var clazz = Java.use(className);
                // Hook all non-constructor methods of the class
                clazz.$methods.forEach(function(method) {
                    var methodName = method.name;
                    if (methodName !== "<init>") {
                        // Handle no-argument methods
                        if (clazz[methodName].overload) {
                            clazz[methodName].overload().implementation = function() {
                                console.log(`[+] Called ${className}.${methodName}()`);
                                var result = this[methodName]();
                                // Log string returns (since md is a string)
                                if (typeof result === 'string') {
                                    console.log(`    Returned: ${result}`);
                                    // Check if the return matches md's pattern (adjust regex if needed)
                                    if (result.match(/^[0-9a-fs]+$/)) {
                                        console.log("    [!] Potential md parameter found!");
                                    }
                                }
                                return result;
                            };
                        }

                        // Handle overloaded methods with parameters
                        var overloads = clazz[methodName].overloads;
                        overloads.forEach(function(overload) {
                            overload.implementation = function() {
                                var args = Array.from(arguments);
                                console.log(`[+] Called ${className}.${methodName} with args: ${JSON.stringify(args)}`);
                                var result = this[methodName].apply(this, args);
                                if (typeof result === 'string') {
                                    console.log(`    Returned: ${result}`);
                                    if (result.match(/^[0-9a-fs]+$/)) {
                                        console.log("    [!] Potential md parameter found!");
                                    }
                                }
                                return result;
                            };
                        });
                    }
                });
            } catch (e) {
                // Skip unhookable classes (like abstract ones)
                console.log(`[-] Failed to hook ${className}: ${e.message}`);
            }
        }
    });

    // Optional: Hook network requests to confirm when md is sent
    try {
        var OkHttpClient = Java.use("okhttp3.OkHttpClient");
        OkHttpClient.newCall.implementation = function(request) {
            var url = request.url().toString();
            console.log(`[*] Outgoing Request URL: ${url}`);
            // Extract md parameter if present
            if (url.includes("md=")) {
                var mdValue = url.split("md=")[1].split("&")[0];
                console.log(`[!] md parameter detected: ${mdValue}`);
            }
            return this.newCall(request);
        };
    } catch (e) {
        console.log(`[-] OkHttpClient not found, skipping network hook: ${e.message}`);
    }
});

Step 2: Integrate with Your Python Framework

Replace the empty jscode in your existing Python script with the above JS code. Here's the complete working script:

import sys,frida
Hook_package = "com.n.a.w"
def on_message(message,data):
    if message['type'] == 'send':
        print(f"[Frida] {message['payload']}")
    elif message['type'] == 'error':
        print(f"[Frida Error] {message['stack']}")

jscode = """
Java.perform(function() {
    // Enumerate all classes in the target package
    var classNames = Java.enumerateClassNamesSync();
    var targetPackage = "com.n.a.a";

    classNames.forEach(function(className) {
        if (className.startsWith(targetPackage)) {
            try {
                var clazz = Java.use(className);
                // Hook all non-constructor methods of the class
                clazz.$methods.forEach(function(method) {
                    var methodName = method.name;
                    if (methodName !== "<init>") {
                        // Handle no-argument methods
                        if (clazz[methodName].overload) {
                            clazz[methodName].overload().implementation = function() {
                                console.log(`[+] Called ${className}.${methodName}()`);
                                var result = this[methodName]();
                                // Log string returns (since md is a string)
                                if (typeof result === 'string') {
                                    console.log(`    Returned: ${result}`);
                                    // Check if the return matches md's pattern (adjust regex if needed)
                                    if (result.match(/^[0-9a-fs]+$/)) {
                                        console.log("    [!] Potential md parameter found!");
                                    }
                                }
                                return result;
                            };
                        }

                        // Handle overloaded methods with parameters
                        var overloads = clazz[methodName].overloads;
                        overloads.forEach(function(overload) {
                            overload.implementation = function() {
                                var args = Array.from(arguments);
                                console.log(`[+] Called ${className}.${methodName} with args: ${JSON.stringify(args)}`);
                                var result = this[methodName].apply(this, args);
                                if (typeof result === 'string') {
                                    console.log(`    Returned: ${result}`);
                                    if (result.match(/^[0-9a-fs]+$/)) {
                                        console.log("    [!] Potential md parameter found!");
                                    }
                                }
                                return result;
                            };
                        });
                    }
                });
            } catch (e) {
                // Skip unhookable classes (like abstract ones)
                console.log(`[-] Failed to hook ${className}: ${e.message}`);
            }
        }
    });

    // Optional: Hook network requests to confirm when md is sent
    try {
        var OkHttpClient = Java.use("okhttp3.OkHttpClient");
        OkHttpClient.newCall.implementation = function(request) {
            var url = request.url().toString();
            console.log(`[*] Outgoing Request URL: ${url}`);
            // Extract md parameter if present
            if (url.includes("md=")) {
                var mdValue = url.split("md=")[1].split("&")[0];
                console.log(`[!] md parameter detected: ${mdValue}`);
            }
            return this.newCall(request);
        };
    } catch (e) {
        console.log(`[-] OkHttpClient not found, skipping network hook: ${e.message}`);
    }
});
"""
try:
    device = frida.get_usb_device(timeout=10)
    pid = device.spawn([Hook_package])
    print(f"App is starting.. pid:{pid}")
    process = device.attach(pid)
    device.resume(pid)
    script = process.create_script(jscode)
    script.on('message', on_message)
    print('[*] Running Frida')
    script.load()
    sys.stdin.read()
except Exception as e:
    print(e)

Step 3: How to Use

  1. Ensure your Android device is connected via USB with USB Debugging enabled.
  2. Run the Python script—it will spawn the com.n.a.w app and attach Frida.
  3. Perform actions in the app that trigger server communication (the action that sends the md parameter).
  4. Check the console output:
    • Look for lines marked [!] Potential md parameter found! to identify the exact method generating the value.
    • The network hook will log when md is sent in a request, helping you cross-verify.

Step 4: Refine the Hook

Once you find the specific method (e.g., com.n.a.a.MdGenerator.generate()), simplify the script to hook only that method for cleaner output:

Java.perform(function() {
    var MdGenerator = Java.use("com.n.a.a.MdGenerator");
    MdGenerator.generate.implementation = function() {
        var result = this.generate();
        console.log(`[+] md value generated: ${result}`);
        // Uncomment below to log arguments if the method takes any
        // var args = Array.from(arguments);
        // console.log(`    Args used: ${JSON.stringify(args)}`);
        return result;
    };
});

This will give you precise insight into the input arguments (if any) and generated md value, letting you reverse-engineer the generation logic.

内容的提问来源于stack exchange,提问作者JiAco

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.08 08:48:17