diff --git a/asd.js b/asd.js index 1d89eae..2d57789 100644 --- a/asd.js +++ b/asd.js @@ -1,3 +1,5 @@ +import { replaceFunctions } from "./func_replacements.js"; + function hook_fn(name_in_elf, enter, leave) { var symbol_addr = DebugSymbol.fromName(name_in_elf).address; console.log(`${name_in_elf} addr is: ${symbol_addr}`); @@ -127,32 +129,54 @@ const hook_pack_P2pId = () => { ); }; +const hook_create_P2pRdy = () => { + var sym = "create_P2pRdy"; + hook_fn( + sym, + (args) => { + console.log(`onEnter ${sym}`); + // (ushort *param_1,int param_2,undefined4 *param_3,undefined8 param_4 + this.out = args[0]; // u16 ptr + let _in = args[1].readByteArray(2); + console.log("in", _in); + }, + (retval) => { + console.log(`onExit ${sym}, retval ${retval}`); + console.log(this.out.readByteArray(0x18)); // _g_p2prdy_size = 0x14, retruns +4 + }, + ); +}; let indent = 0; function doHooks() { var libnative_addr = Module.findBaseAddress("libvdp.so"); // const prefixes = ["Send_Pkt*", "P2P*", "*RcvTh*", "parse_*"]; // "XQP2P*", - const prefixes = ["parse_*", "pack_*", "Send_Pkt*"]; // "XQP2P*", + // const prefixes = ["parse_*", "pack_*", "Send_Pkt*", "create_*"]; + const prefixes = ["create_*"]; const spam = ["XQP2P_Check_Buffer", "P2P_ChannelBufferCheck"]; - prefixes - .map((prefix) => DebugSymbol.findFunctionsMatching(prefix)) - .flat() - .map(DebugSymbol.fromAddress) - .filter((dbg) => !spam.includes(dbg.name)) - .map((dbg) => { - Interceptor.attach(dbg.address, { - onEnter: (args) => { - indent = indent + 1; - console.log(" ".repeat(indent) + dbg.name); - }, - onLeave: (retval) => { - indent = indent - 1; - }, - }); - console.log(`Hooked ${dbg.name}`); - }); - if (libnative_addr) { hook___android_log_print(); + hook_create_P2pRdy; + const replaced = replaceFunctions(); + console.log(replaced); + prefixes + .map((prefix) => DebugSymbol.findFunctionsMatching(prefix)) + .flat() + .map(DebugSymbol.fromAddress) + .filter((dbg) => !spam.includes(dbg.name)) + .map((dbg) => { + Interceptor.attach(dbg.address, { + onEnter: (args) => { + indent = indent + 1; + let flag = replaced.includes(dbg.name) ? "[REPLACED] " : ""; + console.log(" ".repeat(indent) + flag + dbg.name); + }, + onLeave: (retval) => { + indent = indent - 1; + }, + }); + console.log(`Hooked ${dbg.name}`); + }); + // hook_p2p_read(); // hook_pack_P2pId(); // hook_pack_ClntPkt(); diff --git a/func_replacements.js b/func_replacements.js new file mode 100644 index 0000000..a805c3d --- /dev/null +++ b/func_replacements.js @@ -0,0 +1,43 @@ +const create_LanSearch = (buf) => { + // buf is u16* + buf.writeU16(0x30f1); + buf.add(2).writeU16(0x0); + return 4; // 2 x u16 entries = 4bytes +}; + +const create_P2pAliveAck = (buf) => { + // buf is u16* + buf.writeU16(0xe1f1); + buf.add(2).writeU16(0x0); + return 4; // 2 x u16 entries = 4bytes +}; +const create_P2pAlive = (buf) => { + // buf is u16* + buf.writeU16(0xe0f1); + buf.add(2).writeU16(0x0); + return 4; // 2 x u16 entries = 4bytes +}; + +export const replace_func = (stub, ret, args) => { + const name_in_elf = stub.name; + const symbol_addr = DebugSymbol.fromName(name_in_elf).address; + if (symbol_addr == 0) { + console.error(`Could not find ${name_in_elf}`); + return; + } + console.log( + `Replacing ${name_in_elf}, signature "${ret} ${name_in_elf}(${args})"`, + ); + Interceptor.replace(symbol_addr, new NativeCallback(stub, ret, args)); +}; + +export const replaceFunctions = () => { + const replacements = [ + [create_P2pAlive, "uchar", ["pointer"]], + [create_P2pAliveAck, "uchar", ["pointer"]], + [create_LanSearch, "uchar", ["pointer"]], + ]; + + replacements.forEach((x) => replace_func(...x)); + return replacements.map((x) => x[0].name); +};