on complete

This commit is contained in:
yincong
2026-01-12 18:12:06 +08:00
parent 5fa73bf622
commit 902d4bae82
3 changed files with 198 additions and 385 deletions
+6 -1
View File
@@ -1 +1,6 @@
触发 STNManager__MMStartTask
触发 STNManager__MMStartTask
Req2Buf 构造消息的buffer入口,其中X4是消息内容,输出的是压缩后的protobuf
Pack是打包函数,消息内容 cgi等信息打包进入
InitClientChannel DoHandShakeLoop 是建立mmtls链接最重要的函数
DoSendEarlyAppData 是消息体函数,可以看到你发的消息体
__RunReadWrite 这条日志打印后的 “task socket send sock:%_, %_ http len:%" 一个BL X8里面有send命令进行发送
+62
View File
@@ -0,0 +1,62 @@
var runReadX0 = ptr(0)
var originCgiPtr = ptr(0)
function patchRunReadWrite() {
Interceptor.attach(runReadWriteAddr, {
onEnter: function (args) {
try {
if (this.context.x5.isNull() || this.context.x5.compare(baseAddr) <= 0) {
return
}
const x5 = this.context.x5;
const cTaskId = x5.add(0x308).readU32();
if (cTaskId !== taskIdGlobal) {
return
}
console.log("[+] enter runReadWriteAddr: " + runReadWriteAddr)
const domainAddr = x5.add(0xd8);
const domainBytes = [
0x73, 0x7A, 0x73, 0x68, 0x6F, 0x72, 0x74, 0x2E, // szshort.
0x77, 0x65, 0x69, 0x78, 0x69, 0x6E, 0x2E, 0x71, // weixin.q
0x71, 0x2E, 0x63, 0x6F, 0x6D // q.com
];
domainAddr.writeByteArray(domainBytes);
domainAddr.add(domainBytes.length).writeU8(0);
domainAddr.add(23).writeU8(0x15);
runReadX0 = this.context.x0;
originCgiPtr = runReadX0.add(0x1018).readPointer();
runReadX0.add(0x1018).writePointer(cgiAddr);
runReadX0.add(0x1020).writeU64(0x22);
console.log("[+] enter runReadWriteAddr finished: " + domainAddr.readUtf8String())
} catch (e) {
console.log("[-] Memory access error at onEnter: " + e);
}
}
})
Interceptor.attach(runReadWriteAddr1, {
onEnter: function (args) {
try {
if (this.context.x20.isNull() || this.context.x20.compare(baseAddr) <= 0) {
return
}
const cTaskId = this.context.x20.add(0x308).readU32();
if (cTaskId !== taskIdGlobal) {
return
}
runReadX0.add(0x1018).writePointer(originCgiPtr);
console.log("[+] leave runReadWriteAddr finished: " + runReadWriteAddr)
} catch (e) {
console.log("[-] Memory access error at onLeave: " + e);
}
}
})
runReadWriteAddr1
}
setImmediate(patchRunReadWrite)
+130 -384
View File
@@ -20,6 +20,8 @@ var buf2RespAddr = baseAddr.add(0x347BD44);
var patchProtobufFunc1 = baseAddr.add(0x2275BB8)
var patchProtobufFunc2 = baseAddr.add(0x2275BD8);
var protobufDeleteAddr = baseAddr.add(0x2275C14);
var CndOnCompleteAddr = baseAddr.add(0x34154E0);
var runReadWriteAddr = baseAddr.add(0x450F518)
var runReadWriteAddr1 = baseAddr.add(0x450F51C);
@@ -42,9 +44,13 @@ var protoX1PayloadAddr = ptr(0);
// 消息的taskId
var taskIdGlobal = 0x20000090 // 最好比较大,不和原始的微信消息重复
var receiverGlobal = "wxid_"
var receiverGlobal = "wxid_7wd1ece99f7i21"
var senderGlobal = "wxid_ldftuhe36izg19"
var contentGlobal = "";
var lastSendTime = 0;
var globalImageCdnKey = "";
var globalAesKey1 = "";
var globalAesKey2 = "";
// 打印消息的地址,便于查询问题
function printAddr() {
@@ -130,35 +136,35 @@ function patchHex(addr, hexStr) {
}
function patchProtoBuf() {
Memory.patchCode(patchProtobufFunc1, 4, code => {
const cw = new Arm64Writer(code, {pc: patchProtobufFunc1});
cw.putNop();
cw.flush();
});
// function patchProtoBuf() {
// Memory.patchCode(patchProtobufFunc1, 4, code => {
// const cw = new Arm64Writer(code, {pc: patchProtobufFunc1});
// cw.putNop();
// cw.flush();
// });
//
// console.log("[+] Patching BL to NOP at " + patchProtobufFunc1 + " completed.");
//
// Memory.patchCode(patchProtobufFunc2, 4, code => {
// const cw = new Arm64Writer(code, {pc: patchProtobufFunc2});
// cw.putNop();
// cw.flush();
// });
//
// console.log("[+] Patching BL to NOP at " + patchProtobufFunc2 + " completed.");
//
// Memory.patchCode(protobufDeleteAddr, 4, code => {
// const cw = new Arm64Writer(code, {pc: protobufDeleteAddr});
// cw.putNop();
// cw.flush();
// });
//
// console.log("[+] Patching BL DELETE to NOP at " + protobufDeleteAddr + " completed.");
// }
//
// setImmediate(patchProtoBuf);
console.log("[+] Patching BL to NOP at " + patchProtobufFunc1 + " completed.");
Memory.patchCode(patchProtobufFunc2, 4, code => {
const cw = new Arm64Writer(code, {pc: patchProtobufFunc2});
cw.putNop();
cw.flush();
});
console.log("[+] Patching BL to NOP at " + patchProtobufFunc2 + " completed.");
Memory.patchCode(protobufDeleteAddr, 4, code => {
const cw = new Arm64Writer(code, {pc: protobufDeleteAddr});
cw.putNop();
cw.flush();
});
console.log("[+] Patching BL DELETE to NOP at " + protobufDeleteAddr + " completed.");
}
setImmediate(patchProtoBuf);
function manualTrigger(taskId, receiver, content) {
function manualTrigger(taskId, sender, receiver, content) {
console.log("[+] Manual Trigger Started...");
if (!taskId || !receiver || !content) {
console.error("[!] taskId or Receiver or Content is empty!");
@@ -176,6 +182,7 @@ function manualTrigger(taskId, receiver, content) {
lastSendTime = timestamp
taskIdGlobal = taskId;
receiverGlobal = receiver;
senderGlobal = sender;
contentGlobal = content;
messageAddr.add(0x08).writeU32(taskIdGlobal);
@@ -188,7 +195,7 @@ function manualTrigger(taskId, receiver, content) {
0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, // 0x08
0x03, 0x00, 0x00, 0x00, 0x10, 0x00, 0x00, 0x00, // 0x10
0x40, 0xec, 0x0e, 0x12, 0x01, 0x00, 0x00, 0x00, // 0x18
0x20, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, // 0x20
0x22, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, // 0x20 cgi的长度
0x30, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x80, // 0x28
0x00, 0x01, 0x01, 0x01, 0x00, 0xAA, 0xAA, 0xAA, // 0x30
0x00, 0x00, 0x00, 0x00, 0x03, 0x00, 0x00, 0x00, // 0x38
@@ -384,311 +391,94 @@ function attachProto() {
// return;
// }
// const type = [0x0A, 0x3F, 0x0A, 0x01, 0x00, 0x10]
// const msgId = [0xc6, 0xbc, 0x90, 0xb9, 0x08]
// const cpHeader = [0x1A, 0x10]
// const cp = [0x6D, 0x33, 0x30, 0x63, 0x34, 0x36, 0x37, 0x34, 0x66, 0x35, 0x61, 0x30, 0x62, 0x39, 0x64, 0x30] // m30c4674f5a0b9d0
// const randomId = [0x20, 0xAF, 0xAC, 0x90, 0x93, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0x01]
// const sysHeader = [0x2A, 0x15]
// // UnifiedPCMac 26 arm64
// const sys = [0x55, 0x6E, 0x69, 0x66, 0x69, 0x65, 0x64, 0x50, 0x43, 0x4D, 0x61, 0x63, 0x20, 0x32, 0x36, 0x20, 0x61, 0x72, 0x6D, 0x36, 0x34]
// const msgIdHeader = [0x30, 0x73, 0x12, 0x2E, 0x0A, 0x2C]
// // 45872025384@chatroom_176787000_60_xwechat_1 只需要改这个时间戳就能重复发送
// const receiverMsgId = [0x34, 0x35, 0x38, 0x37, 0x32, 0x30, 0x32, 0x35, 0x33, 0x38, 0x34,
// 0x40, 0x63, 0x68, 0x61, 0x74, 0x72, 0x6F, 0x6F, 0x6D, 0x5F, 0x31, 0x37, 0x36, 0x37, 0x38, 0x37,
// 0x30, 0x30, 0x30, 0x30, 0x5F, 0x36, 0x30, 0x5F, 0x78, 0x77, 0x65, 0x63, 0x68, 0x61, 0x74, 0x5F, 0x31,
// ]
// const senderHeader = [0x1A, 0x15, 0x0A, 0x13];
// // wxid_xxxx 或者 chatroom
// const sender = [0x77, 0x78, 0x69, 0x64, 0x5F, 0x6C, 0x64, 0x66, 0x74, 0x75, 0x68, 0x65, 0x33, 0x36, 0x69, 0x7A, 0x67, 0x31, 0x39];
// const receiverHeader = [0x22, 0x16, 0x0A, 0x14]
// // wxid_xxxx
// const receiver = [0x34, 0x35, 0x38, 0x37, 0x32, 0x30, 0x32, 0x35, 0x33, 0x38, 0x34, 0x40, 0x63, 0x68, 0x61, 0x74, 0x72, 0x6F, 0x6F, 0x6D]
// const randomId1 = [0x28, 0xF4, 0x0B]
// const type1 = [0x30, 0x00]
// const randomId2 = [0x38, 0xF4, 0x0B]
// const randomId3 = [0x42, 0x04, 0x08, 0x00, 0x12, 0x00]
// const randomId4 = [0x48, 0x03]
// const htmlHeader = [0x52, 0x83, 0x01];
// // <msgsource>
// // <img_file_name>cc357085-cbff-4968-b9fe-b4e4eab5b0ca.png</img_file_name>
// // <alnode>
// // <fr>1</fr>
// // <cf>3</cf>
// // </alnode>
// // </msgsource>
// const html = [0x3C, 0x6D, 0x73, 0x67, 0x73, 0x6F, 0x75, 0x72, 0x63, 0x65, 0x3E, 0x3C, 0x69,
// 0x6D, 0x67, 0x5F, 0x66, 0x69, 0x6C, 0x65, 0x5F, // 0xC0
// 0x6E, 0x61, 0x6D, 0x65, 0x3E, 0x63, 0x63, 0x33, // 0xC8
// 0x35, 0x37, 0x30, 0x38, 0x35, 0x2D, 0x63, 0x62, // 0xD0
// 0x66, 0x66, 0x2D, 0x34, 0x39, 0x36, 0x38, 0x2D, // 0xD8
// 0x62, 0x39, 0x66, 0x65, 0x2D, 0x62, 0x34, 0x65, // 0xE0
// 0x34, 0x65, 0x61, 0x62, 0x35, 0x62, 0x30, 0x63, // 0xE8
// 0x61, 0x2E, 0x70, 0x6E, 0x67, 0x3C, 0x2F, 0x69, // 0xF0
// 0x6D, 0x67, 0x5F, 0x66, 0x69, 0x6C, 0x65, 0x5F, // 0xF8
// 0x6E, 0x61, 0x6D, 0x65, 0x3E, 0x3C, 0x61, 0x6C, // 0x100
// 0x6E, 0x6F, 0x64, 0x65, 0x3E, 0x3C, 0x66, 0x72, // 0x108
// 0x3E, 0x31, 0x3C, 0x2F, 0x66, 0x72, 0x3E, 0x3C, // 0x110
// 0x63, 0x66, 0x3E, 0x33, 0x3C, 0x2F, 0x63, 0x66, // 0x118
// 0x3E, 0x3C, 0x2F, 0x61, 0x6C, 0x6E, 0x6F, 0x64, // 0x120
// 0x65, 0x3E, 0x3C, 0x2F, 0x6D, 0x73, 0x67, 0x73, // 0x128
// 0x6F, 0x75, 0x72, 0x63, 0x65, 0x3E,
// ]
//
// const cdnHeader = [0x58, 0x01, 0x60, 0x02, 0x68, 0x05, 0x7A, 0xB2, 0x01]
// // 3057 开头的cdn key
// const cdn = [0x33, // 0x138
// 0x30, 0x35, 0x37, 0x30, 0x32, 0x30, 0x31, 0x30, // 0x140
// 0x30, 0x30, 0x34, 0x34, 0x62, 0x33, 0x30, 0x34, // 0x148
// 0x39, 0x30, 0x32, 0x30, 0x31, 0x30, 0x30, 0x30, // 0x150
// 0x32, 0x30, 0x34, 0x64, 0x30, 0x61, 0x37, 0x30, // 0x158
// 0x39, 0x35, 0x64, 0x30, 0x32, 0x30, 0x33, 0x32, // 0x160
// 0x66, 0x35, 0x61, 0x34, 0x35, 0x30, 0x32, 0x30, // 0x168
// 0x34, 0x65, 0x61, 0x38, 0x65, 0x30, 0x65, 0x37, // 0x170
// 0x39, 0x30, 0x32, 0x30, 0x34, 0x36, 0x39, 0x35, // 0x178
// 0x66, 0x38, 0x65, 0x33, 0x31, 0x30, 0x34, 0x32, // 0x180
// 0x34, 0x33, 0x37, 0x33, 0x39, 0x36, 0x35, 0x33, // 0x188
// 0x31, 0x33, 0x37, 0x33, 0x31, 0x33, 0x34, 0x33, // 0x190
// 0x35, 0x32, 0x64, 0x33, 0x34, 0x33, 0x34, 0x33, // 0x198
// 0x35, 0x33, 0x35, 0x32, 0x64, 0x33, 0x34, 0x33, // 0x1A0
// 0x33, 0x36, 0x33, 0x33, 0x32, 0x32, 0x64, 0x36, // 0x1A8
// 0x31, 0x33, 0x35, 0x33, 0x32, 0x33, 0x31, 0x32, // 0x1B0
// 0x64, 0x33, 0x39, 0x33, 0x33, 0x33, 0x32, 0x33, // 0x1B8
// 0x32, 0x36, 0x34, 0x36, 0x34, 0x36, 0x32, 0x36, // 0x1C0
// 0x31, 0x33, 0x37, 0x36, 0x36, 0x33, 0x32, 0x36, // 0x1C8
// 0x36, 0x30, 0x32, 0x30, 0x34, 0x30, 0x35, 0x32, // 0x1D0
// 0x34, 0x33, 0x38, 0x30, 0x31, 0x30, 0x32, 0x30, // 0x1D8
// 0x31, 0x30, 0x30, 0x30, 0x34, 0x30, 0x35, 0x30, // 0x1E0
// 0x30, 0x34, 0x63, 0x34, 0x65, 0x36, 0x31, 0x30, // 0x1E8
// 0x30,
// ];
//
// const cdn2Header = [0x82, 0x01, 0xB2, 0x01]
// const cdn2 = [
// 0x33, 0x30, 0x35, // 0x1F0
// 0x37, 0x30, 0x32, 0x30, 0x31, 0x30, 0x30, 0x30, // 0x1F8
// 0x34, 0x34, 0x62, 0x33, 0x30, 0x34, 0x39, 0x30, // 0x200
// 0x32, 0x30, 0x31, 0x30, 0x30, 0x30, 0x32, 0x30, // 0x208
// 0x34, 0x64, 0x30, 0x61, 0x37, 0x30, 0x39, 0x35, // 0x210
// 0x64, 0x30, 0x32, 0x30, 0x33, 0x32, 0x66, 0x35, // 0x218
// 0x61, 0x34, 0x35, 0x30, 0x32, 0x30, 0x34, 0x65, // 0x220
// 0x61, 0x38, 0x65, 0x30, 0x65, 0x37, 0x39, 0x30, // 0x228
// 0x32, 0x30, 0x34, 0x36, 0x39, 0x35, 0x66, 0x38, // 0x230
// 0x65, 0x33, 0x31, 0x30, 0x34, 0x32, 0x34, 0x33, // 0x238
// 0x37, 0x33, 0x39, 0x36, 0x35, 0x33, 0x31, 0x33, // 0x240
// 0x37, 0x33, 0x31, 0x33, 0x34, 0x33, 0x35, 0x32, // 0x248
// 0x64, 0x33, 0x34, 0x33, 0x34, 0x33, 0x35, 0x33, // 0x250
// 0x35, 0x32, 0x64, 0x33, 0x34, 0x33, 0x33, 0x36, // 0x258
// 0x33, 0x33, 0x32, 0x32, 0x64, 0x36, 0x31, 0x33, // 0x260
// 0x35, 0x33, 0x32, 0x33, 0x31, 0x32, 0x64, 0x33, // 0x268
// 0x39, 0x33, 0x33, 0x33, 0x32, 0x33, 0x32, 0x36, // 0x270
// 0x34, 0x36, 0x34, 0x36, 0x32, 0x36, 0x31, 0x33, // 0x278
// 0x37, 0x36, 0x36, 0x33, 0x32, 0x36, 0x36, 0x30, // 0x280
// 0x32, 0x30, 0x34, 0x30, 0x35, 0x32, 0x34, 0x33, // 0x288
// 0x38, 0x30, 0x31, 0x30, 0x32, 0x30, 0x31, 0x30, // 0x290
// 0x30, 0x30, 0x34, 0x30, 0x35, 0x30, 0x30, 0x34, // 0x298
// 0x63, 0x34, 0x65, 0x36, 0x31, 0x30, 0x30,
// ]
//
// const aesKeyHeader = [0x8A, 0x01, 0x20]
// const aesKey = [
// 0x38, 0x31, 0x66, 0x66, 0x37, 0x65, // 0x2A8
// 0x61, 0x37, 0x36, 0x37, 0x31, 0x34, 0x66, 0x33, // 0x2B0
// 0x30, 0x66, 0x36, 0x63, 0x32, 0x63, 0x33, 0x64, // 0x2B8
// 0x37, 0x37, 0x30, 0x64, 0x39, 0x38, 0x63, 0x35, // 0x2C0
// 0x64, 0x65,
// ]
//
// const randomId5 = [0x90, 0x01, 0x01, 0x98, 0x01, 0xFF, // 0x2C8
// 0x13, 0xA0, 0x01, 0xFF, 0x13]
//
// const cdn3Header = [0xAA, 0x01, 0xB2, 0x01]
// const cdn3 = [
// 0x33, 0x30, 0x35, 0x37, 0x30, 0x32, 0x30, // 0x2D8
// 0x31, 0x30, 0x30, 0x30, 0x34, 0x34, 0x62, 0x33, // 0x2E0
// 0x30, 0x34, 0x39, 0x30, 0x32, 0x30, 0x31, 0x30, // 0x2E8
// 0x30, 0x30, 0x32, 0x30, 0x34, 0x64, 0x30, 0x61, // 0x2F0
// 0x37, 0x30, 0x39, 0x35, 0x64, 0x30, 0x32, 0x30, // 0x2F8
// 0x33, 0x32, 0x66, 0x35, 0x61, 0x34, 0x35, 0x30, // 0x300
// 0x32, 0x30, 0x34, 0x65, 0x61, 0x38, 0x65, 0x30, // 0x308
// 0x65, 0x37, 0x39, 0x30, 0x32, 0x30, 0x34, 0x36, // 0x310
// 0x39, 0x35, 0x66, 0x38, 0x65, 0x33, 0x31, 0x30, // 0x318
// 0x34, 0x32, 0x34, 0x33, 0x37, 0x33, 0x39, 0x36, // 0x320
// 0x35, 0x33, 0x31, 0x33, 0x37, 0x33, 0x31, 0x33, // 0x328
// 0x34, 0x33, 0x35, 0x32, 0x64, 0x33, 0x34, 0x33, // 0x330
// 0x34, 0x33, 0x35, 0x33, 0x35, 0x32, 0x64, 0x33, // 0x338
// 0x34, 0x33, 0x33, 0x36, 0x33, 0x33, 0x32, 0x32, // 0x340
// 0x64, 0x36, 0x31, 0x33, 0x35, 0x33, 0x32, 0x33, // 0x348
// 0x31, 0x32, 0x64, 0x33, 0x39, 0x33, 0x33, 0x33, // 0x350
// 0x32, 0x33, 0x32, 0x36, 0x34, 0x36, 0x34, 0x36, // 0x358
// 0x32, 0x36, 0x31, 0x33, 0x37, 0x36, 0x36, 0x33, // 0x360
// 0x32, 0x36, 0x36, 0x30, 0x32, 0x30, 0x34, 0x30, // 0x368
// 0x35, 0x32, 0x34, 0x33, 0x38, 0x30, 0x31, 0x30, // 0x370
// 0x32, 0x30, 0x31, 0x30, 0x30, 0x30, 0x34, 0x30, // 0x378
// 0x35, 0x30, 0x30, 0x34, 0x63, 0x34, 0x65, 0x36, // 0x380
// 0x31, 0x30, 0x30
// ]
//
// const randomId6 = [0xB0, 0x01, 0xF4, 0x0B]
// const randomId7 = [0xB8, 0x01, 0x68]
// const randomId8 = [0xC0, 0x01, 0x3A]
// const aesKey1Header = [0xCA, 0x01, 0x20]
// const aesKey1 = [
// 0x38, 0x31, 0x66, 0x66, 0x37, 0x65, 0x61, 0x37, // 0x398
// 0x36, 0x37, 0x31, 0x34, 0x66, 0x33, 0x30, 0x66, // 0x3A0
// 0x36, 0x63, 0x32, 0x63, 0x33, 0x64, 0x37, 0x37, // 0x3A8
// 0x30, 0x64, 0x39, 0x38, 0x63, 0x35, 0x64, 0x65, // 0x3B0
// ]
// const aesKey2Header = [0xDA, 0x01, 0x20]
// const aesKey2 = [
// 0x36, 0x37, 0x36, 0x33, 0x32, // 0x3B8
// 0x35, 0x32, 0x30, 0x35, 0x36, 0x38, 0x35, 0x37, // 0x3C0
// 0x61, 0x64, 0x66, 0x65, 0x35, 0x36, 0x36, 0x31, // 0x3C8
// 0x30, 0x35, 0x37, 0x30, 0x63, 0x61, 0x34, 0x32, // 0x3D0
// 0x38, 0x34, 0x63,
// ]
//
// const randomId9 = [0xE0, 0x01, 0xd9, 0xe7, 0xc7, 0xF3, 0x02]
//
//
// var left0 = [
// 0xF0, 0x01, 0x00, 0xA0, 0x02, 0x00, // 0x3E0
// 0xC8, 0x02, 0x00, 0x00 // 0x3E8
// ]
const type = [0x0A, 0x40, 0x0A, 0x01, 0x00]
const msgId = [0x10, 0xc6, 0xbc, 0x90, 0xb9, 0x08] // 时间戳
const cpHeader = [0x1A, 0x10]
// m30c4674f5a0b9d
const cp = [0x6D, 0x33, 0x30, 0x63, 0x34, 0x36, 0x37, 0x34, 0x66, 0x35, 0x61, 0x30, 0x62, 0x39, 0x64, 0x30]
const finalPayload = [
0x0A, 0x3F, 0x0A, 0x01, 0x00, 0x10, 0xC6, 0xBC,
0x90, 0xB9, 0x08, 0x1A, 0x10, 0x6D, 0x64, 0x34,
0x34, 0x36, 0x34, 0x65, 0x34, 0x37, 0x36, 0x34,
0x65, 0x61, 0x61, 0x62, 0x62, 0x20, 0xAF, 0xAC,
0x90, 0x93, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0x01,
0x2A, 0x15, 0x55, 0x6E, 0x69, 0x66, 0x69, 0x65,
0x64, 0x50, 0x43, 0x4D, 0x61, 0x63, 0x20, 0x32,
0x36, 0x20, 0x61, 0x72, 0x6D, 0x36, 0x34, 0x30,
0x70, 0x12, 0x2E, 0x0A, 0x2C, 0x77, 0x78, 0x69,
0x64, 0x5F, 0x37, 0x77, 0x64, 0x31, 0x65, 0x63,
0x65, 0x39, 0x39, 0x66, 0x37, 0x69, 0x32, 0x31,
0x5F, 0x31, 0x37, 0x36, 0x38, 0x32, 0x33, 0x30,
0x31, 0x38, 0x35, 0x5F, 0x31, 0x33, 0x35, 0x5F,
0x78, 0x77, 0x65, 0x63, 0x68, 0x61, 0x74, 0x5F,
0x31, 0x1A, 0x15, 0x0A, 0x13, 0x77, 0x78, 0x69,
0x64, 0x5F, 0x6C, 0x64, 0x66, 0x74, 0x75, 0x68,
0x65, 0x33, 0x36, 0x69, 0x7A, 0x67, 0x31, 0x39,
0x22, 0x15, 0x0A, 0x13, 0x77, 0x78, 0x69, 0x64,
0x5F, 0x37, 0x77, 0x64, 0x31, 0x65, 0x63, 0x65,
0x39, 0x39, 0x66, 0x37, 0x69, 0x32, 0x31, 0x28,
0xD3, 0x11, 0x30, 0x00, 0x38, 0xD3, 0x11, 0x42,
0x04, 0x08, 0x00, 0x12, 0x00, 0x48, 0x03, 0x52,
0x83, 0x01, 0x3C, 0x6D, 0x73, 0x67, 0x73, 0x6F,
0x75, 0x72, 0x63, 0x65, 0x3E, 0x3C, 0x69, 0x6D,
0x67, 0x5F, 0x66, 0x69, 0x6C, 0x65, 0x5F, 0x6E,
0x61, 0x6D, 0x65, 0x3E, 0x36, 0x35, 0x39, 0x36,
0x34, 0x33, 0x63, 0x61, 0x2D, 0x66, 0x31, 0x62,
0x63, 0x2D, 0x34, 0x39, 0x33, 0x64, 0x2D, 0x61,
0x65, 0x37, 0x38, 0x2D, 0x35, 0x62, 0x30, 0x62,
0x31, 0x65, 0x34, 0x39, 0x35, 0x33, 0x64, 0x64,
0x2E, 0x70, 0x6E, 0x67, 0x3C, 0x2F, 0x69, 0x6D,
0x67, 0x5F, 0x66, 0x69, 0x6C, 0x65, 0x5F, 0x6E,
0x61, 0x6D, 0x65, 0x3E, 0x3C, 0x61, 0x6C, 0x6E,
0x6F, 0x64, 0x65, 0x3E, 0x3C, 0x66, 0x72, 0x3E,
0x31, 0x3C, 0x2F, 0x66, 0x72, 0x3E, 0x3C, 0x63,
0x66, 0x3E, 0x33, 0x3C, 0x2F, 0x63, 0x66, 0x3E,
0x3C, 0x2F, 0x61, 0x6C, 0x6E, 0x6F, 0x64, 0x65,
0x3E, 0x3C, 0x2F, 0x6D, 0x73, 0x67, 0x73, 0x6F,
0x75, 0x72, 0x63, 0x65, 0x3E, 0x58, 0x01, 0x60,
0x02, 0x68, 0x05, 0x7A, 0xB2, 0x01, 0x33, 0x30,
0x35, 0x37, 0x30, 0x32, 0x30, 0x31, 0x30, 0x30,
0x30, 0x34, 0x34, 0x62, 0x33, 0x30, 0x34, 0x39,
0x30, 0x32, 0x30, 0x31, 0x30, 0x30, 0x30, 0x32,
0x30, 0x34, 0x64, 0x30, 0x61, 0x37, 0x30, 0x39,
0x35, 0x64, 0x30, 0x32, 0x30, 0x33, 0x32, 0x66,
0x38, 0x30, 0x32, 0x39, 0x30, 0x32, 0x30, 0x34,
0x64, 0x32, 0x66, 0x37, 0x33, 0x64, 0x62, 0x37,
0x30, 0x32, 0x30, 0x34, 0x36, 0x39, 0x36, 0x34,
0x39, 0x37, 0x66, 0x39, 0x30, 0x34, 0x32, 0x34,
0x33, 0x39, 0x33, 0x35, 0x36, 0x31, 0x36, 0x33,
0x33, 0x35, 0x36, 0x31, 0x33, 0x37, 0x36, 0x33,
0x32, 0x64, 0x33, 0x31, 0x33, 0x30, 0x33, 0x31,
0x33, 0x34, 0x32, 0x64, 0x33, 0x34, 0x36, 0x34,
0x33, 0x38, 0x36, 0x36, 0x32, 0x64, 0x33, 0x39,
0x33, 0x30, 0x33, 0x37, 0x36, 0x32, 0x32, 0x64,
0x36, 0x33, 0x33, 0x39, 0x33, 0x33, 0x36, 0x35,
0x36, 0x34, 0x36, 0x33, 0x33, 0x35, 0x33, 0x33,
0x33, 0x34, 0x36, 0x34, 0x36, 0x36, 0x36, 0x35,
0x30, 0x32, 0x30, 0x34, 0x30, 0x35, 0x31, 0x34,
0x33, 0x38, 0x30, 0x31, 0x30, 0x32, 0x30, 0x31,
0x30, 0x30, 0x30, 0x34, 0x30, 0x35, 0x30, 0x30,
0x34, 0x63, 0x35, 0x35, 0x30, 0x35, 0x30, 0x30,
0x82, 0x01, 0xB2, 0x01, 0x33, 0x30, 0x35, 0x37,
0x30, 0x32, 0x30, 0x31, 0x30, 0x30, 0x30, 0x34,
0x34, 0x62, 0x33, 0x30, 0x34, 0x39, 0x30, 0x32,
0x30, 0x31, 0x30, 0x30, 0x30, 0x32, 0x30, 0x34,
0x64, 0x30, 0x61, 0x37, 0x30, 0x39, 0x35, 0x64,
0x30, 0x32, 0x30, 0x33, 0x32, 0x66, 0x38, 0x30,
0x32, 0x39, 0x30, 0x32, 0x30, 0x34, 0x64, 0x32,
0x66, 0x37, 0x33, 0x64, 0x62, 0x37, 0x30, 0x32,
0x30, 0x34, 0x36, 0x39, 0x36, 0x34, 0x39, 0x37,
0x66, 0x39, 0x30, 0x34, 0x32, 0x34, 0x33, 0x39,
0x33, 0x35, 0x36, 0x31, 0x36, 0x33, 0x33, 0x35,
0x36, 0x31, 0x33, 0x37, 0x36, 0x33, 0x32, 0x64,
0x33, 0x31, 0x33, 0x30, 0x33, 0x31, 0x33, 0x34,
0x32, 0x64, 0x33, 0x34, 0x36, 0x34, 0x33, 0x38,
0x36, 0x36, 0x32, 0x64, 0x33, 0x39, 0x33, 0x30,
0x33, 0x37, 0x36, 0x32, 0x32, 0x64, 0x36, 0x33,
0x33, 0x39, 0x33, 0x33, 0x36, 0x35, 0x36, 0x34,
0x36, 0x33, 0x33, 0x35, 0x33, 0x33, 0x33, 0x34,
0x36, 0x34, 0x36, 0x36, 0x36, 0x35, 0x30, 0x32,
0x30, 0x34, 0x30, 0x35, 0x31, 0x34, 0x33, 0x38,
0x30, 0x31, 0x30, 0x32, 0x30, 0x31, 0x30, 0x30,
0x30, 0x34, 0x30, 0x35, 0x30, 0x30, 0x34, 0x63,
0x35, 0x35, 0x30, 0x35, 0x30, 0x30, 0x8A, 0x01,
0x20, 0x65, 0x36, 0x61, 0x65, 0x33, 0x30, 0x63,
0x64, 0x61, 0x65, 0x36, 0x64, 0x31, 0x66, 0x37,
0x64, 0x61, 0x65, 0x36, 0x36, 0x33, 0x38, 0x36,
0x31, 0x36, 0x63, 0x63, 0x35, 0x64, 0x36, 0x31,
0x31, 0x90, 0x01, 0x01, 0x98, 0x01, 0x9A, 0x3E,
0xA0, 0x01, 0x9A, 0x3E, 0xAA, 0x01, 0xB2, 0x01,
0x33, 0x30, 0x35, 0x37, 0x30, 0x32, 0x30, 0x31,
0x30, 0x30, 0x30, 0x34, 0x34, 0x62, 0x33, 0x30,
0x34, 0x39, 0x30, 0x32, 0x30, 0x31, 0x30, 0x30,
0x30, 0x32, 0x30, 0x34, 0x64, 0x30, 0x61, 0x37,
0x30, 0x39, 0x35, 0x64, 0x30, 0x32, 0x30, 0x33,
0x32, 0x66, 0x38, 0x30, 0x32, 0x39, 0x30, 0x32,
0x30, 0x34, 0x64, 0x32, 0x66, 0x37, 0x33, 0x64,
0x62, 0x37, 0x30, 0x32, 0x30, 0x34, 0x36, 0x39,
0x36, 0x34, 0x39, 0x37, 0x66, 0x39, 0x30, 0x34,
0x32, 0x34, 0x33, 0x39, 0x33, 0x35, 0x36, 0x31,
0x36, 0x33, 0x33, 0x35, 0x36, 0x31, 0x33, 0x37,
0x36, 0x33, 0x32, 0x64, 0x33, 0x31, 0x33, 0x30,
0x33, 0x31, 0x33, 0x34, 0x32, 0x64, 0x33, 0x34,
0x36, 0x34, 0x33, 0x38, 0x36, 0x36, 0x32, 0x64,
0x33, 0x39, 0x33, 0x30, 0x33, 0x37, 0x36, 0x32,
0x32, 0x64, 0x36, 0x33, 0x33, 0x39, 0x33, 0x33,
0x36, 0x35, 0x36, 0x34, 0x36, 0x33, 0x33, 0x35,
0x33, 0x33, 0x33, 0x34, 0x36, 0x34, 0x36, 0x36,
0x36, 0x35, 0x30, 0x32, 0x30, 0x34, 0x30, 0x35,
0x31, 0x34, 0x33, 0x38, 0x30, 0x31, 0x30, 0x32,
0x30, 0x31, 0x30, 0x30, 0x30, 0x34, 0x30, 0x35,
0x30, 0x30, 0x34, 0x63, 0x35, 0x35, 0x30, 0x35,
0x30, 0x30, 0xB0, 0x01, 0xD3, 0x11, 0xB8, 0x01,
0x66, 0xC0, 0x01, 0xB4, 0x01, 0xCA, 0x01, 0x20,
0x65, 0x36, 0x61, 0x65, 0x33, 0x30, 0x63, 0x64,
0x61, 0x65, 0x36, 0x64, 0x31, 0x66, 0x37, 0x64,
0x61, 0x65, 0x36, 0x36, 0x33, 0x38, 0x36, 0x31,
0x36, 0x63, 0x63, 0x35, 0x64, 0x36, 0x31, 0x31,
0xDA, 0x01, 0x20, 0x31, 0x63, 0x63, 0x64, 0x35,
0x63, 0x35, 0x32, 0x37, 0x31, 0x62, 0x34, 0x61,
0x30, 0x37, 0x62, 0x39, 0x65, 0x64, 0x30, 0x33,
0x36, 0x64, 0x65, 0x65, 0x61, 0x38, 0x35, 0x63,
0x38, 0x63, 0x33, 0xE0, 0x01, 0xD2, 0xE4, 0xD1,
0xC3, 0x04, 0xF0, 0x01, 0x00, 0xA0, 0x02, 0x00,
0xC8, 0x02, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00
const randomId = [0x20, 0xAF, 0xAC, 0x90, 0x93, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0x01]
const sysHeader = [0x2A, 0x15]
// UnifiedPCMac 26 arm64
const sys = [0x55, 0x6E, 0x69, 0x66, 0x69, 0x65, 0x64, 0x50, 0x43, 0x4D, 0x61, 0x63, 0x20, 0x32, 0x36, 0x20, 0x61, 0x72, 0x6D, 0x36, 0x34, 0x30]
// 45872025384@chatroom_176787000_60_xwechat_1 只需要改这个时间戳就能重复发送
const receiverMsgId = stringToHexArray(receiverGlobal).concat([0x5F])
.concat(stringToHexArray(Math.floor(Date.now() / 1000).toString()))
.concat([0x5F, 0x31, 0x36, 0x30, 0x5F, 0x78, 0x77, 0x65, 0x63, 0x68, 0x61, 0x74, 0x5F, 0x33]);
// 0xb0, 0x02 是长度,需要看一下什么的长度
const msgIdHeader = [0xb0, 0x02, 0x12, 0x2E, 0x0A, 0x2C]
const senderHeader = [0x1A, senderGlobal.length + 2, 0x0A, senderGlobal.length];
// wxid_xxxx 或者 chatroom
const sender = stringToHexArray(senderGlobal);
const receiverHeader = [0x22, receiverGlobal.length + 2, 0x0A, receiverGlobal.length]
// wxid_xxxx
const receiver = stringToHexArray(receiverGlobal)
const randomId1 = [0x28, 0xF4, 0x0B]
const type1 = [0x30, 0x00]
const randomId2 = [0x38, 0xF4, 0x0B]
const randomId3 = [0x42, 0x04, 0x08, 0x00, 0x12, 0x00]
const randomId4 = [0x48, 0x03]
const htmlHeader = [0x52, 0x32];
const html = [0x3C,
0x6D, 0x73, 0x67, 0x73, 0x6F, 0x75, 0x72, // 0x30 msgsour
0x63, 0x65, 0x3E, 0x3C, 0x61, 0x6C, 0x6E, 0x6F, // 0x38 ce><alno
0x64, 0x65, 0x3E, 0x3C, 0x66, 0x72, 0x3E, 0x31, // 0x40 de><fr>1
0x3C, 0x2F, 0x66, 0x72, 0x3E, 0x3C, 0x2F, 0x61, // 0x48 </fr></a
0x6C, 0x6E, 0x6F, 0x64, 0x65, 0x3E, 0x3C, 0x2F, // 0x50 lnode></
0x6D, 0x73, 0x67, 0x73, 0x6F, 0x75, 0x72, // 0x58 msgsour
0x63, 0x65, 0x3E // 0x60 ce>
];
const cdnHeader = [0x58, 0x01, 0x60, 0x02, 0x68, 0x00, 0x7A, 0xB2, 0x01]
// 3057 开头的cdn key
const cdn = stringToHexArray(globalImageCdnKey);
const cdn2Header = [0x82, 0x01, 0xB2, 0x01]
const cdn2 = stringToHexArray(globalImageCdnKey)
const aesKeyHeader = [0x8A, 0x01, 0x20]
const aesKey = stringToHexArray(globalAesKey1)
const randomId5 = [0x90, 0x01, 0x01, 0x98, 0x01, 0xFF, // 0x2C8
0x13, 0xA0, 0x01, 0xFF, 0x13]
const cdn3Header = [0xAA, 0x01, 0xB2, 0x01]
const cdn3 = stringToHexArray(globalImageCdnKey)
const randomId6 = [0xB0, 0x01, 0xF4, 0x0B]
const randomId7 = [0xB8, 0x01, 0x68]
const randomId8 = [0xC0, 0x01, 0x3A]
const aesKey1Header = [0xCA, 0x01, 0x20]
const aesKey1 = stringToHexArray(globalAesKey1)
const aesKey2Header = [0xDA, 0x01, 0x20]
const aesKey2 = stringToHexArray(globalAesKey2)
const randomId9 = [0xE0, 0x01, 0xd9, 0xe7, 0xc7, 0xF3, 0x02]
var left0 = [
0xF0, 0x01, 0x00, 0xA0, 0x02, 0x00, // 0x3E0
0xC8, 0x02, 0x00, 0x00 // 0x3E8
]
const finalPayload = type.concat(msgId, cpHeader, cp, randomId, sysHeader, sys, msgIdHeader, receiverMsgId,
senderHeader, sender, receiverHeader, receiver, randomId1, type1, randomId2, randomId3, randomId4, htmlHeader, html,
cdnHeader, cdn, cdn2Header, cdn2, aesKeyHeader, aesKey, randomId5, cdn3Header, cdn3, randomId6, randomId7, randomId8,
aesKey1Header, aesKey1, aesKey2Header, aesKey2, randomId9, left0)
console.log("[+] Payload 准备写入");
// dumpMemoryToHex(this.context.x1, 1024)
// console.log("[+] 寄存器修改完成: X1=" + hexdump(this.context.x1, {
// offset: 0,
// length: 1024,
// header: true,
// ansi: true
// }));
protoX1PayloadAddr.writeByteArray(finalPayload);
console.log("[+] Payload 已写入,长度: " + finalPayload.length);
@@ -895,69 +685,25 @@ function isPrintableOrChinese(startPtr, maxScanLength) {
return true;
}
var runReadX0 = ptr(0)
var originCgiPtr = ptr(0)
function patchRunReadWrite() {
Interceptor.attach(runReadWriteAddr, {
function patchCdnOnComplete() {
Interceptor.attach(CndOnCompleteAddr, {
onEnter: function (args) {
console.log("[+] enter CndOnCompleteAddr");
try {
if (this.context.x5.isNull() || this.context.x5.compare(baseAddr) <= 0) {
return
}
const x5 = this.context.x5;
const cTaskId = x5.add(0x308).readU32();
if (cTaskId !== taskIdGlobal) {
return
}
console.log("[+] enter runReadWriteAddr: " + runReadWriteAddr)
const domainAddr = x5.add(0xd8);
const domainBytes = [
0x73, 0x7A, 0x73, 0x68, 0x6F, 0x72, 0x74, 0x2E, // szshort.
0x77, 0x65, 0x69, 0x78, 0x69, 0x6E, 0x2E, 0x71, // weixin.q
0x71, 0x2E, 0x63, 0x6F, 0x6D // q.com
];
domainAddr.writeByteArray(domainBytes);
domainAddr.add(domainBytes.length).writeU8(0);
domainAddr.add(23).writeU8(0x15);
runReadX0 = this.context.x0;
originCgiPtr = runReadX0.add(0x1018).readPointer();
runReadX0.add(0x1018).writePointer(cgiAddr);
runReadX0.add(0x1020).writeU64(0x22);
console.log("[+] enter runReadWriteAddr finished: " + domainAddr.readUtf8String())
const x2 = this.context.x2;
globalImageCdnKey = x2.add(0x60).readPointer().readUtf8String();
globalAesKey1 = x2.add(0x78).readPointer().readUtf8String();
globalAesKey2 = x2.add(0x90).readPointer().readUtf8String();
console.log("[+] globalImageCdnKey: " + globalImageCdnKey + " globalAesKey1: " + globalAesKey1 + " globalAesKey2: " + globalAesKey2);
} catch (e) {
console.log("[-] Memory access error at onEnter: " + e);
}
}
})
Interceptor.attach(runReadWriteAddr1, {
onEnter: function (args) {
try {
if (this.context.x20.isNull() || this.context.x20.compare(baseAddr) <= 0) {
return
}
const cTaskId = this.context.x20.add(0x308).readU32();
if (cTaskId !== taskIdGlobal) {
return
}
runReadX0.add(0x1018).writePointer(originCgiPtr);
console.log("[+] leave runReadWriteAddr finished: " + runReadWriteAddr)
} catch (e) {
console.log("[-] Memory access error at onLeave: " + e);
}
}
})
runReadWriteAddr1
}
setImmediate(patchRunReadWrite)
setImmediate(patchCdnOnComplete)
rpc.exports = {