能力值:
( LV2,RANK:10 )
|
-
-
2 楼
注入x86作为bridge调用houdini加载arm的so完成hack
|
能力值:
( LV2,RANK:10 )
|
-
-
3 楼
当然直接远程调用houdini注入arm的库进行hack也行
|
能力值:
( LV1,RANK:0 )
|
-
-
4 楼
不吃早饭
注入x86作为bridge调用houdini加载arm的so完成hack
感谢回复, 没能在网上找到太多的相关资料, 有相关的代码参考吗
|
能力值:
( LV2,RANK:10 )
|
-
-
5 楼
Migration
感谢回复, 没能在网上找到太多的相关资料, 有相关的代码参考吗
看aosp里libnativebridge部分代码,那是官方调用houdini的方法
|
能力值:
( LV2,RANK:10 )
|
-
-
6 楼
Migration
感谢回复, 没能在网上找到太多的相关资料, 有相关的代码参考吗
104K9s2c8@1M7s2y4Q4x3@1q4Q4x3V1k6Q4x3V1k6U0M7#2)9J5k6h3q4F1k6s2u0G2K9h3c8Q4x3X3g2U0L8$3#2Q4x3V1k6S2L8X3c8J5L8$3W2V1i4K6u0r3M7r3I4S2N6r3k6G2M7X3#2Q4x3V1k6K6N6i4m8W2M7Y4m8J5L8$3A6W2j5%4c8Q4x3V1k6Q4x3V1u0Q4x3V1k6E0j5i4y4@1k6i4u0Q4x3@1q4S2M7Y4c8Q4x3V1k6D9K9h3u0F1j5i4c8A6N6X3g2T1M7X3W2V1k6$3g2Q4x3V1k6F1j5i4c8A6N6X3g2Q4y4h3k6T1M7X3W2V1k6$3g2Q4x3X3g2U0j5#2)9K6b7X3I4Q4x3@1b7#2y4U0x3`.
|
能力值:
( LV1,RANK:0 )
|
-
-
7 楼
十分感谢, 我去参考一下
|
能力值:
( LV1,RANK:0 )
|
-
-
8 楼
十分感谢, 我去参考一下
|
能力值:
( LV1,RANK:0 )
|
-
-
9 楼
不吃早饭
517K9s2c8@1M7s2y4Q4x3@1q4Q4x3V1k6Q4x3V1k6U0M7#2)9J5k6h3q4F1k6s2u0G2K9h3c8Q4x3X3g2U0L8$3#2Q4x3V1k6S2L8X3c8J5L8$3W2V1i4K6u0r3M7r3I4S2N6r3k6G2M7X3#2Q4x3V1k6K6N6i4m8W2M7Y4m8J5L8$3A6W2j5%4c8Q4x3V1k6Q4x3V1u0Q4x3V1k6E0j5i4y4@1k6i4u0Q4x3@1q4S2M7Y4c8Q4x3V1k6D9K9h3u0F1j5i4c8A6N6X3g2T1M7X3W2V1k6$3g2Q4x3V1k6F1j5i4c8A6N6X3g2Q4y4h3k6T1M7X3W2V1k6$3g2Q4x3X3g2U0j5#2)9K6b7X3H3`. ...
十分感谢, 我去参考一下
|
能力值:
( LV2,RANK:10 )
|
-
-
10 楼
可以替换掉libnb.so native_bridge2_loadLibrary 加载arm的so static void *native_bridge2_loadLibrary(const char *libpath, int flag) {
ALOGV("enter native_bridge2_loadLibrary %s", libpath);
NativeBridgeCallbacks *cb = get_callbacks();
if (strstr(libpath, "xxx.so")) {
ALOGV("load xxx.so");
// 加载我们自己的so文件
void *handle = cb->loadLibrary("/data/local/tmp/libhackclient.so", flag);
ALOGV("load libhackclient = %p", handle);
}
return cb ? cb->loadLibrary(libpath, flag) : nullptr;
} 233K9s2c8@1M7s2y4Q4x3@1q4Q4x3V1k6Q4x3V1k6Y4K9i4c8Z5N6h3u0Q4x3X3g2U0L8$3#2Q4x3V1k6G2M7r3g2F1N6r3S2G2M7#2)9J5c8X3c8W2N6X3W2U0k6g2)9J5k6r3N6W2L8X3g2J5K9h3y4Q4x3X3c8U0L8$3#2E0L8$3&6Q4x3V1k6T1L8r3!0T1i4K6u0r3L8h3q4J5M7$3S2E0j5h3I4D9L8%4N6Q4x3X3c8G2M7r3g2F1N6r3S2G2M7#2)9J5c8X3&6S2N6r3W2$3k6h3u0J5K9h3c8Y4k6g2)9J5c8Y4y4J5j5#2)9J5c8X3I4A6j5X3&6T1i4K6u0W2j5%4m8H3
最后于 2022-5-10 13:19
被Yecate编辑
,原因:
|
能力值:
( LV1,RANK:0 )
|
-
-
11 楼
Yecate
可以替换掉libnb.so native_bridge2_loadLibrary 加载arm的sostatic void *native_brid ...
十分感谢, 我试试
|
能力值:
( LV1,RANK:0 )
|
-
-
12 楼
大佬们,出出视频讲解一下,带带弟弟,。
|
能力值:
( LV1,RANK:0 )
|
-
-
13 楼
大佬最后有解决了吗
|
能力值:
( LV2,RANK:10 )
|
-
-
14 楼
 大佬能给个联系方式吗 学习一下
|
能力值:
( LV1,RANK:0 )
|
-
-
15 楼
x86加载armv7的动态库可以参考java层System.load方法,或者直接java层注入就可以了。
|
能力值:
( LV2,RANK:10 )
|
-
-
16 楼
Yecate
可以替换掉libnb.so native_bridge2_loadLibrary 加载arm的sostatic void *native_brid ...
大佬请问: libnb 这个该如何才能编译 他的nativebridge目录下 只有android.mk 和 nativebridge.mk 没有application.mk 这种情况该如何才能编译
|
能力值:
( LV2,RANK:10 )
|
-
-
17 楼
happyZore
大佬请问: libnb 这个该如何才能编译 他的nativebridge目录下 只有android.mk 和 nativebridge.mk 没有application.mk 这种情况该如何才能 ...
Android.mk LOCAL_PATH := $(call my-dir)
include $(CLEAR_VARS)
LOCAL_MODULE := nb
LOCAL_SRC_FILES := ../libnb.cpp
LOCAL_LDLIBS := -llog
include $(BUILD_SHARED_LIBRARY)
Application.mk APP_ABI := x86
APP_PLATFORM := android-21
APP_STL := c++_static
|
能力值:
( LV2,RANK:10 )
|
-
-
18 楼
还是用感染注入好了 这些编译的方式好麻烦
|
能力值:
( LV1,RANK:0 )
|
-
-
19 楼
wx_小薛_256
还是用感染注入好了 这些编译的方式好麻烦
我想买这个 添加我的 QQ2491045843
|
能力值:
( LV1,RANK:0 )
|
-
-
20 楼
大佬,你解决了吗
|
能力值:
( LV1,RANK:0 )
|
-
-
21 楼
梅雨个个
大佬,你解决了吗
很多人实现不了应该是不懂如何处理houdini,那玩意确实很坑,网上资料不会很多
|
能力值:
( LV1,RANK:0 )
|
-
-
22 楼
龙乎
很多人实现不了应该是不懂如何处理houdini,那玩意确实很坑,网上资料不会很多
我看了一个https://bbs.kanxue.com/thread-271478.htm 这个链接里有其他解决方法。但我没怎么看懂
|
能力值:
( LV1,RANK:0 )
|
-
-
23 楼
梅雨个个
我看了一个https://bbs.kanxue.com/thread-271478.htm
这个链接里有其他解决方法。但我没怎么看懂
看下这篇文章就可以了 2e8K9s2c8@1M7s2y4Q4x3@1q4Q4x3V1k6Q4x3V1k6%4N6%4N6Q4x3X3g2H3k6i4u0X3j5i4u0W2i4K6u0W2L8X3g2@1i4K6u0r3j5i4u0U0K9r3W2$3k6i4y4Q4x3V1j5I4z5o6V1%4i4@1g2r3i4@1u0o6i4K6S2o6i4@1f1$3i4K6R3^5i4K6V1I4i4@1f1@1i4@1t1&6i4K6W2r3i4@1f1$3i4K6V1^5i4@1q4r3i4@1f1@1i4@1u0n7i4K6S2q4i4@1f1^5i4@1u0r3i4K6V1&6i4@1f1#2i4@1u0q4i4K6V1%4i4@1f1#2i4K6R3^5i4@1t1H3i4@1f1%4i4K6R3I4i4@1t1#2i4@1f1$3i4K6R3@1i4K6W2r3i4@1g2r3i4@1u0o6i4K6S2o6i4@1f1^5i4@1t1H3i4K6R3K6i4@1f1^5i4@1q4r3i4K6V1#2i4@1f1@1i4@1u0m8i4K6R3$3i4@1f1#2i4K6S2p5i4K6S2m8i4@1f1@1i4@1t1^5i4@1q4m8i4@1f1#2i4@1p5@1i4K6W2m8i4@1f1$3i4K6W2o6i4K6R3^5i4@1f1^5i4@1t1%4i4K6V1I4i4@1f1&6i4K6R3H3i4K6W2m8i4@1f1@1i4@1u0m8i4K6R3$3i4@1f1$3i4@1p5^5i4@1p5I4i4@1f1$3i4K6S2n7i4K6W2r3i4@1f1#2i4K6V1&6i4@1p5^5i4@1f1#2i4K6R3#2i4@1p5^5i4@1f1$3i4K6W2q4i4@1t1$3i4@1f1$3i4K6W2q4i4K6R3@1i4@1f1%4i4K6W2m8i4K6R3@1i4@1f1$3i4@1t1K6i4@1p5^5i4@1f1#2i4K6R3#2i4@1p5#2
|
能力值:
( LV1,RANK:0 )
|
-
-
24 楼
龙乎
看下这篇文章就可以了6b9K9s2c8@1M7s2y4Q4x3@1q4Q4x3V1k6Q4x3V1k6%4N6%4N6Q4x3X3g2H3k6i4u0X3j5i4u0W2i4K6u0W2L8X3g2@1i4K6u0r3j5i4u0U0K9r3W2$3k6i4y4Q4x3V1j5I4z5o6V1%4i4@1g2r3i4@1u0o6i4K6S2o6i4@1f1$3i4K6R3^5i4K6V1I4i4@1f1@1i4@1t1&6i4K6W2r3i4@1f1$3i4K6V1^5i4@1q4r3i4@1f1@1i4@1u0n7i4K6S2q4i4@1f1^5i4@1u0r3i4K6V1&6i4@1f1#2i4@1u0q4i4K6V1%4i4@1f1#2i4K6R3^5i4@1t1H3i4@1f1%4i4K6R3I4i4@1t1#2i4@1f1$3i4K6R3@1i4K6W2r3i4@1g2r3i4@1u0o6i4K6S2o6i4@1f1^5i4@1t1H3i4K6R3K6i4@1f1^5i4@1q4r3i4K6V1#2i4@1f1@1i4@1u0m8i4K6R3$3i4@1f1#2i4K6S2p5i4K6S2m8i4@1f1@1i4@1t1^5i4@1q4m8i4@1f1#2i4@1p5@1i4K6W2m8i4@1f1$3i4K6W2o6i4K6R3^5i4@1f1^5i4@1t1%4i4K6V1I4i4@1f1&6i4K6R3H3i4K6W2m8i4@1f1@1i4@1u0m8i4K6R3$3i4@1f1$3i4@1p5^5i4@1p5I4i4@1f1$3i4K6S2n7i4K6W2r3i4@1f1#2i4K6V1&6i4@1p5^5i4@1f1#2i4K6R3#2i4@1p5^5i4@1f1$3i4K6W2q4i4@1t1$3i4@1f1$3i4K6W2q4i4K6R3@1i4@1f1%4i4K6W2m8i4K6R3@1i4@1f1$3i4@1t1K6i4@1p5^5i4@1f1#2i4K6R3#2i4@1p5#2
这么牛逼..感谢 我去看看, 但这个好像是用面具来注入修改的吧。可以不用面具直接有shell root权限注入嘛?
|
能力值:
( LV2,RANK:10 )
|
-
-
25 楼
龙乎
看下这篇文章就可以了d96K9s2c8@1M7s2y4Q4x3@1q4Q4x3V1k6Q4x3V1k6%4N6%4N6Q4x3X3g2H3k6i4u0X3j5i4u0W2i4K6u0W2L8X3g2@1i4K6u0r3j5i4u0U0K9r3W2$3k6i4y4Q4x3V1j5I4z5o6V1%4i4@1g2r3i4@1u0o6i4K6S2o6i4@1f1$3i4K6R3^5i4K6V1I4i4@1f1@1i4@1t1&6i4K6W2r3i4@1f1$3i4K6V1^5i4@1q4r3i4@1f1@1i4@1u0n7i4K6S2q4i4@1f1^5i4@1u0r3i4K6V1&6i4@1f1#2i4@1u0q4i4K6V1%4i4@1f1#2i4K6R3^5i4@1t1H3i4@1f1%4i4K6R3I4i4@1t1#2i4@1f1$3i4K6R3@1i4K6W2r3i4@1g2r3i4@1u0o6i4K6S2o6i4@1f1^5i4@1t1H3i4K6R3K6i4@1f1^5i4@1q4r3i4K6V1#2i4@1f1@1i4@1u0m8i4K6R3$3i4@1f1#2i4K6S2p5i4K6S2m8i4@1f1@1i4@1t1^5i4@1q4m8i4@1f1#2i4@1p5@1i4K6W2m8i4@1f1$3i4K6W2o6i4K6R3^5i4@1f1^5i4@1t1%4i4K6V1I4i4@1f1&6i4K6R3H3i4K6W2m8i4@1f1@1i4@1u0m8i4K6R3$3i4@1f1$3i4@1p5^5i4@1p5I4i4@1f1$3i4K6S2n7i4K6W2r3i4@1f1#2i4K6V1&6i4@1p5^5i4@1f1#2i4K6R3#2i4@1p5^5i4@1f1$3i4K6W2q4i4@1t1$3i4@1f1$3i4K6W2q4i4K6R3@1i4@1f1%4i4K6W2m8i4K6R3@1i4@1f1$3i4@1t1K6i4@1p5^5i4@1f1#2i4K6R3#2i4@1p5#2
感谢大佬无私馈赠,天不生龙乎大哥,逆向万古如长夜~
|
|
|