├── .gitignore
├── app
├── .gitignore
├── build.gradle
├── proguard-rules.pro
└── src
│ ├── androidTest
│ └── java
│ │ └── com
│ │ └── leadroyal
│ │ └── friposed
│ │ └── ExampleInstrumentedTest.java
│ ├── main
│ ├── AndroidManifest.xml
│ ├── assets
│ │ └── friposed.json
│ ├── java
│ │ └── com
│ │ │ └── leadroyal
│ │ │ └── friposed
│ │ │ ├── MainActivity.java
│ │ │ └── SimpleHook.java
│ └── res
│ │ ├── drawable-v24
│ │ └── ic_launcher_foreground.xml
│ │ ├── drawable
│ │ └── ic_launcher_background.xml
│ │ ├── layout
│ │ └── activity_main.xml
│ │ ├── mipmap-anydpi-v26
│ │ ├── ic_launcher.xml
│ │ └── ic_launcher_round.xml
│ │ ├── mipmap-hdpi
│ │ ├── ic_launcher.png
│ │ └── ic_launcher_round.png
│ │ ├── mipmap-mdpi
│ │ ├── ic_launcher.png
│ │ └── ic_launcher_round.png
│ │ ├── mipmap-xhdpi
│ │ ├── ic_launcher.png
│ │ └── ic_launcher_round.png
│ │ ├── mipmap-xxhdpi
│ │ ├── ic_launcher.png
│ │ └── ic_launcher_round.png
│ │ ├── mipmap-xxxhdpi
│ │ ├── ic_launcher.png
│ │ └── ic_launcher_round.png
│ │ └── values
│ │ ├── colors.xml
│ │ ├── strings.xml
│ │ └── styles.xml
│ └── test
│ └── java
│ └── com
│ └── leadroyal
│ └── friposed
│ └── ExampleUnitTest.java
├── build.gradle
├── friposed-api
├── .gitignore
├── build.gradle
└── src
│ └── main
│ └── java
│ └── com
│ └── leadroyal
│ └── friposed
│ ├── IHook.java
│ ├── InvokedByFrida.java
│ └── ParamObj.java
├── friposed.js
├── gradle.properties
├── gradle
└── wrapper
│ ├── gradle-wrapper.jar
│ └── gradle-wrapper.properties
├── gradlew
├── gradlew.bat
├── readme.md
└── settings.gradle
/.gitignore:
--------------------------------------------------------------------------------
1 | *.iml
2 | .gradle
3 | /local.properties
4 | /.idea/caches
5 | /.idea/libraries
6 | /.idea/modules.xml
7 | /.idea/workspace.xml
8 | /.idea/navEditor.xml
9 | /.idea/assetWizardSettings.xml
10 | .DS_Store
11 | /build
12 | /captures
13 | .externalNativeBuild
14 | .cxx
15 | .idea
--------------------------------------------------------------------------------
/app/.gitignore:
--------------------------------------------------------------------------------
1 | /build
--------------------------------------------------------------------------------
/app/build.gradle:
--------------------------------------------------------------------------------
1 | apply plugin: 'com.android.application'
2 |
3 | android {
4 | compileSdkVersion 29
5 | buildToolsVersion "29.0.3"
6 |
7 | defaultConfig {
8 | applicationId "com.leadroyal.friposed"
9 | minSdkVersion 19
10 | targetSdkVersion 29
11 | versionCode 1
12 | versionName "1.0"
13 |
14 | testInstrumentationRunner "androidx.test.runner.AndroidJUnitRunner"
15 | }
16 |
17 | buildTypes {
18 | release {
19 | minifyEnabled false
20 | proguardFiles getDefaultProguardFile('proguard-android-optimize.txt'), 'proguard-rules.pro'
21 | }
22 | }
23 | }
24 |
25 | dependencies {
26 | implementation project(":friposed-api")
27 | implementation fileTree(dir: "libs", include: ["*.jar"])
28 | implementation 'androidx.appcompat:appcompat:1.1.0'
29 | implementation 'androidx.constraintlayout:constraintlayout:1.1.3'
30 | testImplementation 'junit:junit:4.12'
31 | androidTestImplementation 'androidx.test.ext:junit:1.1.1'
32 | androidTestImplementation 'androidx.test.espresso:espresso-core:3.2.0'
33 |
34 | }
--------------------------------------------------------------------------------
/app/proguard-rules.pro:
--------------------------------------------------------------------------------
1 | # Add project specific ProGuard rules here.
2 | # You can control the set of applied configuration files using the
3 | # proguardFiles setting in build.gradle.
4 | #
5 | # For more details, see
6 | # http://developer.android.com/guide/developing/tools/proguard.html
7 |
8 | # If your project uses WebView with JS, uncomment the following
9 | # and specify the fully qualified class name to the JavaScript interface
10 | # class:
11 | #-keepclassmembers class fqcn.of.javascript.interface.for.webview {
12 | # public *;
13 | #}
14 |
15 | # Uncomment this to preserve the line number information for
16 | # debugging stack traces.
17 | #-keepattributes SourceFile,LineNumberTable
18 |
19 | # If you keep the line number information, uncomment this to
20 | # hide the original source file name.
21 | #-renamesourcefileattribute SourceFile
--------------------------------------------------------------------------------
/app/src/androidTest/java/com/leadroyal/friposed/ExampleInstrumentedTest.java:
--------------------------------------------------------------------------------
1 | package com.leadroyal.friposed;
2 |
3 | import android.content.Context;
4 |
5 | import androidx.test.platform.app.InstrumentationRegistry;
6 | import androidx.test.ext.junit.runners.AndroidJUnit4;
7 |
8 | import org.junit.Test;
9 | import org.junit.runner.RunWith;
10 |
11 | import static org.junit.Assert.*;
12 |
13 | /**
14 | * Instrumented test, which will execute on an Android device.
15 | *
16 | * @see Testing documentation
17 | */
18 | @RunWith(AndroidJUnit4.class)
19 | public class ExampleInstrumentedTest {
20 | @Test
21 | public void useAppContext() {
22 | // Context of the app under test.
23 | Context appContext = InstrumentationRegistry.getInstrumentation().getTargetContext();
24 | assertEquals("com.leadroyal.friposed", appContext.getPackageName());
25 | }
26 | }
--------------------------------------------------------------------------------
/app/src/main/AndroidManifest.xml:
--------------------------------------------------------------------------------
1 |
2 |
4 |
5 |
12 |
13 |
14 |
15 |
16 |
17 |
18 |
19 |
20 |
21 |
--------------------------------------------------------------------------------
/app/src/main/assets/friposed.json:
--------------------------------------------------------------------------------
1 | [
2 | {
3 | "enable": true,
4 | "targetPackage": "com.leadroyal.friposed",
5 | "targetClassName": "com.leadroyal.friposed.MainActivity",
6 | "targetMethodSig": "func(java.lang.String,int)",
7 | "hookClassName": "com.leadroyal.friposed.SimpleHook"
8 | }
9 | ]
--------------------------------------------------------------------------------
/app/src/main/java/com/leadroyal/friposed/MainActivity.java:
--------------------------------------------------------------------------------
1 | package com.leadroyal.friposed;
2 |
3 | import android.os.Bundle;
4 | import android.util.Log;
5 | import android.view.View;
6 |
7 | import androidx.appcompat.app.AppCompatActivity;
8 |
9 | public class MainActivity extends AppCompatActivity {
10 | private static final String TAG = "MainActivity";
11 |
12 | @Override
13 | protected void onCreate(Bundle savedInstanceState) {
14 | super.onCreate(savedInstanceState);
15 | setContentView(R.layout.activity_main);
16 | }
17 |
18 | public void click(View view) {
19 | func("Click Me!", 123);
20 | }
21 |
22 | private void func(String s, int i) {
23 | Log.d(TAG, s + '\t' + i);
24 | }
25 | }
--------------------------------------------------------------------------------
/app/src/main/java/com/leadroyal/friposed/SimpleHook.java:
--------------------------------------------------------------------------------
1 | package com.leadroyal.friposed;
2 |
3 | import android.util.Log;
4 |
5 | public class SimpleHook implements IHook {
6 | private static final String TAG = "SimpleHook";
7 |
8 | @Override
9 | public void beforeHook(ParamObj paramObj) {
10 | for (int i = 0; i < paramObj.args.length; i++) {
11 | if (paramObj.args[i] == null)
12 | Log.e(TAG, "args[" + i + "]=" + "null@null");
13 | else
14 | Log.e(TAG, "args[" + i + "]=" + paramObj.args[i] + "@" + paramObj.args[i].getClass());
15 | }
16 | }
17 |
18 | @Override
19 | public void afterHook(ParamObj paramObj) {
20 | Log.e(TAG, "return " + paramObj.getResult());
21 | }
22 | }
23 |
--------------------------------------------------------------------------------
/app/src/main/res/drawable-v24/ic_launcher_foreground.xml:
--------------------------------------------------------------------------------
1 |
7 |
8 |
9 |
15 |
18 |
21 |
22 |
23 |
24 |
30 |
--------------------------------------------------------------------------------
/app/src/main/res/drawable/ic_launcher_background.xml:
--------------------------------------------------------------------------------
1 |
2 |
7 |
10 |
15 |
20 |
25 |
30 |
35 |
40 |
45 |
50 |
55 |
60 |
65 |
70 |
75 |
80 |
85 |
90 |
95 |
100 |
105 |
110 |
115 |
120 |
125 |
130 |
135 |
140 |
145 |
150 |
155 |
160 |
165 |
170 |
171 |
--------------------------------------------------------------------------------
/app/src/main/res/layout/activity_main.xml:
--------------------------------------------------------------------------------
1 |
2 |
8 |
9 |
20 |
21 |
--------------------------------------------------------------------------------
/app/src/main/res/mipmap-anydpi-v26/ic_launcher.xml:
--------------------------------------------------------------------------------
1 |
2 |
3 |
4 |
5 |
--------------------------------------------------------------------------------
/app/src/main/res/mipmap-anydpi-v26/ic_launcher_round.xml:
--------------------------------------------------------------------------------
1 |
2 |
3 |
4 |
5 |
--------------------------------------------------------------------------------
/app/src/main/res/mipmap-hdpi/ic_launcher.png:
--------------------------------------------------------------------------------
https://raw.githubusercontent.com/LeadroyaL/friposed/726b26dab8d419d5f2b5e23cdbd128022fc803fe/app/src/main/res/mipmap-hdpi/ic_launcher.png
--------------------------------------------------------------------------------
/app/src/main/res/mipmap-hdpi/ic_launcher_round.png:
--------------------------------------------------------------------------------
https://raw.githubusercontent.com/LeadroyaL/friposed/726b26dab8d419d5f2b5e23cdbd128022fc803fe/app/src/main/res/mipmap-hdpi/ic_launcher_round.png
--------------------------------------------------------------------------------
/app/src/main/res/mipmap-mdpi/ic_launcher.png:
--------------------------------------------------------------------------------
https://raw.githubusercontent.com/LeadroyaL/friposed/726b26dab8d419d5f2b5e23cdbd128022fc803fe/app/src/main/res/mipmap-mdpi/ic_launcher.png
--------------------------------------------------------------------------------
/app/src/main/res/mipmap-mdpi/ic_launcher_round.png:
--------------------------------------------------------------------------------
https://raw.githubusercontent.com/LeadroyaL/friposed/726b26dab8d419d5f2b5e23cdbd128022fc803fe/app/src/main/res/mipmap-mdpi/ic_launcher_round.png
--------------------------------------------------------------------------------
/app/src/main/res/mipmap-xhdpi/ic_launcher.png:
--------------------------------------------------------------------------------
https://raw.githubusercontent.com/LeadroyaL/friposed/726b26dab8d419d5f2b5e23cdbd128022fc803fe/app/src/main/res/mipmap-xhdpi/ic_launcher.png
--------------------------------------------------------------------------------
/app/src/main/res/mipmap-xhdpi/ic_launcher_round.png:
--------------------------------------------------------------------------------
https://raw.githubusercontent.com/LeadroyaL/friposed/726b26dab8d419d5f2b5e23cdbd128022fc803fe/app/src/main/res/mipmap-xhdpi/ic_launcher_round.png
--------------------------------------------------------------------------------
/app/src/main/res/mipmap-xxhdpi/ic_launcher.png:
--------------------------------------------------------------------------------
https://raw.githubusercontent.com/LeadroyaL/friposed/726b26dab8d419d5f2b5e23cdbd128022fc803fe/app/src/main/res/mipmap-xxhdpi/ic_launcher.png
--------------------------------------------------------------------------------
/app/src/main/res/mipmap-xxhdpi/ic_launcher_round.png:
--------------------------------------------------------------------------------
https://raw.githubusercontent.com/LeadroyaL/friposed/726b26dab8d419d5f2b5e23cdbd128022fc803fe/app/src/main/res/mipmap-xxhdpi/ic_launcher_round.png
--------------------------------------------------------------------------------
/app/src/main/res/mipmap-xxxhdpi/ic_launcher.png:
--------------------------------------------------------------------------------
https://raw.githubusercontent.com/LeadroyaL/friposed/726b26dab8d419d5f2b5e23cdbd128022fc803fe/app/src/main/res/mipmap-xxxhdpi/ic_launcher.png
--------------------------------------------------------------------------------
/app/src/main/res/mipmap-xxxhdpi/ic_launcher_round.png:
--------------------------------------------------------------------------------
https://raw.githubusercontent.com/LeadroyaL/friposed/726b26dab8d419d5f2b5e23cdbd128022fc803fe/app/src/main/res/mipmap-xxxhdpi/ic_launcher_round.png
--------------------------------------------------------------------------------
/app/src/main/res/values/colors.xml:
--------------------------------------------------------------------------------
1 |
2 |
3 | #6200EE
4 | #3700B3
5 | #03DAC5
6 |
--------------------------------------------------------------------------------
/app/src/main/res/values/strings.xml:
--------------------------------------------------------------------------------
1 |
2 | friposed
3 |
--------------------------------------------------------------------------------
/app/src/main/res/values/styles.xml:
--------------------------------------------------------------------------------
1 |
2 |
3 |
9 |
10 |
--------------------------------------------------------------------------------
/app/src/test/java/com/leadroyal/friposed/ExampleUnitTest.java:
--------------------------------------------------------------------------------
1 | package com.leadroyal.friposed;
2 |
3 | import org.junit.Test;
4 |
5 | import static org.junit.Assert.*;
6 |
7 | /**
8 | * Example local unit test, which will execute on the development machine (host).
9 | *
10 | * @see Testing documentation
11 | */
12 | public class ExampleUnitTest {
13 | @Test
14 | public void addition_isCorrect() {
15 | assertEquals(4, 2 + 2);
16 | }
17 | }
--------------------------------------------------------------------------------
/build.gradle:
--------------------------------------------------------------------------------
1 | // Top-level build file where you can add configuration options common to all sub-projects/modules.
2 | buildscript {
3 | repositories {
4 | google()
5 | jcenter()
6 | }
7 | dependencies {
8 | classpath "com.android.tools.build:gradle:4.0.0"
9 |
10 | // NOTE: Do not place your application dependencies here; they belong
11 | // in the individual module build.gradle files
12 | }
13 | }
14 |
15 | allprojects {
16 | repositories {
17 | google()
18 | jcenter()
19 | }
20 | }
21 |
22 | task clean(type: Delete) {
23 | delete rootProject.buildDir
24 | }
--------------------------------------------------------------------------------
/friposed-api/.gitignore:
--------------------------------------------------------------------------------
1 | /build
--------------------------------------------------------------------------------
/friposed-api/build.gradle:
--------------------------------------------------------------------------------
1 | apply plugin: 'java-library'
2 |
3 | dependencies {
4 | implementation fileTree(dir: 'libs', include: ['*.jar'])
5 | }
6 |
7 | sourceCompatibility = "1.7"
8 | targetCompatibility = "1.7"
--------------------------------------------------------------------------------
/friposed-api/src/main/java/com/leadroyal/friposed/IHook.java:
--------------------------------------------------------------------------------
1 | package com.leadroyal.friposed;
2 |
3 | public interface IHook {
4 | public void beforeHook(ParamObj paramObj);
5 |
6 | public void afterHook(ParamObj paramObj);
7 | }
8 |
--------------------------------------------------------------------------------
/friposed-api/src/main/java/com/leadroyal/friposed/InvokedByFrida.java:
--------------------------------------------------------------------------------
1 | package com.leadroyal.friposed;
2 |
3 |
4 | public @interface InvokedByFrida {
5 | }
6 |
--------------------------------------------------------------------------------
/friposed-api/src/main/java/com/leadroyal/friposed/ParamObj.java:
--------------------------------------------------------------------------------
1 | package com.leadroyal.friposed;
2 |
3 | public class ParamObj {
4 | public Object thisObj;
5 | public Object[] args;
6 | @InvokedByFrida
7 | private boolean returnEarly;
8 | @InvokedByFrida
9 | private Object result;
10 |
11 | public ParamObj(Object thisObj, Object[] args) {
12 | this.thisObj = thisObj;
13 | this.args = args;
14 | }
15 |
16 | public Object getResult() {
17 | return this.result;
18 | }
19 |
20 | public void setResult(Object result) {
21 | this.result = result;
22 | this.returnEarly = true;
23 | }
24 | }
25 |
--------------------------------------------------------------------------------
/friposed.js:
--------------------------------------------------------------------------------
1 | Java.perform(function () {
2 | function loadApk(apkPath) {
3 | Java.openClassFile(apkPath).load();
4 | }
5 | function hasFile(fileName) {
6 | return Java.use("java.io.File").$new(fileName).exists();
7 | }
8 | function getPackagePath(pkgName) {
9 | return Java.use("android.app.ActivityThread").currentApplication().getPackageManager().getPackageInfo(pkgName, 0).applicationInfo.value.sourceDir.value;
10 | }
11 | function js2java(typeName, value) {
12 | // js boolean/number/Int64 -- > java boolean/byte/short/int/long/float/double
13 | switch (typeName) {
14 | case "Z":
15 | return Java.use("java.lang.Boolean").valueOf(value);
16 | case "B":
17 | return Java.use("java.lang.Byte").valueOf(value);
18 | case "S":
19 | return Java.use("java.lang.Short").valueOf(value);
20 | case "I":
21 | return Java.use("java.lang.Integer").valueOf(value);
22 | case "J":
23 | return Java.use("java.lang.Long").valueOf(value);
24 | case "F":
25 | return Java.use("java.lang.Float").valueOf(value);
26 | case "D":
27 | return Java.use("java.lang.Double").valueOf(value);
28 | default:
29 | return value;
30 | }
31 | }
32 | function java2js(typeName, value) {
33 | // java boolean/byte/short/int/long/float/double --> js boolean/number/Int64
34 | switch (typeName) {
35 | case "Z":
36 | return Java.cast(value, Java.use("java.lang.Boolean")).booleanValue();
37 | case "B":
38 | return Java.cast(value, Java.use("java.lang.Byte")).byteValue();
39 | case "S":
40 | return Java.cast(value, Java.use("java.lang.Short")).shortValue();
41 | case "I":
42 | return Java.cast(value, Java.use("java.lang.Integer")).intValue();
43 | case "J":
44 | return Java.cast(value, Java.use("java.lang.Long")).longValue();
45 | case "F":
46 | return Java.cast(value, Java.use("java.lang.Float")).floatValue();
47 | case "D":
48 | return Java.cast(value, Java.use("java.lang.Double")).doubleValue();
49 | default:
50 | return value;
51 | }
52 | }
53 | function readZipContent(zipPath, entryName) {
54 | var zipFile = Java.use("java.util.zip.ZipFile").$new(zipPath);
55 | var zipEntry = zipFile.getEntry(entryName);
56 | var fis = zipFile.getInputStream(zipEntry);
57 | var fakebs = new Array(fis.available());
58 | for (var index = 0; index < fakebs.length; index++) {
59 | fakebs[index] = 0;
60 | }
61 | var _bs = Java.array("byte", fakebs);
62 | fis.read(_bs);
63 | fis.close();
64 | zipFile.close();
65 | return Java.use("java.lang.String").$new(_bs).toString();
66 | }
67 | function findMatch(overloads, sig) {
68 | var sp = sig.split(",");
69 | for (var i in overloads) {
70 | var curArgumentTypes = overloads[i].argumentTypes;
71 | if (sp.length != curArgumentTypes.length)
72 | continue;
73 | for (var j in curArgumentTypes) {
74 | if (curArgumentTypes[j].className != sp[j]) {
75 | continue;
76 | }
77 | }
78 | return overloads[i];
79 | }
80 | }
81 | function getPackageName() {
82 | return Java.use("android.app.ActivityThread").currentApplication().getPackageName();
83 | }
84 |
85 | // load plugin
86 | const LOCAL_APK_PATH = "/data/local/tmp/friposed.apk";
87 | const FRIPOSED_PKGNAME = "com.leadroyal.friposed";
88 | var dir;
89 | if (hasFile(LOCAL_APK_PATH)) {
90 | dir = LOCAL_APK_PATH;
91 | } else {
92 | dir = getPackagePath(FRIPOSED_PKGNAME);
93 | }
94 | var content = readZipContent(dir, "assets/friposed.json")
95 | loadApk(dir);
96 |
97 | var config = JSON.parse(content);
98 | var clz_ParamObj = Java.use("com.leadroyal.friposed.ParamObj");
99 |
100 | var currentPackageName = getPackageName();
101 | for (var configIndex in config) {
102 | if (config[configIndex].enable != undefined && !config[configIndex].enable) {
103 | console.log("[Disabled]. Skip:", config[configIndex].hookClassName);
104 | continue;
105 | }
106 | if (config[configIndex].targetPackage != currentPackageName) {
107 | console.log("[Mismatch]. Skip: target/current", config[configIndex].targetPackage, currentPackageName);
108 | continue;
109 | }
110 | var targetClassName = config[configIndex].targetClassName;
111 | var targetMethodSig = config[configIndex].targetMethodSig;
112 | var targetMethodName = targetMethodSig.split('(')[0];
113 | var targetMethodParam = targetMethodSig.split('(')[1];
114 | targetMethodParam = targetMethodParam.substring(0, targetMethodParam.length - 1);
115 | var targetMethod = findMatch(Java.use(targetClassName)[targetMethodName].overloads, targetMethodSig);
116 | var hookClassName = config[configIndex].hookClassName;
117 | var hook = Java.use(hookClassName).$new();
118 | startHook(targetMethod, hook);
119 | }
120 |
121 | function startHook(targetMethod, hook) {
122 | targetMethod.implementation = function () {
123 | // 将 js 的 arguments 处理为 java 的 Object[],主要处理基本类型
124 | var argJsArray = Array(arguments.length);
125 | for (var i = 0; i < arguments.length; i++) {
126 | argJsArray[i] = js2java(targetMethod.argumentTypes[i].name, arguments[i]);
127 | }
128 | var argJavaArray = Java.array("java.lang.Object", argJsArray);
129 |
130 | // 根据是否static,决定是否传递this
131 | var isInstanceMethod = targetMethod.type == 3; // Java.MethodType.Instance
132 | var thisObject = null;
133 | if (isInstanceMethod)
134 | thisObject = this;
135 |
136 | var param_obj = clz_ParamObj.$new(thisObject, argJavaArray);
137 |
138 | // 调用before
139 | console.log("before invoked:", targetMethod.methodName);
140 | hook.beforeHook(param_obj);
141 |
142 | // 如果需要提前返回,就返回
143 | if (param_obj.returnEarly.value) {
144 | console.log("return early");
145 | } else {
146 | // 执行原先的方法
147 | // 将 Object[] 转为 frida传参的格式,主要处理基本类型
148 | var after_obj = param_obj.args.value;
149 | var invokeArray = Array(after_obj.length);
150 | for (var i = 0; i < after_obj.length; i++) {
151 | invokeArray[i] = java2js(targetMethod.argumentTypes[i].name, after_obj[i]);
152 | }
153 | console.log("original invoked:", targetMethod.methodName);
154 | var ret = targetMethod.apply(this, invokeArray);
155 |
156 | // 将结果赋值给 param_obj
157 | var ret2js = js2java(targetMethod.returnType.name, ret);
158 | if (targetMethod.returnType.name == "V") {
159 | // 如果函数的返回值声明为 void,不要设置param_obj.result,因为 frida 会报错
160 | } else {
161 | param_obj.result.value = ret2js;
162 | }
163 | }
164 |
165 | // 调用after
166 | console.log("after invoked:", targetMethod.methodName);
167 | hook.afterHook(param_obj);
168 |
169 | // 如果函数的返回值声明为 void,返回undefined 表示返回void
170 | if (targetMethod.returnType.name == "V")
171 | return undefined;
172 |
173 | // 最终结果以 param_obj.result 为准,转为js认的基本类型
174 | return java2js(targetMethod.returnType.name, param_obj.result.value);
175 | };
176 | }
177 | });
--------------------------------------------------------------------------------
/gradle.properties:
--------------------------------------------------------------------------------
1 | # Project-wide Gradle settings.
2 | # IDE (e.g. Android Studio) users:
3 | # Gradle settings configured through the IDE *will override*
4 | # any settings specified in this file.
5 | # For more details on how to configure your build environment visit
6 | # http://www.gradle.org/docs/current/userguide/build_environment.html
7 | # Specifies the JVM arguments used for the daemon process.
8 | # The setting is particularly useful for tweaking memory settings.
9 | org.gradle.jvmargs=-Xmx2048m
10 | # When configured, Gradle will run in incubating parallel mode.
11 | # This option should only be used with decoupled projects. More details, visit
12 | # http://www.gradle.org/docs/current/userguide/multi_project_builds.html#sec:decoupled_projects
13 | # org.gradle.parallel=true
14 | # AndroidX package structure to make it clearer which packages are bundled with the
15 | # Android operating system, and which are packaged with your app"s APK
16 | # https://developer.android.com/topic/libraries/support-library/androidx-rn
17 | android.useAndroidX=true
18 | # Automatically convert third-party libraries to use AndroidX
19 | android.enableJetifier=true
--------------------------------------------------------------------------------
/gradle/wrapper/gradle-wrapper.jar:
--------------------------------------------------------------------------------
https://raw.githubusercontent.com/LeadroyaL/friposed/726b26dab8d419d5f2b5e23cdbd128022fc803fe/gradle/wrapper/gradle-wrapper.jar
--------------------------------------------------------------------------------
/gradle/wrapper/gradle-wrapper.properties:
--------------------------------------------------------------------------------
1 | #Fri May 29 19:34:43 CST 2020
2 | distributionBase=GRADLE_USER_HOME
3 | distributionPath=wrapper/dists
4 | zipStoreBase=GRADLE_USER_HOME
5 | zipStorePath=wrapper/dists
6 | distributionUrl=https\://services.gradle.org/distributions/gradle-6.1.1-all.zip
7 |
--------------------------------------------------------------------------------
/gradlew:
--------------------------------------------------------------------------------
1 | #!/usr/bin/env sh
2 |
3 | ##############################################################################
4 | ##
5 | ## Gradle start up script for UN*X
6 | ##
7 | ##############################################################################
8 |
9 | # Attempt to set APP_HOME
10 | # Resolve links: $0 may be a link
11 | PRG="$0"
12 | # Need this for relative symlinks.
13 | while [ -h "$PRG" ] ; do
14 | ls=`ls -ld "$PRG"`
15 | link=`expr "$ls" : '.*-> \(.*\)$'`
16 | if expr "$link" : '/.*' > /dev/null; then
17 | PRG="$link"
18 | else
19 | PRG=`dirname "$PRG"`"/$link"
20 | fi
21 | done
22 | SAVED="`pwd`"
23 | cd "`dirname \"$PRG\"`/" >/dev/null
24 | APP_HOME="`pwd -P`"
25 | cd "$SAVED" >/dev/null
26 |
27 | APP_NAME="Gradle"
28 | APP_BASE_NAME=`basename "$0"`
29 |
30 | # Add default JVM options here. You can also use JAVA_OPTS and GRADLE_OPTS to pass JVM options to this script.
31 | DEFAULT_JVM_OPTS=""
32 |
33 | # Use the maximum available, or set MAX_FD != -1 to use that value.
34 | MAX_FD="maximum"
35 |
36 | warn () {
37 | echo "$*"
38 | }
39 |
40 | die () {
41 | echo
42 | echo "$*"
43 | echo
44 | exit 1
45 | }
46 |
47 | # OS specific support (must be 'true' or 'false').
48 | cygwin=false
49 | msys=false
50 | darwin=false
51 | nonstop=false
52 | case "`uname`" in
53 | CYGWIN* )
54 | cygwin=true
55 | ;;
56 | Darwin* )
57 | darwin=true
58 | ;;
59 | MINGW* )
60 | msys=true
61 | ;;
62 | NONSTOP* )
63 | nonstop=true
64 | ;;
65 | esac
66 |
67 | CLASSPATH=$APP_HOME/gradle/wrapper/gradle-wrapper.jar
68 |
69 | # Determine the Java command to use to start the JVM.
70 | if [ -n "$JAVA_HOME" ] ; then
71 | if [ -x "$JAVA_HOME/jre/sh/java" ] ; then
72 | # IBM's JDK on AIX uses strange locations for the executables
73 | JAVACMD="$JAVA_HOME/jre/sh/java"
74 | else
75 | JAVACMD="$JAVA_HOME/bin/java"
76 | fi
77 | if [ ! -x "$JAVACMD" ] ; then
78 | die "ERROR: JAVA_HOME is set to an invalid directory: $JAVA_HOME
79 |
80 | Please set the JAVA_HOME variable in your environment to match the
81 | location of your Java installation."
82 | fi
83 | else
84 | JAVACMD="java"
85 | which java >/dev/null 2>&1 || die "ERROR: JAVA_HOME is not set and no 'java' command could be found in your PATH.
86 |
87 | Please set the JAVA_HOME variable in your environment to match the
88 | location of your Java installation."
89 | fi
90 |
91 | # Increase the maximum file descriptors if we can.
92 | if [ "$cygwin" = "false" -a "$darwin" = "false" -a "$nonstop" = "false" ] ; then
93 | MAX_FD_LIMIT=`ulimit -H -n`
94 | if [ $? -eq 0 ] ; then
95 | if [ "$MAX_FD" = "maximum" -o "$MAX_FD" = "max" ] ; then
96 | MAX_FD="$MAX_FD_LIMIT"
97 | fi
98 | ulimit -n $MAX_FD
99 | if [ $? -ne 0 ] ; then
100 | warn "Could not set maximum file descriptor limit: $MAX_FD"
101 | fi
102 | else
103 | warn "Could not query maximum file descriptor limit: $MAX_FD_LIMIT"
104 | fi
105 | fi
106 |
107 | # For Darwin, add options to specify how the application appears in the dock
108 | if $darwin; then
109 | GRADLE_OPTS="$GRADLE_OPTS \"-Xdock:name=$APP_NAME\" \"-Xdock:icon=$APP_HOME/media/gradle.icns\""
110 | fi
111 |
112 | # For Cygwin, switch paths to Windows format before running java
113 | if $cygwin ; then
114 | APP_HOME=`cygpath --path --mixed "$APP_HOME"`
115 | CLASSPATH=`cygpath --path --mixed "$CLASSPATH"`
116 | JAVACMD=`cygpath --unix "$JAVACMD"`
117 |
118 | # We build the pattern for arguments to be converted via cygpath
119 | ROOTDIRSRAW=`find -L / -maxdepth 1 -mindepth 1 -type d 2>/dev/null`
120 | SEP=""
121 | for dir in $ROOTDIRSRAW ; do
122 | ROOTDIRS="$ROOTDIRS$SEP$dir"
123 | SEP="|"
124 | done
125 | OURCYGPATTERN="(^($ROOTDIRS))"
126 | # Add a user-defined pattern to the cygpath arguments
127 | if [ "$GRADLE_CYGPATTERN" != "" ] ; then
128 | OURCYGPATTERN="$OURCYGPATTERN|($GRADLE_CYGPATTERN)"
129 | fi
130 | # Now convert the arguments - kludge to limit ourselves to /bin/sh
131 | i=0
132 | for arg in "$@" ; do
133 | CHECK=`echo "$arg"|egrep -c "$OURCYGPATTERN" -`
134 | CHECK2=`echo "$arg"|egrep -c "^-"` ### Determine if an option
135 |
136 | if [ $CHECK -ne 0 ] && [ $CHECK2 -eq 0 ] ; then ### Added a condition
137 | eval `echo args$i`=`cygpath --path --ignore --mixed "$arg"`
138 | else
139 | eval `echo args$i`="\"$arg\""
140 | fi
141 | i=$((i+1))
142 | done
143 | case $i in
144 | (0) set -- ;;
145 | (1) set -- "$args0" ;;
146 | (2) set -- "$args0" "$args1" ;;
147 | (3) set -- "$args0" "$args1" "$args2" ;;
148 | (4) set -- "$args0" "$args1" "$args2" "$args3" ;;
149 | (5) set -- "$args0" "$args1" "$args2" "$args3" "$args4" ;;
150 | (6) set -- "$args0" "$args1" "$args2" "$args3" "$args4" "$args5" ;;
151 | (7) set -- "$args0" "$args1" "$args2" "$args3" "$args4" "$args5" "$args6" ;;
152 | (8) set -- "$args0" "$args1" "$args2" "$args3" "$args4" "$args5" "$args6" "$args7" ;;
153 | (9) set -- "$args0" "$args1" "$args2" "$args3" "$args4" "$args5" "$args6" "$args7" "$args8" ;;
154 | esac
155 | fi
156 |
157 | # Escape application args
158 | save () {
159 | for i do printf %s\\n "$i" | sed "s/'/'\\\\''/g;1s/^/'/;\$s/\$/' \\\\/" ; done
160 | echo " "
161 | }
162 | APP_ARGS=$(save "$@")
163 |
164 | # Collect all arguments for the java command, following the shell quoting and substitution rules
165 | eval set -- $DEFAULT_JVM_OPTS $JAVA_OPTS $GRADLE_OPTS "\"-Dorg.gradle.appname=$APP_BASE_NAME\"" -classpath "\"$CLASSPATH\"" org.gradle.wrapper.GradleWrapperMain "$APP_ARGS"
166 |
167 | # by default we should be in the correct project dir, but when run from Finder on Mac, the cwd is wrong
168 | if [ "$(uname)" = "Darwin" ] && [ "$HOME" = "$PWD" ]; then
169 | cd "$(dirname "$0")"
170 | fi
171 |
172 | exec "$JAVACMD" "$@"
173 |
--------------------------------------------------------------------------------
/gradlew.bat:
--------------------------------------------------------------------------------
1 | @if "%DEBUG%" == "" @echo off
2 | @rem ##########################################################################
3 | @rem
4 | @rem Gradle startup script for Windows
5 | @rem
6 | @rem ##########################################################################
7 |
8 | @rem Set local scope for the variables with windows NT shell
9 | if "%OS%"=="Windows_NT" setlocal
10 |
11 | set DIRNAME=%~dp0
12 | if "%DIRNAME%" == "" set DIRNAME=.
13 | set APP_BASE_NAME=%~n0
14 | set APP_HOME=%DIRNAME%
15 |
16 | @rem Add default JVM options here. You can also use JAVA_OPTS and GRADLE_OPTS to pass JVM options to this script.
17 | set DEFAULT_JVM_OPTS=
18 |
19 | @rem Find java.exe
20 | if defined JAVA_HOME goto findJavaFromJavaHome
21 |
22 | set JAVA_EXE=java.exe
23 | %JAVA_EXE% -version >NUL 2>&1
24 | if "%ERRORLEVEL%" == "0" goto init
25 |
26 | echo.
27 | echo ERROR: JAVA_HOME is not set and no 'java' command could be found in your PATH.
28 | echo.
29 | echo Please set the JAVA_HOME variable in your environment to match the
30 | echo location of your Java installation.
31 |
32 | goto fail
33 |
34 | :findJavaFromJavaHome
35 | set JAVA_HOME=%JAVA_HOME:"=%
36 | set JAVA_EXE=%JAVA_HOME%/bin/java.exe
37 |
38 | if exist "%JAVA_EXE%" goto init
39 |
40 | echo.
41 | echo ERROR: JAVA_HOME is set to an invalid directory: %JAVA_HOME%
42 | echo.
43 | echo Please set the JAVA_HOME variable in your environment to match the
44 | echo location of your Java installation.
45 |
46 | goto fail
47 |
48 | :init
49 | @rem Get command-line arguments, handling Windows variants
50 |
51 | if not "%OS%" == "Windows_NT" goto win9xME_args
52 |
53 | :win9xME_args
54 | @rem Slurp the command line arguments.
55 | set CMD_LINE_ARGS=
56 | set _SKIP=2
57 |
58 | :win9xME_args_slurp
59 | if "x%~1" == "x" goto execute
60 |
61 | set CMD_LINE_ARGS=%*
62 |
63 | :execute
64 | @rem Setup the command line
65 |
66 | set CLASSPATH=%APP_HOME%\gradle\wrapper\gradle-wrapper.jar
67 |
68 | @rem Execute Gradle
69 | "%JAVA_EXE%" %DEFAULT_JVM_OPTS% %JAVA_OPTS% %GRADLE_OPTS% "-Dorg.gradle.appname=%APP_BASE_NAME%" -classpath "%CLASSPATH%" org.gradle.wrapper.GradleWrapperMain %CMD_LINE_ARGS%
70 |
71 | :end
72 | @rem End local scope for the variables with windows NT shell
73 | if "%ERRORLEVEL%"=="0" goto mainEnd
74 |
75 | :fail
76 | rem Set variable GRADLE_EXIT_CONSOLE if you need the _script_ return code instead of
77 | rem the _cmd.exe /c_ return code!
78 | if not "" == "%GRADLE_EXIT_CONSOLE%" exit 1
79 | exit /b 1
80 |
81 | :mainEnd
82 | if "%OS%"=="Windows_NT" endlocal
83 |
84 | :omega
85 |
--------------------------------------------------------------------------------
/readme.md:
--------------------------------------------------------------------------------
1 | # friposed —— Write java hook with frida
2 |
3 | `friposed = frida + xposed`,字面意思,本来想借助 frida 实现一套完整的 xposed 支持,但由于代价实在太高,于是只能写一套简单的实现。
4 |
5 | ### 一句话用途
6 |
7 | 在 frida 可用时,使用 java 写 hook。
8 |
9 | ### 背景
10 |
11 | 在2017年初,刚接触 frida 时,我就一直在吐槽 frida hook java 的反人类设计,并不是说 frida 项目不好,而是用 js 这种弱类型语言去描述和操作强类型的 java,在 js 里写 java hook 体验很差,本身就是不优雅的。(而且我那台手机用 frida 经常 crash。)
12 |
13 | 0202年已经过去一半了,不怎么使用 frida。看身边小伙伴在用 frida 而不是 xposed,感觉自己落伍了,不够 fashion,于是突发奇想写了这个项目,使用 frida 作为桥梁,提供在 java 里写 hook 的能力,**从而让像我这样“半截入土”的 xposed 开发者仍然可以苟活在 frida 的环境里**。
14 |
15 | 并且对于仅拥有root、未拥有xposed的环境,提供了使用java hook的办法。
16 |
17 | ### Demo体验方法
18 |
19 | demo就是 `friposed.apk` 本身,实现对自己的 hook,可阅读配置文件来理解它`assets/friposed.json`。
20 |
21 | 1. 安装并运行 APP,配好 frida 环境
22 | 2. `frida -U -l friposed.js com.leadroyal.friposed`
23 | 3. 点击桌面上的 button,观察命令行的输出,观察 logcat 的输出,预期结果如下
24 |
25 | ```java
26 | package com.leadroyal.friposed;
27 |
28 | import android.util.Log;
29 |
30 | public class SimpleHook implements IHook {
31 | private static final String TAG = "SimpleHook";
32 |
33 | @Override
34 | public void beforeHook(ParamObj paramObj) {
35 | for (int i = 0; i < paramObj.args.length; i++) {
36 | if (paramObj.args[i] == null)
37 | Log.e(TAG, "args[" + i + "]=" + "null@null");
38 | else
39 | Log.e(TAG, "args[" + i + "]=" + paramObj.args[i] + "@" + paramObj.args[i].getClass());
40 | }
41 | }
42 |
43 | @Override
44 | public void afterHook(ParamObj paramObj) {
45 | Log.e(TAG, "return " + paramObj.getResult());
46 | }
47 | }
48 |
49 | ```
50 |
51 | ```
52 | > frida
53 | [Redmi 8A::com.leadroyal.friposed]-> before invoked: func
54 | original invoked: func
55 | after invoked: func
56 |
57 | > logcat
58 | SimpleHook: args[0]=Click Me!@class java.lang.String
59 | SimpleHook: args[1]=123@class java.lang.Integer
60 | MainActivity: Click Me! 123
61 | SimpleHook: return null
62 | ```
63 |
64 | ### 基础用法
65 |
66 | 1. 打开本项目里的安卓工程 `com.leadroyal.friposed` ,按需修改 `assets/friposed.json`,并且创建对应实现了 `com.leadroyal.friposed.IHook`的类。
67 |
68 | ```json
69 | [
70 | {
71 | "enable": true,
72 | "targetPackage": "com.leadroyal.friposed",
73 | "targetClassName": "com.leadroyal.friposed.MainActivity",
74 | "targetMethodSig": "func(java.lang.String,int)",
75 | "hookClassName": "com.leadroyal.friposed.SimpleHook"
76 | }
77 | ]
78 | ```
79 |
80 | 2. 开发自定义的 Hook(一定要实现 IHook这个接口)。提供基础功能:在`beforeHook`和`afterHook` 对 arguments 进行读写,对 result 进行读写,从而实现`XC_MethodHook`,使用 setResult 实现 `XC_MethodReplacement`。
81 | 3. 安装 `friposed.apk` 或者 `adb push friposed.apk /data/local/tmp/`,
82 | 4. `frida -U friposed.js TARGET_PACKAGE_NAME`
83 |
84 | ### 实现原理
85 |
86 | 使用 frida-cli 进行 attach 后,加载 `com.leadoryal.friposed` 这个 apk,访问内部的 `assets/friposed.json` 配置文件,寻找对应的 class 和 method进行 hook,依次执行这几步操作:
87 |
88 | 1. 调用前的参数传递给 apk 里的 hook 类的 `beforeMethod`,此时可修改参数和返回值
89 | 2. 调用原先的实现或者提前返回
90 | 3. 将参数和返回值传递给 apk 里 hook 类的 `afterMethod`,此时同样可修改参数和返回值
91 | 4. js 将结果返回
92 |
93 | ### 高级用法
94 |
95 | - 不安装 APP 来加载 friposed
96 |
97 | friposed 会先访问 `/data/local/tmp/friposed.apk`,将 apk 文件放到该位置即可,也可以修js改代码的`LOCAL_APK_PATH`使用其他位置的 apk。
98 |
99 | - 使用其他包名
100 |
101 | 修改 js 代码的`FRIPOSED_PKGNAME`使用其他包名作为 friposed 的入口,但一定要保证下面三个文件还存在,建议将`friposed-api`这个 gradle 项目打包带走:
102 | - com.leadroyal.friposed.ParamObj
103 | - com.leadroyal.friposed.IHook
104 | - assets/friposed.json
105 |
106 |
107 | ### 其他
108 |
109 | 这真的只是个小项目,是我第一个 frida 项目也应该是最后一个 frida 项目,因此请不要对它抱有过高的期望,有 bug 和需求请提出来。
--------------------------------------------------------------------------------
/settings.gradle:
--------------------------------------------------------------------------------
1 | include ':app'
2 | include ':friposed-api'
3 | rootProject.name = "friposed"
--------------------------------------------------------------------------------