我试图在我的apk中修改一个dex文件,以使代码模糊。
我在eclipse上编译以下代码:
boolean test = false;
SmsManager sm = SmsManager.getDefault();
if (test){ // always false
test = true; // this branch is never taken
} else {
String messageBody = "sms";
sm.sendTextMessage("5556", null, messageBody, null, null);
}
因此,仅执行“ else分支”。另一个分支是无效代码。
然后,我将代码导出到带有Eclipse的apk中。
之后,我使用apktools打开apk,选择了dex文件,因此具有以下字节码:
CODE:3EE80 const/4 v2, 0
CODE:3EE82 206F 001C 0087 invoke-super {this, p0}, <void Activity.onCreate(ref) imp. @ _def_Activity_onCreate@VL>
CODE:3EE88 0115 7F03 const/high16 v1, 0x7F030000
CODE:3EE8C 206E 12C9 0017 invoke-virtual {this, v1}, <void MainActivity.setContentView(int) imp. @ _def_MainActivity_setContentView@VI>
CODE:3EE92 0612 const/4 v6, 0
CODE:3EE94 0071 0FD3 0000 invoke-static {}, <ref SmsManager.getDefault() imp. @ _def_SmsManager_getDefault@L>
CODE:3EE9A 000C move-result-object v0
CODE:3EE9C 0638 0003 if-eqz v6, loc_3EEA2
CODE:3EEA0 1612 const/4 v6, 1
CODE:3EEA2
CODE:3EEA2 031A 143A const-string v3, aSmsI # "sms"
CODE:3EEA6 011A 00BE const-string v1, a5556 # "5556"
CODE:3EEAA 2407 move-object v4, v2
CODE:3EEAC 2507 move-object v5, v2
CODE:3EEAE 0674 0FD4 0000 invoke-virtual/range {v0..v5}, <void SmsManager.sendTextMessage(ref, ref, ref, ref, ref) imp. @ _def_SmsManager_sendTextMessage@VLLLLL>
CODE:3EEB4 000E return-void
CODE:3EEB4 Method End
我在0 / x3eea0的if / else构造中更改了无效代码,使其重叠并在“ else branch”中隐藏了一些代码:
CODE:3EEA0 0218 031A 143A 011A+ const-wide v2:v3, 0xBE011A143A031A
CODE:3EEAA 2407 move-object v4, v2
CODE:3EEAC 2507 move-object v5, v2
CODE:3EEAE 0674 0FD4 0000 invoke-virtual/range {v0..v5}, <void SmsManager.sendTextMessage(ref, ref, ref, ref, ref) imp. @ _def_SmsManager_sendTextMessage@VLLLLL>
CODE:3EEB4 000E return-void
CODE:3EEB4 Method End
然后,我更改dex文件的校验和和哈希值。我用apktools关闭我的apk,并用jarsigner签名。
使用adb时,我将apk安装在仿真设备上。一切都成功了。
但是,当我尝试启动该应用程序时,它崩溃了,并且在我的设备上出现以下错误:“不幸的是,myApps已停止”。
日志猫给我这个:
09-06 08:31:13.126: E/AndroidRuntime(874): FATAL EXCEPTION: main
09-06 08:31:13.126: E/AndroidRuntime(874): java.lang.VerifyError: trust/vuln/myApps/MainActivity
09-06 08:31:13.126: E/AndroidRuntime(874): at java.lang.Class.newInstanceImpl(Native Method)
09-06 08:31:13.126: E/AndroidRuntime(874): at java.lang.Class.newInstance(Class.java:1130)
09-06 08:31:13.126: E/AndroidRuntime(874): at android.app.Instrumentation.newActivity(Instrumentation.java:1061)
09-06 08:31:13.126: E/AndroidRuntime(874): at android.app.ActivityThread.performLaunchActivity(ActivityThread.java:2128)
09-06 08:31:13.126: E/AndroidRuntime(874): at android.app.ActivityThread.handleLaunchActivity(ActivityThread.java:2261)
09-06 08:31:13.126: E/AndroidRuntime(874): at android.app.ActivityThread.access$600(ActivityThread.java:141)
09-06 08:31:13.126: E/AndroidRuntime(874): at android.app.ActivityThread$H.handleMessage(ActivityThread.java:1256)
09-06 08:31:13.126: E/AndroidRuntime(874): at android.os.Handler.dispatchMessage(Handler.java:99)
09-06 08:31:13.126: E/AndroidRuntime(874): at android.os.Looper.loop(Looper.java:137)
09-06 08:31:13.126: E/AndroidRuntime(874): at android.app.ActivityThread.main(ActivityThread.java:5103)
09-06 08:31:13.126: E/AndroidRuntime(874): at java.lang.reflect.Method.invokeNative(Native Method)
09-06 08:31:13.126: E/AndroidRuntime(874): at java.lang.reflect.Method.invoke(Method.java:525)
09-06 08:31:13.126: E/AndroidRuntime(874): at com.android.internal.os.ZygoteInit$MethodAndArgsCaller.run(ZygoteInit.java:737)
09-06 08:31:13.126: E/AndroidRuntime(874): at com.android.internal.os.ZygoteInit.main(ZygoteInit.java:553)
09-06 08:31:13.126: E/AndroidRuntime(874): at dalvik.system.NativeStart.main(Native Method)
09-06 08:31:13.226: W/ActivityManager(288): Force finishing activity com.vuln.myApps/.MainActivity
是java.lang.VerifyError是否因为我的应用程序中的字节码重叠?并且无论如何要在Android应用程序中实现重叠的字节码?
最佳答案
Dalvik验证程序将不允许您跳转到指令的中间。明确禁止您尝试执行的操作。
如果您在问题显示的异常上方几行中查看logcat输出,则应该看到一堆“ VFY”消息,它们指示出特定的关注点。