feat: MariBank 风控 bypass、澳洲银行 Hook 与 reverse 逆向工作区
新增 MariBank/SeaBank PH Root 与 SHPSSDK bypass、riskToken 净化及 Up/Suncorp/ubank 消息 Hook;整理 reverse/ 脚本与 Frida 工具链,并补充当日工作说明文档。
This commit is contained in:
19
reverse/scripts/find_native_encrypt.py
Normal file
19
reverse/scripts/find_native_encrypt.py
Normal file
@@ -0,0 +1,19 @@
|
||||
# -*- coding: utf-8 -*-
|
||||
import re
|
||||
import zipfile
|
||||
from pathlib import Path
|
||||
|
||||
APK = Path(__file__).resolve().parent.parent / "apks" / "seabank_ph_base.apk"
|
||||
with zipfile.ZipFile(str(APK)) as zf:
|
||||
data = b"".join(zf.read(n) for n in zf.namelist() if n.endswith(".dex"))
|
||||
for kw in [b"NativeEncrypt", b"CharacterCrypto", b"IV_Monitor", b"register scene", b"dfp is empty"]:
|
||||
print(kw.decode(), data.count(kw))
|
||||
print("\n--- bke.lib.jni crypto/security ---")
|
||||
seen = set()
|
||||
for m in re.finditer(rb"Lcom/shopee/bke/lib/jni/[^;]{1,120};", data):
|
||||
s = m.group().decode()[1:-1].replace("/", ".")
|
||||
if s in seen:
|
||||
continue
|
||||
if any(x in s.lower() for x in ("crypto", "encrypt", "security", "native", "tee")):
|
||||
seen.add(s)
|
||||
print(s)
|
||||
Reference in New Issue
Block a user