美文网首页
class-dump & otool

class-dump & otool

作者: iChuck | 来源:发表于2018-04-20 11:17 被阅读105次

    class-dump

    • 可以将Mach-O文件中的Objective-C运行时的声明的信息导出,即编写OC代码时的 .h文件。class-dump只能导出未经加密的App的头文件。classdump是对”otool -ov” 信息的翻译,以一种我们熟悉的易读的方式呈现。官网 http://stevenygard.com/projects/class-dump/

    • otool(object file displaying tool)的使用

      • 目标文件的展示工具
      • 可以用来发现应用中使用到了哪些系统库,调用了其中哪些方法,使用了库中哪些对象及属性,它是Xcode自带的常用工具。
    Usage: /Applications/Xcode.app/Contents/Developer/Toolchains/XcodeDefault.xctoolchain/usr/bin/otool [-arch arch_type] [-fahlLDtdorSTMRIHGvVcXmqQjCP] [-mcpu=arg] [--version] <object file> ...
        -f print the fat headers
        -a print the archive header
        -h print the mach header
        -l print the load commands
        -L print shared libraries used
        -D print shared library id name
        -t print the text section (disassemble with -v)
        -p <routine name>  start dissassemble from routine name
        -s <segname> <sectname> print contents of section
        -d print the data section
        -o print the Objective-C segment
        -r print the relocation entries
        -S print the table of contents of a library (obsolete)
        -T print the table of contents of a dynamic shared library (obsolete)
        -M print the module table of a dynamic shared library (obsolete)
        -R print the reference table of a dynamic shared library (obsolete)
        -I print the indirect symbol table
        -H print the two-level hints table (obsolete)
        -G print the data in code table
        -v print verbosely (symbolically) when possible
        -V print disassembled operands symbolically
        -c print argument strings of a core file
        -X print no leading addresses or headers
        -m don't use archive(member) syntax
        -B force Thumb disassembly (ARM objects only)
        -q use llvm's disassembler (the default)
        -Q use otool(1)'s disassembler
        -mcpu=arg use `arg' as the cpu for disassembly
        -j print opcode bytes
        -P print the info plist section as strings
        -C print linker optimization hints
        --version print the version of /Applications/Xcode.app/Contents/Developer/Toolchains/XcodeDefault.xctoolchain/usr/bin/otool
        
    
    • 依赖库查询

      otool -L WeChat
      
      # 是否加壳
      
      otool -l WeChat | grep -B 2 crypt
      
    • class-dump 的使用

    class-dump: unrecognized option `--hlep'
    class-dump 3.5 (64 bit)
    Usage: class-dump [options] <mach-o-file>
    
      where options are:
            -a             show instance variable offsets
            -A             show implementation addresses
            --arch <arch>  choose a specific architecture from a universal binary (ppc, ppc64, i386, x86_64, armv6, armv7, armv7s, arm64)
            -C <regex>     only display classes matching regular expression
            -f <str>       find string in method name
            -H             generate header files in current directory, or directory specified with -o
            -I             sort classes, categories, and protocols by inheritance (overrides -s)
            -o <dir>       output directory used for -H
            -r             recursively expand frameworks and fixed VM shared libraries
            -s             sort classes and categories by name
            -S             sort methods by name
            -t             suppress header in output, for testing
            --list-arches  list the arches in the file, then exit
            --sdk-ios      specify iOS SDK version (will look in /Developer/Platforms/iPhoneOS.platform/Developer/SDKs/iPhoneOS<version>.sdk
            --sdk-mac      specify Mac OS X version (will look in /Developer/SDKs/MacOSX<version>.sdk
            --sdk-root     specify the full SDK root path (or use --sdk-ios/--sdk-mac for a shortcut)
    
    • 使用
    class-dump -s -S -H App路径 -o ./MyHeaders
    
    # 查看某个文件下的文件个数,包括子文件里的。
    ls -lR|grep "^-"|wc -l
    
    # 查看某文件下的文件夹的个数,包括子文件夹里的。
    ls -lR|grep "^d"|wc -l
    

    相关文章

      网友评论

          本文标题:class-dump & otool

          本文链接:https://www.haomeiwen.com/subject/kleakftx.html