apk 破解之dexdump反编译Android程序
<LinearLayout??
??? xmlns:android="http://schemas.android.com/apk/res/android"
??? android:orientation="1"
??? android:layout_width="-1"
??? android:layout_height="-1"
??? >??
??? <WebView??
??????? android:id="@7F050000"
??????? android:layout_width="-1"
??????? android:layout_height="-2"
??????? >??
??? </WebView>??
</LinearLayout>
<?xml version="1.0" encoding="utf-8"?>
<LinearLayout
xmlns:android="http://schemas.android.com/apk/res/android"
android:orientation="1"
android:layout_width="-1"
android:layout_height="-1"
>
<WebView
?? android:id="@7F050000"
?? android:layout_width="-1"
?? android:layout_height="-2"
?? >
</WebView>
</LinearLayout>
为了比对打开源程序中的main.xml代码如下(大家比对一下吧):
view plaincopy to clipboardprint?
<?xml version="1.0" encoding="utf-8"?>??
<LinearLayout xmlns:android="http://schemas.android.com/apk/res/android"
??? android:orientation="vertical"
??? android:layout_width="fill_parent"
??? android:layout_height="fill_parent"
??? >??
<WebView??
??? android:id="@+id/apk_web"
??? android:layout_height="wrap_content"
??? android:layout_width="fill_parent"
??????
/>??
</LinearLayout>
<?xml version="1.0" encoding="utf-8"?>
<LinearLayout xmlns:android="http://schemas.android.com/apk/res/android"
??? android:orientation="vertical"
??? android:layout_width="fill_parent"
??? android:layout_height="fill_parent"
??? >
<WebView
android:id="@+id/apk_web"
android:layout_height="wrap_content"
android:layout_width="fill_parent"
/>
</LinearLayout>
2.用baksmali.jar反编译classes.dex:
将ApkInstaller.apk里的classes.dex解压到tools目录里,然后baksmali.jar就派上用场了,在cmd命令行里输入如下命令:
java -jar baksmali.jar -o classout/ classes.dex .(如下图所示:)
# instance fields??
.field private apkWeb:Landroid/webkit/WebView;??
# direct methods??
.method public constructor <init>()V??
??? .registers 1
??? .prologue??
??? .line 8
??? invoke-direct {p0}, Landroid/app/Activity;-><init>()V??
??? return-void
.end method??
# virtual methods??
.method public onCreate(Landroid/os/Bundle;)V??
??? .registers 5
??? .parameter "savedInstanceState"
??? .prologue??
??? .line 13
??? invoke-super {p0, p1}, Landroid/app/Activity;->onCreate(Landroid/os/Bundle;)V??
??? .line 14
??? const/high16 v2, 0x7f03
??? invoke-virtual {p0, v2}, Lcom/tutor/apkinstaller/ApkInstaller;->setContentView(I)V??
??? .line 15
??? const/high16 v2, 0x7f05
??? invoke-virtual {p0, v2}, Lcom/tutor/apkinstaller/ApkInstaller;->findViewById(I)Landroid/view/View;??
??? move-result-object v2??
??? check-cast v2, Landroid/webkit/WebView;??
??? iput-object v2, p0, Lcom/tutor/apkinstaller/ApkInstaller;->apkWeb:Landroid/webkit/WebView;??
??? .line 16
??? iget-object v2, p0, Lcom/tutor/apkinstaller/ApkInstaller;->apkWeb:Landroid/webkit/WebView;??
??? invoke-virtual {v2}, Landroid/webkit/WebView;->getSettings()Landroid/webkit/WebSettings;??
??? move-result-object v1??
??? .line 17
??? .local v1, webSettings:Landroid/webkit/WebSettings;??
??? const/4 v2, 0x1
??? invoke-virtual {v1, v2}, Landroid/webkit/WebSettings;->setJavaScriptEnabled(Z)V??
??? .line 19
??? const-string v0, "http://frankiewei.net/apk/demos/main/index.html#home"
??? .line 20
??? .local v0, apkUrl:Ljava/lang/String;??
??? iget-object v2, p0, Lcom/tutor/apkinstaller/ApkInstaller;->apkWeb:Landroid/webkit/WebView;??
??? invoke-virtual {v2, v0}, Landroid/webkit/WebView;->loadUrl(Ljava/lang/String;)V??
??? .line 21
??? return-void
.end method
.class public Lcom/tutor/apkinstaller/ApkInstaller;
.super Landroid/app/Activity;
.source "ApkInstaller.java"
# instance fields
.field private apkWeb:Landroid/webkit/WebView;
# direct methods
.method public constructor <init>()V
??? .registers 1
??? .prologue
??? .line 8
??? invoke-direct {p0}, Landroid/app/Activity;-><init>()V
??? return-void
.end method
# virtual methods
.method public onCreate(Landroid/os/Bundle;)V
??? .registers 5
??? .parameter "savedInstanceState"
??? .prologue
??? .line 13
??? invoke-super {p0, p1}, Landroid/app/Activity;->onCreate(Landroid/os/Bundle;)V
??? .line 14
??? const/high16 v2, 0x7f03
??? invoke-virtual {p0, v2}, Lcom/tutor/apkinstaller/ApkInstaller;->setContentView(I)V
??? .line 15
??? const/high16 v2, 0x7f05
??? invoke-virtual {p0, v2}, Lcom/tutor/apkinstaller/ApkInstaller;->findViewById(I)Landroid/view/View;
??? move-result-object v2
??? check-cast v2, Landroid/webkit/WebView;
??? iput-object v2, p0, Lcom/tutor/apkinstaller/ApkInstaller;->apkWeb:Landroid/webkit/WebView;
??? .line 16
??? iget-object v2, p0, Lcom/tutor/apkinstaller/ApkInstaller;->apkWeb:Landroid/webkit/WebView;
??? invoke-virtual {v2}, Landroid/webkit/WebView;->getSettings()Landroid/webkit/WebSettings;
??? move-result-object v1
??? .line 17
??? .local v1, webSettings:Landroid/webkit/WebSettings;
??? const/4 v2, 0x1
??? invoke-virtual {v1, v2}, Landroid/webkit/WebSettings;->setJavaScriptEnabled(Z)V
??? .line 19
??? const-string v0, "http://frankiewei.net/apk/demos/main/index.html#home"
??? .line 20
??? .local v0, apkUrl:Ljava/lang/String;
??? iget-object v2, p0, Lcom/tutor/apkinstaller/ApkInstaller;->apkWeb:Landroid/webkit/WebView;
??? invoke-virtual {v2, v0}, Landroid/webkit/WebView;->loadUrl(Ljava/lang/String;)V
??? .line 21
??? return-void
.end method
同样为了比对我们看一下ApkInstaller.java的源代码如下:
view plaincopy to clipboardprint?
package com.tutor.apkinstaller;??
import android.app.Activity;??
import android.os.Bundle;??
import android.webkit.WebSettings;??
import android.webkit.WebView;??
public class ApkInstaller extends Activity {??
?????
??? private WebView apkWeb;??
??? @Override
??? public void onCreate(Bundle savedInstanceState) {??
??????? super.onCreate(savedInstanceState);??
??????? setContentView(R.layout.main);??
?????? apkWeb = (WebView)findViewById(R.id.apk_web);??
?????? WebSettings webSettings = apkWeb.getSettings();??
?????? webSettings.setJavaScriptEnabled(true);??
????????
?????? String apkUrl = "http://frankiewei.net/apk/demos/main/index.html#home";??
?????? apkWeb.loadUrl(apkUrl);??
??? }??
}
package com.tutor.apkinstaller;
import android.app.Activity;
import android.os.Bundle;
import android.webkit.WebSettings;
import android.webkit.WebView;
public class ApkInstaller extends Activity {
??
private WebView apkWeb;
??? @Override
??? public void onCreate(Bundle savedInstanceState) {
??????? super.onCreate(savedInstanceState);
??????? setContentView(R.layout.main);
?????? apkWeb = (WebView)findViewById(R.id.apk_web);
?????? WebSettings webSettings = apkWeb.getSettings();
?????? webSettings.setJavaScriptEnabled(true);
?????
?????? String apkUrl = "http://frankiewei.net/apk/demos/main/index.html#home";
?????? apkWeb.loadUrl(apkUrl);
??? }
}
我相信大家 已经能看出来门道来了吧,hoho~
3.用smali.jar编译classout成classes.dex:
我们上一步已经将classes.dex反编译成了.smali文件,好了,我们看看smali文件看够了,在偿试把它编译成classes.dex吧,
输入如下命令:java -jar smali.jar classout/ -o classes.dex. 如下图所示:
我们可以将新生成的classes.dex塞入ApkInstaller.apk里覆盖原来的classes.dex文件,这样我们的apk还是一样能用的哦
?
?
首先要把apk的class.dex dump出来、 :
具体步骤:1.用winrar或者winzip打开apk,直接拖出来。
? ?? ?? ? 2.用android sdk1.1版本以上的一个dexdump工具把class.dex文件dump成文本:
? ?? ?? ?? ?把刚才的class.dex文件放在和dexdump工具同目录 用命令窗口执行 :
????????????dexdump.exe -d classes.dex > spk.dump.txt
? ?? ?? ?? ?意思是将classes.dex dump出来 形成一个txt文件
下一步就要读懂这个txt文件了,先从header中可以看清楚这个应用的总体信息,有几个类,包括内部类 ,header只是了解概况。要详细去分析下面的每一个class才能真正理解这个软件的设计过程。最好的方法是一边研究里面的opcode一边打开api来查看里面调用到的类和方法,减少误解的机率。。
opcode就是介于高级编程语言和二进制代码之间的一层中间码,operation
code 叫操作码。读懂opcode主要是熟悉里面的逻辑跳转以及一些个别助记符的含义。。
通过opcode你就可以清晰的知道里面每个方法资源的调用过程和逻辑跳转过程。做过的例子都有点复杂,就不举例了。。当然,要破解整个apk最好是翻译opcode和应HexWorkShop查看资源文件相结合比较合理和轻松,尤其是ManiFest.xml这个文件,一定要看清楚里面的activity和service receiver,permissions 这几个部分的信息,这可能会成为整个破译流程的关键部分 。。。能够说的经验暂时就只有这么多,正着手写一个工具专门用来翻译opcode成java代码。。这是一个复杂的过程,普通的资源调用只需要匹配相关的文本就能翻译过来,但是一些复杂的跳转和个别特殊表达式需要费时费力去想想。。。