安卓协议逆向 cxdx 分析与实现

您所在的位置:网站首页 soap协议与http协议 安卓协议逆向 cxdx 分析与实现

安卓协议逆向 cxdx 分析与实现

2023-03-24 08:25| 来源: 网络整理| 查看: 265

本文为看雪论坛优秀文章

看雪论坛作者ID:行简

一、Kit

app 版本:5.0.0

设备:K40 刷 piexl 11 rom

抓包工具:Charles

反汇编工具:JEB、JADX、IDA

inject:frida

二、抓包

POST /v1/api/app/login/doLogin HTTP/1.1 X-OsVersion: 30 User-Agent: Mo zilla/5.0 (Linux; Android 11; M2012K11AC Build/RQ3A.211001.001; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/108.0.5359.128 Mobile Safari/537.36 CSDNApp/5.0.0(Android)wToken/0.0.1 X-RandomNum: 54736 X-Access-Token: 00871d5df0d4f51efb5883b3b2fd2359 platform: android X-Ca-Signature-Headers: X-Ca-Timestamp,X-Ca-Key,X-Ca-Nonce Authorization: X-OS: Android c_appVersion: 5.0.0 X-App-ID: CSDN-APP X-App-Theme: day content-type: application/json; charset=UTF-8 X-Ca-Signature: BqhPpXbobBOndykiyCtOVK06GHLkfLbs1y4B3Ek0gnY= X-ConnectionType: WIFI UserToken: X-TimeStamp: 1671939318488 Cookie: UserName=;UserToken= X-Ca-Key: 203789067 Accept: application/json X-Device-ID: aid0f0fef992b53479187546b3c621157f0 wToken: e447_5rU5WWYQegPo5EMOZSnKzF4YPtJSetwo+lGrEUrtZaKEe73GkiTOoE83PLp0yivsi4pZV7HySc+lbsebppMqHlXmQwVLx0vrlQpYC0b99vOYBRZWnVbeMhLZ4WUuAAKH/V07WkNSNXORUsgHumLj1BZZ7x1riK8beahdp9ctmSwP3AdA/sZA4OkzEVF4rJ+G6nwyyGcI/JLoRH0/1hPUT91sdBKKA64yj1QKRAZuJjsX9WRcqo9xYgfcJDnpqVnhObGQD96CfSok8z8d9otv+Fl6ULZrddvcnvzs6cJhjuW3ryBn151Xat/2CU/9EXUEKG3e0g4/K9rEaDRb2JhDGEDwIj+Qd5RU1uaBKxS/7jlSVq8wQ7x3qVVN1tHqS4AXhVow6eMABT6PArcEfkFm42bwXOFWsAUd5C7uGvHGIlTGytU6Vx/CJPwPvCuSffef5mQL7daszEzN+zQJ9VjxgOrjKXkDVkt6O6UpyA+1u3lowOqUaSPK6u2vND/Xqus7&ff4b_85475962D8E15A4E7AE60ED42FF3568E8EDB86EE620E495591 X-DeviceModel: Redmi M2012K11AC version: 5.0.0 X-Ca-Nonce: be0eca5c-e959-4b0f-b4e7-22e00118157e X-Ca-Timestamp: 1671939318489 X-Sign: 70B21B02FD0EFD2353F0D7F4F2E7CDB6FC1C3C42 Host: passport.csdn.net Connection: Keep-Alive Accept-Encoding: gzip Content-Length: 95 {"pwdOrVerifyCode":"123456","loginType":"1","userIdentification":"17750659921","checkAli":true}

意料之中一大堆参数,反复几次总结需分析的参数应该为以下几个:

X-Sign、wToken、X-Ca-Signature、X-Access-Token、X-Ca-Timestamp

阅读原文:[原创] 安卓协议逆向 cxdx 分析与实现



【本文地址】


今日新闻


推荐新闻


CopyRight 2018-2019 办公设备维修网 版权所有 豫ICP备15022753号-3