dumpdecrypted的使用
2018-07-15 本文已影响1人
alitan2015
1.首先从官网下载《dumpdecrypted》https://github.com/stefanesser/dumpdecrypted
2.下载完后可以看到如下图文件
![](https://img.haomeiwen.com/i4955462/7e1b54d38e087b9d.png)
3.cd到dumpdecypted目录下,然后执行make命令
![](https://img.haomeiwen.com/i4955462/68cf2e961886876e.png)
4.待编译完成后可以查看到如下图文件,多了dumpdecrypted.o文件以及编译产出物dumpdecrypted.dylib文件
![](https://img.haomeiwen.com/i4955462/d784dc34dd16322b.png)
5.通过ssh命令连接上手机端 ssh@root(ip地址),回车并输入密码
![](https://img.haomeiwen.com/i4955462/83fe89db76e02679.png)
6.注入微信进程,并获取沙盒路径file:///var/mobile/Containers/Data/Application/A59D5283-A414-4FEB-B0E3-F402CBC5EB64/Documents/
![](https://img.haomeiwen.com/i4955462/91cf17cb72f7f3da.png)
7.进入沙盒目录
![](https://img.haomeiwen.com/i4955462/801cbd2787573e3a.png)
8.把dumpdecrypted.dylib文件copy到沙盒路径下
![](https://img.haomeiwen.com/i4955462/4df60e4f2e457cd2.png)
9.使用DYLD_INSERT_LIBRARIES=dumpdecrypted.dylib (App路径) 进行砸壳
![](https://img.haomeiwen.com/i4955462/2a1f209ca4f0ee9b.png)
10.砸壳完成如下图
![](https://img.haomeiwen.com/i4955462/3305dff74268bf67.png)
11.并生成砸壳完后文件 WeChat.decrypted文件
![](https://img.haomeiwen.com/i4955462/5d35004ae5e3e1b8.png)
12.copy WeChat.decrypted文件到电脑
![](https://img.haomeiwen.com/i4955462/dce10b8fb1fcb929.png)
13.使用class-dump --arch armv7 -s -S -H WeChat.decrypted -o ./WCHeaders/进行砸壳 (--arch armv7 根据设备芯片架构进行选择)
![](https://img.haomeiwen.com/i4955462/c6d8f74d785b309e.png)
14.到此砸壳已经完成
![](https://img.haomeiwen.com/i4955462/f5781d196776bda3.png)