-
Notifications
You must be signed in to change notification settings - Fork 32
/
Copy pathfrida-dump-memory.py
executable file
·81 lines (74 loc) · 3.29 KB
/
frida-dump-memory.py
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
#!/usr/bin/python
import sys
import frida
import time
def on_message(message, data):
if 'payload' in message:
pname = message['payload']
filename = ("%s.bin" % pname)
print("Writing %s" % filename)
fo = open(filename, "wb")
fo.write(data)
fo.close()
def main(target_process):
session = frida.get_usb_device().attach(target_process)
script = session.create_script("""
var modules = Process.enumerateModulesSync();
var module;
var lastmodule="";
var lastmodulebase=0;
var modulelist = [];
for (var i=0; i<modules.length; i++) {
module = modules[i];
if (lastmodule == "") {
lastmodule = module.name;
lastmodulebase = module.base;
continue;
}
console.log(module.name+":"+module.base+":"+module.size);
line = { "name":module.name, "start":parseInt(module.base,16), "end":parseInt(lastmodulebase,16) };
modulelist.push(line);
lastmodule = module.name;
lastmodulebase = module.base;
}
var ranges = Process.enumerateRangesSync({protection: 'r--', coalesce: true});
var range;
for (var j=0; j<ranges.length; j++) {
range = ranges[j]; //ranges.pop();
console.log(range.base+":"+range.size+":"+range.protection);
for(var i=0; i<modulelist.length; i++) {
name = modulelist[i].name;
if (name == "%s") {
start = modulelist[i].start;
end = modulelist[i].end;
//console.log(name+":"+start+":"+end);
if (parseInt(range.base,16) <= end && parseInt(range.base,16) >= start) {
console.log(modulelist[i].name);
console.log(range.base+':'+range.size+':'+range.protection);
var bytes = Memory.readByteArray(range.base, range.size);
send(range.base, bytes);
}
} else if (name == "ApplePushService") {
if (parseInt(range.base,16) >= modulelist[i].start && range.size < 1000000) {
console.log(modulelist[i].name+":"+range.size);
var bytes = Memory.readByteArray(range.base, range.size);
send(range.base, bytes);
}
}
}
}
""" % target_process)
script.on('message', on_message)
script.load()
raw_input('[!] Press <Enter> at any time to detach from instrumented program.\n\n')
session.detach()
sys.exit(0)
if __name__ == '__main__':
if len(sys.argv) < 2:
print 'Usage: %s <process name or PID> <pattern in form "41 42 ?? 43">' % __file__
sys.exit(1)
try:
target_process = int(sys.argv[1])
except ValueError:
target_process = sys.argv[1]
main(target_process)