function hook_so_x() {
var soAddr = Module.findBaseAddress("****.so")
console.log("模块基址:", soAddr)
var four_add = soAddr.add(0x942d4)
let result;
let num = 0;
Interceptor.attach(four_add, {
onEnter: function (args) {
result = args[2]
console.log(result, num, "入参2:", hexdump(args[2]))
console.log(result, num, "入参0:", hexdump(args[0]))
console.log(result, num, "入参1:", args[1])
}
})
Interceptor.attach(soAddr.add(0x95b70), {
onEnter: function (args) {
console.log(result, num, "入参的出参:", hexdump(result))
num += 1
}
})
}
function call_x_func() {
let baselibEncryptor = Module.findBaseAddress("libmetasec_ov.so");
let addr_8bb80 = baselibEncryptor.add(0x8c4a0);
let str0 = "870K9s2c8@1M7s2y4Q4x3@1q4Q4x3V1k6Q4x3V1k6S2M7r3V1I4y4W2)9J5k6r3y4G2M7X3g2Q4x3X3c8#2M7$3g2S2M7%4b7#2i4K6u0W2N6i4y4Q4x3X3g2@1K9h3E0@1L8$3E0$3i4K6u0W2j5$3!0E0i4K6u0r3j5i4N6W2L8h3g2Q4x3V1k6$3x3g2)9J5c8X3q4%4k6h3#2W2i4K6u0r3M7r3!0K6N6q4)9J5c8W2)9K6c8Y4y4G2N6i4u0U0k6g2)9K6c8o6m8Q4x3U0k6S2L8i4m8Q4x3@1u0#2M7$3g2J5i4K6g2X3j5i4k6S2N6r3q4J5i4K6g2X3M7$3S2J5K9h3&6C8i4K6y4p5z5e0k6Q4y4h3j5&6y4W2)9J5y4X3q4E0M7q4)9K6b7Y4k6A6k6r3g2G2i4K6g2X3j5$3!0$3k6i4u0Q4y4h3k6K6K9s2u0A6L8X3E0Q4x3@1b7J5y4o6S2Q4y4h3j5K6x3K6m8Q4x3U0k6S2L8i4m8Q4x3@1u0E0j5i4S2Q4y4h3k6U0N6i4u0K6L8%4u0Q4x3@1b7H3i4K6t1$3j5h3#2H3i4K6y4n7M7$3g2U0i4K6g2X3N6i4y4W2M7W2)9#2k6X3W2V1i4K6y4p5e0g2x3@1N6@1I4B7b7f1u0m8b7f1q4m8e0g2c8s2g2o6W2#2P5V1b7#2y4X3W2^5d9W2k6D9j5V1Z5@1b7e0W2v1g2h3c8Q4y4h3k6a6g2#2)9#2k6Y4q4c8g2W2W2U0k6e0f1#2x3e0q4U0k6e0b7#2L8f1W2e0b7$3k6a6f1p5c8n7L8U0g2K9h3V1q4K6e0p5!0p5b7$3E0S2b7h3E0Q4x3U0k6S2L8i4m8Q4x3@1u0U0L8%4g2F1N6q4)9K6c8o6W2Q4x3U0k6S2L8i4m8Q4x3@1u0D9L8$3y4S2N6r3g2Q4y4h3k6A6N6r3g2E0i4K6g2X3K9h3c8Q4x3U0k6S2L8i4m8Q4x3@1u0K6L8%4u0@1i4K6g2X3N6s2W2H3k6g2)9K6c8o6m8Q4x3U0k6S2L8i4m8Q4x3@1u0A6K9h3c8Q4x3@1b7%4x3U0V1@1y4e0p5^5y4K6t1@1x3K6x3%4x3e0V1H3y4U0V1^5i4K6t1$3j5h3#2H3i4K6y4n7k6r3g2$3K9h3y4W2i4K6g2X3K9h3c8Q4x3@1b7$3y4U0j5I4x3U0f1^5y4U0b7J5y4o6l9#2x3K6t1^5x3K6R3&6i4K6t1$3j5h3#2H3i4K6y4n7j5h3y4Q4x3@1c8%4K9h3k6A6i4K6t1$3j5h3#2H3i4K6y4n7j5$3S2S2L8X3&6W2L8q4)9K6c8r3N6G2L8$3N6D9k6i4m8D9j5i4W2Q4x3U0k6S2L8i4m8Q4x3@1u0S2K9h3c8Q4x3@1b7I4x3U0x3K6i4K6t1$3j5h3#2H3i4K6y4n7j5i4m8H3i4K6g2X3L8X3q4E0k6g2)9K6c8r3#2#2M7$3W2U0j5h3I4Q4y4h3k6D9P5g2)9J5y4X3q4E0M7q4)9K6b7Y4k6W2M7Y4y4A6L8$3&6Q4y4h3k6U0L8$3c8W2i4K6y4p5x3K6p5H3z5e0l9I4i4K6t1$3j5h3#2H3i4K6y4n7N6X3g2J5M7$3W2G2L8W2)9#2k6X3&6S2L8h3g2Q4x3@1b7K6x3g2)9J5k6e0W2Q4x3X3f1I4i4K6t1$3j5h3#2H3i4K6y4n7k6r3g2$3K9h3y4W2i4K6g2X3M7r3I4S2N6r3k6G2M7X3#2Q4x3@1c8S2L8X3c8J5L8$3W2V1i4K6t1$3j5h3#2H3i4K6y4n7L8%4y4Q4x3@1c8S2L8X3c8J5L8$3W2V1i4K6t1$3j5h3#2H3i4K6y4n7j5h3u0Q4y4h3k6$3k6i4u0K6K9h3!0F1i4K6y4p5x3K6q4Q4x3X3f1&6i4K6u0W2x3g2)9J5y4X3q4E0M7q4)9K6b7Y4y4K6L8h3W2^5i4K6y4p5j5g2)9J5y4X3q4E0M7q4)9K6b7X3c8W2N6X3W2U0k6g2)9#2k6Y4c8&6M7r3g2Q4x3@1c8e0e0g2)9J5k6p5M7&6y4K6N6z5i4K6t1$3j5h3#2H3i4K6y4n7k6r3g2$3K9h3y4W2i4K6g2X3j5Y4u0S2L8X3c8Q4x3@1c8K6j5h3#2K6N6h3&6Y4i4K6t1$3j5h3#2H3i4K6y4n7L8r3q4F1k6%4g2S2k6$3g2Q4x3@1c8W2L8W2)9J5y4X3q4E0M7q4)9K6b7X3!0K6i4K6g2X3j5i4m8A6i4K6y4p5x3U0S2Q4x3U0k6S2L8i4m8Q4x3@1u0G2M7#2)9#2k6Y4k6W2M7Y4y4A6L8$3&6Q4x3@1b7&6i4K6t1$3j5h3#2H3i4K6y4n7L8%4m8W2L8Y4g2V1K9h3c8Q4x3@1c8S2y4U0M7J5z5h3f1K6y4K6m8S2j5$3x3#2j5h3j5#2i4K6t1$3j5h3#2H3i4K6y4n7L8h3q4F1K9h3k6W2M7%4c8Q4y4h3k6$3k6i4u0K6K9h3!0F1i4K6g2X3j5$3!0V1k6g2)9K6c8o6t1H3x3U0x3I4x3o6V1H3x3e0m8Q4x3U0k6S2L8i4m8Q4x3@1u0J5k6i4y4G2L8s2g2@1K9h3!0F1i4K6y4p5x3e0j5H3x3q4)9J5y4e0u0m8z5e0l9H3i4K6t1$3j5h3#2H3i4K6y4n7k6s2m8A6i4K6y4p5x3K6t1H3i4K6t1$3j5h3#2H3i4K6y4n7N6i4m8V1j5i4c8W2i4K6g2X3N6X3g2J5M7$3W2G2L8W2)9#2k6X3y4G2k6r3g2Q4x3@1b7J5x3o6t1K6x3e0l9&6x3o6p5H3i4K6t1$3j5h3#2H3i4K6y4n7i4K6g2X3M7Y4c8A6j5$3E0W2N6q4)9K6c8o6p5%4x3o6p5I4y4o6b7&6y4K6p5$3x3e0m8Q4x3U0k6S2L8i4m8Q4x3@1u0A6M7#2)9#2k6Y4m8S2k6q4)9K6c8o6m8Q4x3U0k6S2L8i4m8Q4x3@1u0U0N6i4u0J5k6h3&6@1i4K6g2X3M7X3g2Y4K9h3!0F1i4K6y4p5g2g2y4Q4x3U0k6S2L8i4m8Q4x3@1u0S2M7s2m8Q4y4h3k6@1P5i4m8W2i4K6y4p5L8X3!0J5L8h3q4D9i4K6t1$3j5h3#2H3i4K6y4n7M7%4W2K6i4K6g2X3M7X3g2Y4K9h3!0F1i4K6y4p5g2g2y4Q4x3U0k6S2L8i4m8Q4x3@1u0E0j5$3y4Q4y4h3k6E0L8X3y4Q4x3@1b7K6x3e0l9I4y4W2)9J5y4X3q4E0M7q4)9K6b7Y4c8A6L8h3g2*7L8$3&6W2i4K6g2X3L8X3q4E0k6g2)9K6c8p5q4E0k6i4u0A6j5$3q4Q4x3U0f1J5y4e0u0r3f1r3S2G2k6h3&6A6P5q4)9J5y4X3q4E0M7q4)9K6b7X3y4S2M7Y4u0A6k6i4u0Q4y4h3k6J5k6h3N6A6L8$3&6Q4y4h3k6$3x3W2)9K6c8o6x3I4x3q4)9J5y4X3q4E0M7q4)9K6b7Y4u0W2M7$3W2V1k6h3&6U0k6g2)9K6c8q4g2e0i4K6t1$3j5h3#2H3i4K6y4n7j5i4m8H3i4K6g2X3L8r3q4F1k6%4g2S2k6$3g2Q4x3@1c8W2L8W2)9J5y4X3q4E0M7q4)9K6b7X3y4S2M7Y4u0A6k6i4u0Q4y4h3k6J5k6h3N6A6L8$3&6Q4x3@1c8g2f1#2)9J5y4X3q4E0M7q4)9K6b7X3q4U0x3W2)9K6c8s2N6A6k6X3V1#2k6#2)9J5y4X3q4E0M7q4)9K6b7Y4g2G2L8#2)9K6c8o6m8Q4x3U0k6S2L8i4m8Q4x3@1u0G2M7q4)9#2k6Y4u0W2k6$3W2G2L8W2)9K6c8q4g2e0i4K6t1$3j5h3#2H3i4K6y4n7N6r3W2E0k6i4A6G2L8X3g2Q4y4h3k6G2k6X3k6K6k6i4c8Q4x3@1c8Q4x3X3b7J5y4e0t1H3x3q4)9J5y4X3q4E0M7q4)9K6b7X3u0#2K9h3I4V1i4K6g2X3L8Y4g2E0j5X3g2J5i4K6y4p5x3K6q4Q4x3X3f1&6i4K6u0W2x3g2)9J5y4X3q4E0M7q4)9K6b7X3S2G2M7%4c8Q4y4h3k6S2j5X3W2Q4x3@1c8S2M7X3@1$3y4q4)9J5k6s2j5^5j5g2)9J5y4X3q4E0M7q4)9K6b7X3I4G2j5$3q4D9k6g2)9K6c8r3g2F1i4K6t1$3j5h3#2H3i4K6y4n7M7X3g2Y4K9h3!0F1i4K6y4p5g2g2y4Q4x3U0k6S2L8i4m8Q4x3@1u0@1M7#2)9K6c8o6p5%4x3o6p5I4y4o6b7&6y4K6g2Q4x3U0k6S2L8i4m8Q4x3@1u0U0k6r3W2V1i4K6y4p5z5o6R3@1z5o6M7@1y4K6u0Q4x3X3b7%4y4o6S2S2i4K6u0V1y4r3j5&6j5#2)9J5k6r3t1&6y4o6g2Q4x3X3b7^5k6h3u0W2y4o6l9#2x3X3u0U0x3e0S2Q4x3U0k6I4N6h3!0@1i4K6y4n7
let arg0 = Memory.allocUtf8String(str0);
let str1 = decodeURIComponent("x-tt-bypass-dp%0D%0A1%0D%0Asdk-version%0D%0A2%0D%0Apassport-sdk-version%0D%0A19%0D%0Ax-ss-req-ticket%0D%0A1717052656600%0D%0Ax-vc-bdturing-sdk-version%0D%0A2.3.0.i18n%0D%0Ax-tt-dm-status%0D%0Alogin%3D0%3Bct%3D0%3Brt%3D7%0D%0Acontent-type%0D%0Aapplication%2Fx-www-form-urlencoded%3B%20charset%3DUTF-8%0D%0Ax-ss-stub%0D%0AE10ADC3949BA59ABBE56E057F20F883E%0D%0Acontent-length%0D%0A81%0D%0Ax-tt-trace-id%0D%0A00-c8504d6c010de75c6a96840a3f9a04d1-c8504d6c010de75c-01%0D%0Auser-agent%0D%0Acom.zhiliaoapp.musically%2F2022900010%20(Linux%3B%20U%3B%20Android%208.1.0%3B%20en_US%3B%20AOSP%20on%20taimen%3B%20Build%2FOPM1.171019.011%3B%20Cronet%2FTTNetVersion%3A55e3b3c8%202023-03-20%20QuicVersion%3Ad298137e%202023-02-13)%0D%0Aaccept-encoding%0D%0Agzip%2C%20deflate\n")
let arg1 = Memory.allocUtf8String(str1);
var sub9ad50 = new NativeFunction(addr_8bb80, "pointer", ["pointer", "pointer"]);
var result = sub9ad50(arg0, arg1)
console.log(result.readCString())
}