This commit is contained in:
Jean-Marie Mineau 2024-02-05 17:31:28 +01:00
parent 2cf3963532
commit 84eacfb7d4
Signed by: histausse
GPG key ID: B66AEEDA9B645AD2
9 changed files with 860 additions and 49 deletions

91
test.py
View file

@ -5,20 +5,21 @@ logging.basicConfig(format=FORMAT)
logging.getLogger().setLevel(logging.DEBUG)
import json
import androscalpel as asc
import zipfile as z
from androscalpel import *
from pathlib import Path
from androscalpel import Apk, IdType, IdMethodType, ins, DexString, IdMethod, Code, utils # type: ignore
# APK_NAME = Path(__file__).parent / "test.apk"
APK_NAME = Path(__file__).parent / "app-release.apk"
APK_NAME = Path(__file__).parent / "app.apk"
DEX_NAME = "classes.dex"
print(f"[+] Load bytecode ")
with z.ZipFile(APK_NAME) as zipf:
with zipf.open(DEX_NAME, "r") as dex:
dex = dex.read()
with zipf.open(DEX_NAME, "r") as dex_f:
dex = dex_f.read()
apk = asc.Apk()
apk = Apk()
apk.add_dex_file(dex)
clazz_id = IdType("Lcom/example/testapplication/ui/home/HomeViewModel;")
@ -35,17 +36,18 @@ print(f"[+] Code of {method_id} ")
for i in code.insns:
print(f" {i}")
print("[+] Modify code")
new_insns = []
for i in code.insns:
if isinstance(i, asc.ins.ConstString):
if isinstance(i, ins.ConstString):
if i.lit == "Hello":
i = asc.ins.ConstString(i.reg, DexString("Degemer Mat"))
i = ins.ConstString(i.reg, DexString("Degemer Mat"))
elif i.lit == "Bye":
i = asc.ins.ConstString(i.reg, DexString("Kenavo"))
i = ins.ConstString(i.reg, DexString("Kenavo"))
new_insns.append(i)
# This need improving!
code = asc.Code(code.registers_size, code.ins_size, code.outs_size, new_insns)
code = Code(code.registers_size, code.ins_size, code.outs_size, new_insns)
apk.set_method_code(method_id, code)
# apk.set_method_code(method.descriptor, code)
@ -58,49 +60,44 @@ for i in code.insns:
print(f" {i}")
# Strip class for debugging
# classes = list(
# filter(
# lambda x: x
# not in [
# IdType("Lcom/example/testapplication/ui/home/HomeViewModel;"),
# IdType("Landroidx/navigation/NavDeepLink$Builder;"),
# IdType("Landroidx/constraintlayout/core/widgets/ConstraintWidget$1;"),
# ],
# apk.classes.keys(),
# )
# )
# for cls in classes:
# apk.remove_class(cls)
classes = list(
filter(
lambda x: x
not in [
IdType("Lcom/example/testapplication/ui/home/HomeViewModel;"),
IdType("Landroidx/navigation/NavDeepLink$Builder;"),
IdType("Landroidx/constraintlayout/core/widgets/ConstraintWidget$1;"),
],
apk.classes.keys(),
)
)
for cls in classes:
apk.remove_class(cls)
print("[+] Recompile")
dex_raw = apk.gen_raw_dex()
utils.replace_dex(
APK_NAME,
APK_NAME.parent / "app-instrumented.apk",
dex_raw,
Path().parent / "my-release-key.jks",
zipalign=Path.home() / "Android" / "Sdk" / "build-tools" / "34.0.0" / "zipalign",
apksigner=Path.home() / "Android" / "Sdk" / "build-tools" / "34.0.0" / "apksigner",
)
# assert len(dex_raw) == 1
# with open(DEX_NAME, "wb") as file:
# file.write(dex_raw[0])
#
# with open(DEX_NAME, "rb") as file:
# dex = file.read()
print("[+] Load new dex")
new_apk = asc.Apk()
new_apk = Apk()
for dex in dex_raw:
new_apk.add_dex_file(dex)
clazz = new_apk.classes[clazz_id]
method = clazz.virtual_methods[method_id]
code = method.code
print(f"{new_apk == apk=}")
print(f"[+] Code of {method_id} in new apk")
for i in code.insns:
print(f" {i}")
# print("[+] Repackage")
#
# utils.replace_dex(
# APK_NAME,
# APK_NAME.parent / (APK_NAME.name.removesuffix(".apk") + "-instrumented.apk"),
# dex_raw,
# Path().parent / "my-release-key.jks",
# zipalign=Path.home() / "Android" / "Sdk" / "build-tools" / "34.0.0" / "zipalign",
# apksigner=Path.home() / "Android" / "Sdk" / "build-tools" / "34.0.0" / "apksigner",
# )
def cmp(a, b):
for f in dir(a):
if getattr(getattr(a, f), "__call__", None) is None:
print(f"{f}: {getattr(a, f) == getattr(b, f)}")