From 6e2984682b30b86c5604f818fefbd2d00e8a7f9d Mon Sep 17 00:00:00 2001 From: yincong Date: Tue, 23 Dec 2025 18:33:27 +0800 Subject: [PATCH] update --- .gitignore | 3 +- function.md | 172 +++++++++++++++++++++++++++++++++++++-- go_al/go.mod | 3 + idapro/analysis_x.py | 2 +- idapro/trigger_send.py | 9 +- idapro/trigger_task.py | 3 - idapro/update_sendMsg.py | 69 ++++++++++++++++ 7 files changed, 243 insertions(+), 18 deletions(-) create mode 100644 go_al/go.mod delete mode 100644 idapro/trigger_task.py create mode 100644 idapro/update_sendMsg.py diff --git a/.gitignore b/.gitignore index a5e0706..2177bd8 100644 --- a/.gitignore +++ b/.gitignore @@ -4,4 +4,5 @@ __handlers__ .DS_Store diaphora_batch* data -.venv \ No newline at end of file +.venv +*.go \ No newline at end of file diff --git a/function.md b/function.md index baf1771..b730d32 100644 --- a/function.md +++ b/function.md @@ -1,9 +1,4 @@ -text_message_handler_10227A9C4 text_message_handler.cc ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEEaSERKS5_ -sub_1033EF820 Req2BufImpl -研究sub_104527E84 这个函数 /Users/bkdevops/.wconan2/mmnet/dce0e807_1764759442/mars-private/mars/protobuf/google/protobuf/wire_format_lite.cc -protoWriteAllValue_10344FFEC 写protobuf的函数 -compress_103413610 compress函数进行压缩 - +STNManager__MMStartTask下面的sub_10444A99C 函数 taskid 4位 cmdId 4位 @@ -11,9 +6,6 @@ cmdId 4位 00030001 固定 cgi 字符串指针 -后面都是固定的,按照这个来 -sub_10481C304 taskId生成函数 - ```azure debug697:0000000175ED6600 DCB 0xE2 debug697:0000000175ED6601 DCB 0 @@ -454,3 +446,165 @@ channel_select:3, limit_flow:true, channel_name:default-longlink ``` + + +[x0,#0x60]赋值给x0 +[x0,#0x28]赋值给x0 +X0=X0+#0xB8就是消息的指针 + +第二个指针 7d88fbfc0 + 第一个指针 7d3f60a80 + 第一个指针 107f968a0 函数 + 第二个指针 7d74ae4a0 + 第一个指针 7d3fd9a20 是接收者id + 第三个指针 7d3fdb500 消息内容,如果长的话是消息的指针 + 紧接着4位是1 + 紧接着4位是时间戳 + 第5个指针是html标签指针:1 + 接着8位是数字 可能是消息id? + +后面就有时一个相同的指针,也是消息的一些内容,但是和上面的指针不是同一个 + +``` +7D3F60A80 DCB 0xA0 +debug5019:00000007D3F60A81 DCB 0x68 ; h +debug5019:00000007D3F60A82 DCB 0xF9 +debug5019:00000007D3F60A83 DCB 7 +debug5019:00000007D3F60A84 DCB 1 +debug5019:00000007D3F60A85 DCB 0 +debug5019:00000007D3F60A86 DCB 0 +debug5019:00000007D3F60A87 DCB 0 +debug5019:00000007D3F60A88 DCB 0xA0 +debug5019:00000007D3F60A89 DCB 0xE4 +debug5019:00000007D3F60A8A DCB 0x4A ; J +debug5019:00000007D3F60A8B DCB 0xD7 +debug5019:00000007D3F60A8C DCB 7 +debug5019:00000007D3F60A8D DCB 0 +debug5019:00000007D3F60A8E DCB 0 +debug5019:00000007D3F60A8F DCB 0 +debug5019:00000007D3F60A90 DCB 0 +debug5019:00000007D3F60A91 DCB 0xB5 +debug5019:00000007D3F60A92 DCB 0xFD +debug5019:00000007D3F60A93 DCB 0xD3 +debug5019:00000007D3F60A94 DCB 7 +debug5019:00000007D3F60A95 DCB 0 +debug5019:00000007D3F60A96 DCB 0 +debug5019:00000007D3F60A97 DCB 0 +debug5019:00000007D3F60A98 DCB 1 +debug5019:00000007D3F60A99 DCB 0 +debug5019:00000007D3F60A9A DCB 0 +debug5019:00000007D3F60A9B DCB 0 +debug5019:00000007D3F60A9C DCB 0xB8 +debug5019:00000007D3F60A9D DCB 0x2B ; + +debug5019:00000007D3F60A9E DCB 0x4A ; J +debug5019:00000007D3F60A9F DCB 0x69 ; i +debug5019:00000007D3F60AA0 DCB 0x20 +debug5019:00000007D3F60AA1 DCB 0xB5 +debug5019:00000007D3F60AA2 DCB 0xFD +debug5019:00000007D3F60AA3 DCB 0xD3 +debug5019:00000007D3F60AA4 DCB 7 +debug5019:00000007D3F60AA5 DCB 0 +debug5019:00000007D3F60AA6 DCB 0 +debug5019:00000007D3F60AA7 DCB 0 +debug5019:00000007D3F60AA8 DCB 0x30 ; 0 +debug5019:00000007D3F60AA9 DCB 0x35 ; 5 +debug5019:00000007D3F60AAA DCB 0xAE +debug5019:00000007D3F60AAB DCB 0x8C +debug5019:00000007D3F60AAC DCB 0 +debug5019:00000007D3F60AAD DCB 0 +debug5019:00000007D3F60AAE DCB 0 +debug5019:00000007D3F60AAF DCB 0 +debug5019:00000007D3F60AB0 DCB 0 +debug5019:00000007D3F60AB1 DCB 0 +debug5019:00000007D3F60AB2 DCB 0 +debug5019:00000007D3F60AB3 DCB 0 +debug5019:00000007D3F60AB4 DCB 0x3F ; ? +debug5019:00000007D3F60AB5 DCB 0 +debug5019:00000007D3F60AB6 DCB 0 +debug5019:00000007D3F60AB7 DCB 0 +debug5019:00000007D3F60AB8 DCB 0 +debug5019:00000007D3F60AB9 DCB 0 +debug5019:00000007D3F60ABA DCB 0 +debug5019:00000007D3F60ABB DCB 0 +debug5019:00000007D3F60ABC DCB 0 +debug5019:00000007D3F60ABD DCB 0 +debug5019:00000007D3F60ABE DCB 0 +debug5019:00000007D3F60ABF DCB 0 +debug5019:00000007D3F60AC0 DCB 0xA0 +debug5019:00000007D3F60AC1 DCB 0x68 ; h +debug5019:00000007D3F60AC2 DCB 0xF9 +debug5019:00000007D3F60AC3 DCB 7 +debug5019:00000007D3F60AC4 DCB 1 +debug5019:00000007D3F60AC5 DCB 0 +debug5019:00000007D3F60AC6 DCB 0 +debug5019:00000007D3F60AC7 DCB 0 +debug5019:00000007D3F60AC8 DCB 0xC0 +debug5019:00000007D3F60AC9 DCB 0x6B ; k +debug5019:00000007D3F60ACA DCB 0x62 ; b +debug5019:00000007D3F60ACB DCB 0xD7 +debug5019:00000007D3F60ACC DCB 7 +debug5019:00000007D3F60ACD DCB 0 +debug5019:00000007D3F60ACE DCB 0 +debug5019:00000007D3F60ACF DCB 0 +debug5019:00000007D3F60AD0 DCB 0x20 +debug5019:00000007D3F60AD1 DCB 0xAC +debug5019:00000007D3F60AD2 DCB 0xFD +debug5019:00000007D3F60AD3 DCB 0xD3 +debug5019:00000007D3F60AD4 DCB 7 +debug5019:00000007D3F60AD5 DCB 0 +debug5019:00000007D3F60AD6 DCB 0 +debug5019:00000007D3F60AD7 DCB 0 +debug5019:00000007D3F60AD8 DCB 1 +debug5019:00000007D3F60AD9 DCB 0 +debug5019:00000007D3F60ADA DCB 0 +debug5019:00000007D3F60ADB DCB 0 +debug5019:00000007D3F60ADC DCB 0xB8 +debug5019:00000007D3F60ADD DCB 0x2B ; + +debug5019:00000007D3F60ADE DCB 0x4A ; J +debug5019:00000007D3F60ADF DCB 0x69 ; i +debug5019:00000007D3F60AE0 DCB 0 +debug5019:00000007D3F60AE1 DCB 0xBE +debug5019:00000007D3F60AE2 DCB 0xFD +debug5019:00000007D3F60AE3 DCB 0xD3 +debug5019:00000007D3F60AE4 DCB 7 +debug5019:00000007D3F60AE5 DCB 0 +debug5019:00000007D3F60AE6 DCB 0 +debug5019:00000007D3F60AE7 DCB 0 +debug5019:00000007D3F60AE8 DCB 0x30 ; 0 +debug5019:00000007D3F60AE9 DCB 0x35 ; 5 +debug5019:00000007D3F60AEA DCB 0xAE +debug5019:00000007D3F60AEB DCB 0x8C +debug5019:00000007D3F60AEC DCB 0 +debug5019:00000007D3F60AED DCB 0 +debug5019:00000007D3F60AEE DCB 0 +debug5019:00000007D3F60AEF DCB 0 +debug5019:00000007D3F60AF0 DCB 0 +debug5019:00000007D3F60AF1 DCB 0 +debug5019:00000007D3F60AF2 DCB 0 +debug5019:00000007D3F60AF3 DCB 0 +debug5019:00000007D3F60AF4 DCB 0x3F ; ? +debug5019:00000007D3F60AF5 DCB 0 +debug5019:00000007D3F60AF6 DCB 0 +debug5019:00000007D3F60AF7 DCB 0 +debug5019:00000007D3F60AF8 DCB 0 +debug5019:00000007D3F60AF9 DCB 0 +debug5019:00000007D3F60AFA DCB 0 +debug5019:00000007D3F60AFB DCB 0 +debug5019:00000007D3F60AFC DCB 0 +debug5019:00000007D3F60AFD DCB 0 +debug5019:00000007D3F60AFE DCB 0 +debug5019:00000007D3F60AFF DCB 0 +debug5019:00000007D3F60B00 DCB 0x43 ; C +debug5019:00000007D3F60B01 DCB 0x55 ; U +debug5019:00000007D3F60B02 DCB 0xCB +debug5019:00000007D3F60B03 DCB 0xA4 +debug5019:00000007D3F60B04 DCB 0x55 ; U +debug5019:00000007D3F60B05 DCB 0x7C ; | +debug5019:00000007D3F60B06 DCB 0xE4 +debug5019:00000007D3F60B07 DCB 0x96 +debug5019:00000007D3F60B08 DCB 0xF0 +debug5019:00000007D3F60B09 DCB 0x90 +debug5019:00000007D3F60B0A DCB 0x52 ; R + +``` + diff --git a/go_al/go.mod b/go_al/go.mod new file mode 100644 index 0000000..2e465a2 --- /dev/null +++ b/go_al/go.mod @@ -0,0 +1,3 @@ +module github.com/yincongcyincong/weixin-macos/go_al + +go 1.25.0 diff --git a/idapro/analysis_x.py b/idapro/analysis_x.py index d7bb07f..0f2187d 100644 --- a/idapro/analysis_x.py +++ b/idapro/analysis_x.py @@ -193,4 +193,4 @@ analyze_all_args() example_usage() """ -print_register_struct("X1", 128, 4) \ No newline at end of file +print_register_struct("X0", 128, 4) \ No newline at end of file diff --git a/idapro/trigger_send.py b/idapro/trigger_send.py index ac5b63a..3b72146 100644 --- a/idapro/trigger_send.py +++ b/idapro/trigger_send.py @@ -2,12 +2,11 @@ import ida_idd import ida_bytes # 改task id, 改 cgi,改第一个指针即可 - payload = ( - b"\xFF\x00\x00\x00\x0A\x02\x00\x00" # 0x00 // task id / cmd id 175ED6600 + b"\x00\x00\x00\x02\x0A\x02\x00\x00" # 0x00 // task id / cmd id 175ED6600 b"\x00\x00\x00\x00\x00\x00\x00\x00" # 0x08 b"\x03\x00\x00\x00\x10\x00\x00\x00" # 0x10 - b"\x70\xa9\x07\xb8\x0c\x00\x00\x00" # 0x18 // cgi + b"\xf0\x02\x38\x38\x0d\x00\x00\x00" # 0x18 // cgi b"\x20\x00\x00\x00\x00\x00\x00\x00" # 0x20 b"\x30\x00\x00\x00\x00\x00\x00\x80" # 0x28 b"\x00\x01\x01\x01\x00\xAA\xAA\xAA" # 0x30 @@ -59,8 +58,10 @@ payload = ( ) ida_bytes.patch_bytes(0x175ED6600, payload) +my_func = ida_idd.Appcall.proto(0x10444A99C, "long long __fastcall sub_10444A99C(long long *a1, long long a2);") + try: - Appcall.sub_10444B75C(0x8776FE800, 0x175ED6600) + my_func(0x7D72BD400, 0x175ED6600) print("Executed with manually set X0.") except Exception as e: print(f"Error: {e}") \ No newline at end of file diff --git a/idapro/trigger_task.py b/idapro/trigger_task.py deleted file mode 100644 index 9f4decb..0000000 --- a/idapro/trigger_task.py +++ /dev/null @@ -1,3 +0,0 @@ - - -Appcall.netimplement_StartTask_1033EEC84(0xC374FC818, 0xC3813F200) \ No newline at end of file diff --git a/idapro/update_sendMsg.py b/idapro/update_sendMsg.py new file mode 100644 index 0000000..7ee849a --- /dev/null +++ b/idapro/update_sendMsg.py @@ -0,0 +1,69 @@ +import time + +import ida_bytes +import idc + + +def get_varint_timestamp_bytes(): + """ + 获取当前时间戳并编码为 Protobuf Varint 字节流 (bytes类型) + """ + ts = int(time.time()) + encoded_bytes = bytearray() + temp_ts = ts & 0xFFFFFFFF # 32位无符号整数 + while True: + byte = temp_ts & 0x7F + temp_ts >>= 7 + if temp_ts: + encoded_bytes.append(byte | 0x80) + else: + encoded_bytes.append(byte) + break + return bytes(encoded_bytes) + + +def run_patch_script(): + # --- 1. 设置目标空内存地址 --- + x1_addr = idc.get_reg_value("X1") + print(f"[*] 原始 X1 指向地址: {hex(x1_addr)}") + + # --- 2. 构造 Payload --- + # 前缀部分 + payload = ( + b"\x08\x01\x12\x5E\x0A\x15\x0A\x13" # 0x00 第一个字段头部 + 接收人id头部 + b"\x77\x78\x69\x64\x5F\x37\x77\x64" # 0x08 (接收人id wxid_xxxx) + b"\x31\x65\x63\x65\x39\x39\x66\x37" # 0x10 (接收人id wxid_xxxx) + b"\x69\x32\x31\x12\x03\x38\x38\x38" # 0x18 (接收人id wxid_xxxx + 第二个字段头部 + 字符串长度+字符串内容) + b"\x18\x01\x20" # 0x20 (第三个字段时间戳头部+时间戳) + ) + + # 动态插入时间戳 (bytes + bytes) + payload += get_varint_timestamp_bytes() + + # 后缀部分 + payload += ( + b"\x28\xD1\xF7\xA6\xE6\x0c" # (某个id的头部和值) + b"\x32\x32\x3C" # 0x28 (第四个字段时间戳头部) + b"\x6D\x73\x67\x73\x6F\x73\x75\x72" # 0x30 (msgsour) + b"\x63\x65\x3E\x3C\x61\x6C\x6E\x6F" # 0x38 (ce>1) + b"\x3C\x2F\x66\x72\x3E\x3C\x2F\x61" # 0x48 (.) + ) + + # --- 4. 写入内存 --- + # 使用 ida_bytes.patch_bytes 写入完整 payload + ida_bytes.patch_bytes(x1_addr, payload) + + # --- 5. 设置寄存器 --- + # 将 X1 指向我们刚刚填充好的内存地址 + if idc.set_reg_value(x1_addr, "X1"): + print(f"[*] 成功: 数据已写入 {hex(x1_addr)}") + else: + print("[-] 错误: 无法设置 X1 寄存器,请检查寄存器名称。") + + +# 启动脚本 +run_patch_script()