1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152
| package com.dta.lesson2;
import capstone.api.Instruction; import com.github.unidbg.AndroidEmulator; import com.github.unidbg.Module; import com.github.unidbg.arm.backend.Backend; import com.github.unidbg.arm.backend.BlockHook; import com.github.unidbg.arm.backend.CodeHook; import com.github.unidbg.arm.backend.UnHook; import com.github.unidbg.linux.android.AndroidEmulatorBuilder; import com.github.unidbg.linux.android.AndroidResolver; import com.github.unidbg.linux.android.dvm.DalvikModule; import com.github.unidbg.linux.android.dvm.DvmObject; import com.github.unidbg.linux.android.dvm.StringObject; import com.github.unidbg.linux.android.dvm.VM; import com.github.unidbg.linux.android.dvm.jni.ProxyDvmObject; import com.github.unidbg.memory.Memory; import com.sun.jna.Pointer;
import java.io.File; import java.util.ArrayList; import java.util.HashMap; import java.util.List; import java.util.Map;
public class MainActivity { private final AndroidEmulator emulator; private final VM vm; private final Memory memory; private final Module module;
public static Map<Integer, Integer> subTraceMap = new HashMap<>(); public static Map<Integer, Integer> calcMap = new HashMap<>();
private void traceBlock(final long baseAddr, final long startAddr, final long endAddr) { emulator.getBackend().hook_add_new(new BlockHook() { @Override public void hookBlock(Backend backend, long address, int size, Object user) { if (size > 20) { Instruction[] insns = emulator.disassemble(address, 4, 0); int iSize = insns[0].getSize(); int iUseAddr = 0;
if (iSize == 4) { iUseAddr = (int) (address - baseAddr); } else { iUseAddr = (int) (address - baseAddr) + 1; }
if (calcMap.containsKey(iUseAddr)) { int iValue = calcMap.get(iUseAddr); calcMap.put(iUseAddr, iValue + 1);
if (iValue > 3) { subTraceMap.remove(iUseAddr); } else { System.out.println("sub_" + Integer.toHexString(iUseAddr)); } } else { calcMap.put(iUseAddr, 1); subTraceMap.put(iUseAddr, 1); System.out.println("sub_" + Integer.toHexString(iUseAddr)); } } }
@Override public void onAttach(UnHook unHook) { }
@Override public void detach() { } }, startAddr, endAddr, 0); }
public MainActivity(){ emulator = AndroidEmulatorBuilder .for32Bit() .build();
memory = emulator.getMemory(); memory.setLibraryResolver(new AndroidResolver(23)); vm = emulator.createDalvikVM(new File("unidbg-android/src/test/java/com/dta/lesson2/app-debug.apk")); DalvikModule dalvikModule = vm.loadLibrary(new File("unidbg-android/src/test/java/com/dta/lesson2/libnative-lib.so"), true); module = dalvikModule.getModule(); vm.callJNI_OnLoad(emulator,module);
long baseAddr = module.base; long startAddr = baseAddr + 0x8E70; long endAddr = baseAddr + 0x8E90;
this.traceBlock(baseAddr, startAddr, endAddr);
this.callMd5();
System.out.println("Sub Trace Map: " + subTraceMap); System.out.println("Calc Map: " + calcMap);
}
public void callMd5(){ DvmObject obj = ProxyDvmObject.createObject(vm,this); String data = "dta"; DvmObject dvmObject = obj.callJniMethodObject(emulator, "md5(Ljava/lang/String;)Ljava/lang/String;", data); String result = (String) dvmObject.getValue(); System.out.println("[symble] Call the so md5 function result is ==> "+ result); }
public static void main(String[] args) { long start = System.currentTimeMillis(); MainActivity mainActivity = new MainActivity(); System.out.println("load the vm "+( System.currentTimeMillis() - start )+ "ms");
}
}
|