HookYDSJ.js 7.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172
  1. import {logColor, LogColor} from "../logger";
  2. const IS_SAVE_ALL_JS = false;
  3. const TARGET_PACKAGE = "com.rbigkic.yyydsj";
  4. const targetModuleName = "libcocos2djs.so";
  5. let TAGET_DATA_FILES = `/data/data/${TARGET_PACKAGE}/files`;
  6. // const RE_PROJECT_PATH = `${TAGET_DATA_FILES}/index.jsc`;
  7. const RE_PROJECT_PATH = `/data/local/tmp/index.jsc`;
  8. // 命令
  9. // adb push D:\Project_Repostory\HookCli\yyyy_js\assets\main\index.jsc /data/local/tmp/index.jsc
  10. export let HookYDSJ = {
  11. start: function () {
  12. Java.perform(function () {
  13. Interceptor.attach(Module.findExportByName(null, "android_dlopen_ext"), {
  14. onEnter: function (args) {
  15. var soName = args[0].readCString();
  16. // console.log("dlopen called with: " + soName);
  17. // 获取正在加载的模块的名称
  18. var moduleName = Memory.readUtf8String(args[0]);
  19. this.isTargetModule = (moduleName.indexOf(targetModuleName) !== -1);
  20. },
  21. onLeave: function (ret) {
  22. if (this.isTargetModule) {
  23. HookYDSJ.hook();
  24. }
  25. }
  26. });
  27. })
  28. }, hook: function () {
  29. logColor("HookLDGP start", LogColor.RED_BG);
  30. let addressBase = Module.findBaseAddress(targetModuleName);
  31. function createDir(saveFilePath) {
  32. let path = require('path'); // 引入path模块,假设Frida环境支持或者有类似的路径处理方法
  33. // 分离目录路径和文件名
  34. let dirPath = path.dirname(saveFilePath);
  35. let fileName = path.basename(saveFilePath);
  36. // 检查目录是否存在,不存在则创建
  37. Java.perform(function () {
  38. // 使用 Java 的 File 类
  39. var File = Java.use("java.io.File");
  40. // 目标目录路径
  41. // 创建 File 对象表示这个目录
  42. var targetDir = File.$new(dirPath);
  43. // 检查目录是否存在
  44. if (!targetDir.exists()) {
  45. // 目录不存在,尝试创建目录
  46. var success = targetDir.mkdirs();
  47. if (success) {
  48. logColor("目录创建成功:" + saveFilePath, LogColor.GREEN_TEXT)
  49. } else {
  50. logColor("目录创建失败:" + saveFilePath, LogColor.RED_TEXT)
  51. }
  52. } else {
  53. logColor("目录已存在:" + saveFilePath, LogColor.RED_TEXT)
  54. }
  55. });
  56. }
  57. function saveAllJs(args) {
  58. if (IS_SAVE_ALL_JS) {
  59. let saveFilePath = `${TAGET_DATA_FILES}/saved_js/`;
  60. //判断saveFilePath是否存在,不存在则创建
  61. if (!args[4].isNull()) {//这个应该是别名
  62. var jsName = args[4].readUtf8String();
  63. let filePath = `${saveFilePath}${jsName}`;
  64. createDir(filePath);
  65. var scriptString = args[1].readUtf8String();
  66. logColor(`=======开始写入--${jsName}--========`, LogColor.GREEN_TEXT);
  67. var file = new File(filePath, "wb");
  68. file.write(scriptString);
  69. file.flush();
  70. file.close();
  71. logColor(`=======写入--${jsName}--完成========`, LogColor.GREEN_TEXT);
  72. }
  73. }
  74. return IS_SAVE_ALL_JS;
  75. }
  76. try {
  77. logColor("addressBase: " + addressBase, LogColor.RED_BG);
  78. Module.ensureInitialized(targetModuleName);
  79. var targetFunctionAddress = addressBase.add(0x000008E3FE4);
  80. Interceptor.attach(targetFunctionAddress, {
  81. onEnter: function (args) {
  82. // console.log("evalString Function called");
  83. //判断args是否为空
  84. if (args === null) {
  85. console.log("evalString Function args is null");
  86. return;
  87. }
  88. //用颜色打印所有的参数
  89. if (!args[4].isNull()) {//这个应该是别名
  90. var contextName = args[4].readUtf8String();
  91. console.log("脚本别名" + contextName);
  92. var scriptLength = args[2].toInt32();
  93. console.log("Length of code: " + scriptLength);
  94. if (saveAllJs(args)){
  95. logColor("----------保存所有脚本-----", LogColor.RED_BG);
  96. return;
  97. }
  98. if (contextName.indexOf("assets/main/index.jsc") !== -1) {
  99. //保存最新的版本
  100. // var scriptString = args[1].readUtf8String();
  101. // console.log("JavaScript scriptString: " + scriptString);
  102. // saveString(scriptString);
  103. // return 1;
  104. this.replaced = 1;
  105. //获取当前时间
  106. this.startTime = new Date().getTime();
  107. // return 1;
  108. var env = Java.vm.getEnv();
  109. let libCliSo = Module.load("/data/data/com.rbigkic.yyydsj/files/libcli.so");
  110. logColor("libCliSo: " + libCliSo, LogColor.GREEN_TEXT);
  111. let readFileAddress = libCliSo.findExportByName("readFile");
  112. logColor("readFile: " + readFileAddress, LogColor.GREEN_TEXT);
  113. let readFile = new NativeFunction(readFileAddress, 'pointer', ['pointer', "pointer"]);
  114. let filePath = Memory.allocUtf8String(RE_PROJECT_PATH);
  115. let jByteArray = readFile(env.handle, filePath);
  116. // 处理返回的 jbyteArray
  117. var length = env.getArrayLength(jByteArray);
  118. var buffer = env.getByteArrayElements(jByteArray, null);
  119. args[1] = ptr(buffer);
  120. args[2] = ptr(length);
  121. // TraceTools.crash2Trace(this.context);
  122. // var scriptEngine = args[0];
  123. // console.log("JavaScript scriptEngine add: " + scriptEngine);
  124. //
  125. // var reProjectJs = readProjectJs();
  126. // args[1] = reProjectJs.buffer;
  127. // args[2] = reProjectJs.length;
  128. // args[3] = reProjectJs.addPtr;
  129. // logColor("reProjectJs: " + reProjectJs.length, LogColor.RED_BG);
  130. //
  131. var scriptLength = args[2].toInt32();
  132. console.log("Length of code: " + scriptLength);
  133. //
  134. console.log("Result storage: " + args[3] + " typeof:" + typeof args[3]);
  135. }
  136. }
  137. },
  138. onLeave: function (retval) {
  139. //尝试所有类型的返回值
  140. if (this.replaced) {
  141. console.log("json 替换结果:", retval.toInt32() === 1);
  142. var endTime = new Date().getTime();
  143. console.log("耗时: " + (endTime - this.startTime) + "ms");
  144. }
  145. }
  146. });
  147. } catch (e) {
  148. console.log("error: " + e);
  149. }
  150. }
  151. }