start replacing create_ functions
This commit is contained in:
@@ -1,3 +1,5 @@
|
||||
import { replaceFunctions } from "./func_replacements.js";
|
||||
|
||||
function hook_fn(name_in_elf, enter, leave) {
|
||||
var symbol_addr = DebugSymbol.fromName(name_in_elf).address;
|
||||
console.log(`${name_in_elf} addr is: ${symbol_addr}`);
|
||||
@@ -127,32 +129,54 @@ const hook_pack_P2pId = () => {
|
||||
);
|
||||
};
|
||||
|
||||
const hook_create_P2pRdy = () => {
|
||||
var sym = "create_P2pRdy";
|
||||
hook_fn(
|
||||
sym,
|
||||
(args) => {
|
||||
console.log(`onEnter ${sym}`);
|
||||
// (ushort *param_1,int param_2,undefined4 *param_3,undefined8 param_4
|
||||
this.out = args[0]; // u16 ptr
|
||||
let _in = args[1].readByteArray(2);
|
||||
console.log("in", _in);
|
||||
},
|
||||
(retval) => {
|
||||
console.log(`onExit ${sym}, retval ${retval}`);
|
||||
console.log(this.out.readByteArray(0x18)); // _g_p2prdy_size = 0x14, retruns +4
|
||||
},
|
||||
);
|
||||
};
|
||||
let indent = 0;
|
||||
function doHooks() {
|
||||
var libnative_addr = Module.findBaseAddress("libvdp.so");
|
||||
// const prefixes = ["Send_Pkt*", "P2P*", "*RcvTh*", "parse_*"]; // "XQP2P*",
|
||||
const prefixes = ["parse_*", "pack_*", "Send_Pkt*"]; // "XQP2P*",
|
||||
// const prefixes = ["parse_*", "pack_*", "Send_Pkt*", "create_*"];
|
||||
const prefixes = ["create_*"];
|
||||
const spam = ["XQP2P_Check_Buffer", "P2P_ChannelBufferCheck"];
|
||||
prefixes
|
||||
.map((prefix) => DebugSymbol.findFunctionsMatching(prefix))
|
||||
.flat()
|
||||
.map(DebugSymbol.fromAddress)
|
||||
.filter((dbg) => !spam.includes(dbg.name))
|
||||
.map((dbg) => {
|
||||
Interceptor.attach(dbg.address, {
|
||||
onEnter: (args) => {
|
||||
indent = indent + 1;
|
||||
console.log(" ".repeat(indent) + dbg.name);
|
||||
},
|
||||
onLeave: (retval) => {
|
||||
indent = indent - 1;
|
||||
},
|
||||
});
|
||||
console.log(`Hooked ${dbg.name}`);
|
||||
});
|
||||
|
||||
if (libnative_addr) {
|
||||
hook___android_log_print();
|
||||
hook_create_P2pRdy;
|
||||
const replaced = replaceFunctions();
|
||||
console.log(replaced);
|
||||
prefixes
|
||||
.map((prefix) => DebugSymbol.findFunctionsMatching(prefix))
|
||||
.flat()
|
||||
.map(DebugSymbol.fromAddress)
|
||||
.filter((dbg) => !spam.includes(dbg.name))
|
||||
.map((dbg) => {
|
||||
Interceptor.attach(dbg.address, {
|
||||
onEnter: (args) => {
|
||||
indent = indent + 1;
|
||||
let flag = replaced.includes(dbg.name) ? "[REPLACED] " : "";
|
||||
console.log(" ".repeat(indent) + flag + dbg.name);
|
||||
},
|
||||
onLeave: (retval) => {
|
||||
indent = indent - 1;
|
||||
},
|
||||
});
|
||||
console.log(`Hooked ${dbg.name}`);
|
||||
});
|
||||
|
||||
// hook_p2p_read();
|
||||
// hook_pack_P2pId();
|
||||
// hook_pack_ClntPkt();
|
||||
|
||||
@@ -0,0 +1,43 @@
|
||||
const create_LanSearch = (buf) => {
|
||||
// buf is u16*
|
||||
buf.writeU16(0x30f1);
|
||||
buf.add(2).writeU16(0x0);
|
||||
return 4; // 2 x u16 entries = 4bytes
|
||||
};
|
||||
|
||||
const create_P2pAliveAck = (buf) => {
|
||||
// buf is u16*
|
||||
buf.writeU16(0xe1f1);
|
||||
buf.add(2).writeU16(0x0);
|
||||
return 4; // 2 x u16 entries = 4bytes
|
||||
};
|
||||
const create_P2pAlive = (buf) => {
|
||||
// buf is u16*
|
||||
buf.writeU16(0xe0f1);
|
||||
buf.add(2).writeU16(0x0);
|
||||
return 4; // 2 x u16 entries = 4bytes
|
||||
};
|
||||
|
||||
export const replace_func = (stub, ret, args) => {
|
||||
const name_in_elf = stub.name;
|
||||
const symbol_addr = DebugSymbol.fromName(name_in_elf).address;
|
||||
if (symbol_addr == 0) {
|
||||
console.error(`Could not find ${name_in_elf}`);
|
||||
return;
|
||||
}
|
||||
console.log(
|
||||
`Replacing ${name_in_elf}, signature "${ret} ${name_in_elf}(${args})"`,
|
||||
);
|
||||
Interceptor.replace(symbol_addr, new NativeCallback(stub, ret, args));
|
||||
};
|
||||
|
||||
export const replaceFunctions = () => {
|
||||
const replacements = [
|
||||
[create_P2pAlive, "uchar", ["pointer"]],
|
||||
[create_P2pAliveAck, "uchar", ["pointer"]],
|
||||
[create_LanSearch, "uchar", ["pointer"]],
|
||||
];
|
||||
|
||||
replacements.forEach((x) => replace_func(...x));
|
||||
return replacements.map((x) => x[0].name);
|
||||
};
|
||||
Reference in New Issue
Block a user