forked from xsgaaa/WeChatOpenDevTools
-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathhook.js
78 lines (65 loc) · 2.01 KB
/
hook.js
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
var base = Process.enumerateModules()[0].base
send(base)
//HOOK F12配置 替换原本内容
var pvWechatapphtml = base.add(0x2EC9FBD)
Interceptor.attach(pvWechatapphtml, {
onEnter(args) {
this.context.rdx = base.add(0x7C0D6BD);
var rdx = this.context.rdx;
send(rdx)
}
})
function readStdString(s) {
var flag = s.add(23).readU8()
if (flag == 0x80) {
// heap
var size = s.add(8).readUInt()
return s.readPointer().readUtf8String(size)
} else {
// stack
return s.readUtf8String(flag)
}
}
function writeStdString(s, content) {
var flag = s.add(23).readU8()
if (flag == 0x80) {
// heap
var orisize = s.add(8).readUInt()
if (content.length > orisize) {
throw "must below orisize!"
}
s.readPointer().writeUtf8String(content)
s.add(8).writeUInt(content.length)
} else {
// stack
if (content.length > 22) {
throw "max 23 for stack str"
}
s.writeUtf8String(content)
s.add(23).writeU8(content.length)
}
}
var pvLaunchAppletBegin = base.add(0x1B3FF3C)
//HOOK 启动配置
Interceptor.attach(pvLaunchAppletBegin, {
onEnter(args) {
send("HOOK加载完成! " + readStdString(args[1]))
for (var i = 0; i < 0x1000; i+=8) {
try {
var s = readStdString(args[2].add(i))
if (s) {
//send("got str: " + s)
}
var s1 = s.replaceAll("md5", "md6").replaceAll('"enable_vconsole":false', '"enable_vconsole": true')
if (s === s1) {
} else {
//send("changing to str: " + s1)
send("拦截到小程序加载")
writeStdString(args[2].add(i), s1)
}
} catch (a) {
}
}
}
})
send("注入成功!")