上篇文章:https://www.jianshu.com/p/3a4ffe516da6
我们通过了ssl校验,成功抓到了包,此时抓包发现了新的加密参数
data:image/s3,"s3://crabby-images/b4ab9/b4ab9ab02ef8b9f0ac50a315bdd5765542b509f0" alt=""
把apk拖入jadx,搜索 "sign"
data:image/s3,"s3://crabby-images/50646/50646e27e3900b6a3d220466fde158eb0785ac33" alt=""
右键跳到声明
data:image/s3,"s3://crabby-images/25ae2/25ae228873d3f824ada87c8a8ce8891c5f76bc3e" alt=""
data:image/s3,"s3://crabby-images/ee4b4/ee4b4ee3905646c0e60caba181fa6c594bc572e5" alt=""
调用了ocstool这个so
解压apk文件,用ida打开
data:image/s3,"s3://crabby-images/41a16/41a16561e537c60b1641de9388ffea54f0113628" alt=""
data:image/s3,"s3://crabby-images/beb80/beb80bb624be071082d9454112849493697d1394" alt=""
典型的md5加密,直接调用大佬的hook MD5的js文件
data:image/s3,"s3://crabby-images/853c0/853c084c32122ce18fcec55442f5ef2ff265a927" alt=""
此时结果已出。
这个app挺有代表性的,都可以拿来练一下手。
代码在github上
https://github.com/pythonPCS/oppo-ssl-ping-
网友评论