(base) r@R aikucun % frida -H 127.0.0.1:12345 -l hook.js -f com.aikucun.akapp
____
/ _ | Frida 16.2.1 - A world-class dynamic instrumentation toolkit
| (_| |
> _ | Commands:
/_/
|_| help -> Displays the help system
. . . . object? -> Display information about
'object'
. . . .
exit
/quit
-> Exit
. . . .
. . . . More info at https:
//frida
.re
/docs/home/
. . . .
. . . . Connected to 127.0.0.1:12345 (
id
=socket@127.0.0.1:12345)
Spawned `com.aikucun.akapp`. Resuming main thread!
[Remote::com.aikucun.akapp ]-> The thread
function
offset address
in
libmsaoaidsec.so(0x7b6b5e4000) is 0x175f8
replace: 0x175f8
The thread
function
offset address
in
libmsaoaidsec.so(0x7b6b5e4000) is 0x16d30
replace: 0x16d30
replace 0x7b6b5fb5f8
replace 0x7b6b5fad30
Java hook start
MXSecurity.signV3 is called: url=https:
//zuul
.aikucun.com
/akucun-base-data-new/base/address/selectAddrVersion
?appid=38741001&did=8e72f37ab5db201b91de47172047e760&noncestr=3d0f39&svs=v3×tamp=1734184260, nonceStr=3d0f39, timestamp=1734184260, body=
[+] MessageDigest.digest(byte[]) called
Plaintext: appid=38741001&svs=v3&noncestr=3d0f39×tamp=1734184260&secret=04fdc5e4d9c7420e896ee92b17c68e9f&url=https:
//zuul
.aikucun.com
/akucun-base-data-new/base/address/selectAddrVersion
?appid=38741001&did=8e72f37ab5db201b91de47172047e760&noncestr=3d0f39&svs=v3×tamp=1734184260
MXSecurity.signV3 result=5c927464497d321ac3ff49d817cc571d696da21e828ea75bdc9e3465af8a17ae
MXSecurity.signV3 is called: url=https:
//m
.xiangdian.com
/api/mshop/mshop-aggr-prod/outer/common/bwl/isHitByBatch
?appid=38741001&did=8e72f37ab5db201b91de47172047e760&noncestr=22f096&svs=v3×tamp=1734184260, nonceStr=22f096, timestamp=1734184260, body=398a40be5a2a6a5a742f35b1b606277a
[+] MessageDigest.digest(byte[]) called
Plaintext: appid=38741001&svs=v3&noncestr=22f096×tamp=1734184260&secret=04fdc5e4d9c7420e896ee92b17c68e9f&url=https:
//m
.xiangdian.com
/api/mshop/mshop-aggr-prod/outer/common/bwl/isHitByBatch
?appid=38741001&did=8e72f37ab5db201b91de47172047e760&noncestr=22f096&svs=v3×tamp=1734184260&398a40be5a2a6a5a742f35b1b606277a
MXSecurity.signV3 result=bd809e352277f9357b436ed424a8fd62b546f415e7f9e7875a05bda5aa5f6704
MXSecurity.signV3 is called: url=https:
//m
.xiangdian.com
/api/mshop/mshop-aggr-prod/outer/v1/material/create/createAuth
?appid=38741001&did=8e72f37ab5db201b91de47172047e760&noncestr=9908c3&svs=v3×tamp=1734184261, nonceStr=9908c3, timestamp=1734184261, body=37a6259cc0c1dae299a7866489dff0bd
[+] MessageDigest.digest(byte[]) called
Plaintext: appid=38741001&svs=v3&noncestr=9908c3×tamp=1734184261&secret=04fdc5e4d9c7420e896ee92b17c68e9f&url=https:
//m
.xiangdian.com
/api/mshop/mshop-aggr-prod/outer/v1/material/create/createAuth
?appid=38741001&did=8e72f37ab5db201b91de47172047e760&noncestr=9908c3&svs=v3×tamp=1734184261&37a6259cc0c1dae299a7866489dff0bd
MXSecurity.signV3 result=1181b2330a12f04c2501193430b50712d6f0187a2f87eaf0fe861016e2e1f6a7
MXSecurity.signV3 is called: url=https:
//zuul
.aikucun.com
/appconfigmgt/api/v1/download/config
?appid=38741001&did=8e72f37ab5db201b91de47172047e760&noncestr=32a49b&svs=v3×tamp=1734184263, nonceStr=32a49b, timestamp=1734184263, body=2288e58e8bda39d24cb10b10af923d50
[+] MessageDigest.digest(byte[]) called
Plaintext: appid=38741001&svs=v3&noncestr=32a49b×tamp=1734184263&secret=04fdc5e4d9c7420e896ee92b17c68e9f&url=https:
//zuul
.aikucun.com
/appconfigmgt/api/v1/download/config
?appid=38741001&did=8e72f37ab5db201b91de47172047e760&noncestr=32a49b&svs=v3×tamp=1734184263&2288e58e8bda39d24cb10b10af923d50
MXSecurity.signV3 result=4d9b7d406b6ce2e44dc602b8c83a49b4b20ec944bea69d72aae3790249ed7127