脱壳工具frida-dexdump
source link: http://blog.wen2go.site/2022/02/14/%E8%84%B1%E5%A3%B3%E5%B7%A5%E5%85%B7frida-dexdump/
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.
葫芦娃大佬的脱壳工具firda-dexdump
,一键式脱壳,方便快捷,号称三秒脱一壳!!!
git
仓库:https://github.com/hluwa/FRIDA-DEXDump
文档介绍了三种使用方式
命令行直接脱壳
前提:需要安装
python
和frida
环境,并启动frida-server
,参考frida
教程pip3 install frida-dexdump
安装成功之后,在手机端打开需要脱壳的
app
, 然后直接命令行执行frida-dexdump
, 脱出来的dex
文件会保存在当前目录frida-dexdump
使用
python
执行脚本从仓库克隆项目
git clone https://github.com/hluwa/FRIDA-DEXDump
打开克隆的项目,用
python3
执行main.py
, 会在当前目录保存脱壳后的dex
文件python3 main.py
使用
objection
插件依然从
git
克隆项目然后将项目内的
frida_dexdump
移到~/.objection/plugin/
文件下mv ~/Downloads/FRIDA-DEXDump/frida_dexdump ~/.objection/plugins/dexdump
启动
objection
,objection
使用参考文章objection -g com.xxx.xxx explore -P ~/.objection/plugins
直接在
objection
交互界面,输入指令plugin dexdump dump
,就会把app
进行脱壳,同样脱壳文件保存在当前目录plugin dexdump dump
frida-dexdump
可以对付一些简单的加固,对于抽取型的加固推荐寒冰大佬的fart
脱壳王
Recommend
About Joyk
Aggregate valuable and interesting links.
Joyk means Joy of geeK