TLDR 我希望使用 Frida 调用 Android 应用程序中未使用的方法并取回其值。目前,我的脚本输出中没有任何回报。
安卓应用代码:
package securisec.com.methods;
import android.support.v7.app.AppCompatActivity;
import android.os.Bundle;
public class MainActivity extends AppCompatActivity {
@Override
protected void onCreate(Bundle savedInstanceState) {
super.onCreate(savedInstanceState);
setContentView(R.layout.activity_main);
}
public static String strings(){
return "This is a string method";
}
}
如您所见,该strings
方法从未使用过。我希望能够使用 Frida 调用此方法并获取返回值。
这是我的python脚本不起作用。
import frida
from time import sleep
call_back_message = ''
def on_message(message, payload):
global call_back_message
if message['type'] == 'send':
call_back_message = message['payload']
return call_back_message
def object_hooking(comName, className, method):
process = frida.get_usb_device()
pid = process.spawn([comName])
process.resume(pid)
sleep(1)
js = """
Java.perform(function()
{
var getVal = Java.use('%s.%s');
console.log(getVal)
var cons = getVal.$new();
console.log(cons)
var solution = cons.%s;
var send_it = solution.toString();
send(send_it);
});""" % (comName, className, method)
session = process.attach(pid)
script = session.create_script(js)
script.on('message', on_message)
script.load()
return call_back_message
print(object_hooking(
comName='securisec.com.methods',
className='MainActivity',
method='strings()'
))