iOS 7.1.x,原帖中snakeninny略啰嗦。。。
CC_BIN=`xcrun --sdk iphoneos --find gcc` GCC_UNIVERSAL=$(GCC_BASE) -arch armv7 -arch armv7s -arch arm64 SDK=`xcrun --sdk iphoneos --show-sdk-path` CFLAGS = GCC_BASE = $(GCC_BIN) -Os $(CFLAGS) -Wimplicit -isysroot $(SDK) -F$(SDK)/System$ all: dumpdecrypted.dylib dumpdecrypted.dylib: dumpdecrypted.o $(GCC_UNIVERSAL) -dynamiclib -o $@ $^ %.o: %.c $(GCC_UNIVERSAL) -c -o $@ $< clean: rm -f *.o dumpdecrypted.dylib
在Mac中打开终端,输入xcrun --sdk iphoneos --show-sdk-path命令,查看SDK版本:
/Applications/Xcode 5.1.1.app/Contents/Developer/Platforms/iPhoneOS.platform/Developer/SDKs/iPhoneOS7.1.sdk
`xcrun --sdk iphoneos --find gcc` -Os -Wimplicit -isysroot `xcrun --sdk iphoneos --show-sdk-path` -F`xcrun --sdk iphoneos --show-sdk-path`/System/Library/Frameworks -F`xcrun --sdk iphoneos --show-sdk-path`/System/Library/PrivateFrameworks -arch armv7 -arch armv7s -arch arm64 -c -o dumpdecrypted.o dumpdecrypted.c /bin/sh: /Applications/Xcode: No such file or directory make: *** [dumpdecrypted.o] Error 127
原因是找不到/Applications/Xcode来执行其中的一些脚本。 好吧,我的Mac中有3个Xcode:/Applications/Xcode 5.0.2, /Applications/Xcode 5.1.1, /Applications/Xcode 6 Beta4,就是没有/Applications/Xcode。
没事,将Xcode 5.1.1重命名为Xcode就行了:
$ sudo mv Xcode\ 5.1.1.app/ Xcode.app/
$ xcode-select -p /Applications/Xcode 5.1.1.app/Contents/Developer
$ sudo xcode-select -r $ xcode-select -p /Applications/Xcode.app/Contents/Developer
$ make `xcrun --sdk iphoneos --find gcc` -Os -Wimplicit -isysroot `xcrun --sdk iphoneos --show-sdk-path` -F`xcrun --sdk iphoneos --show-sdk-path`/System/Library/Frameworks -F`xcrun --sdk iphoneos --show-sdk-path`/System/Library/PrivateFrameworks -arch armv7 -arch armv7s -arch arm64 -c -o dumpdecrypted.o dumpdecrypted.c `xcrun --sdk iphoneos --find gcc` -Os -Wimplicit -isysroot `xcrun --sdk iphoneos --show-sdk-path` -F`xcrun --sdk iphoneos --show-sdk-path`/System/Library/Frameworks -F`xcrun --sdk iphoneos --show-sdk-path`/System/Library/PrivateFrameworks -arch armv7 -arch armv7s -arch arm64 -dynamiclib -o dumpdecrypted.dylib dumpdecrypted.o $ ls Makefile dumpdecrypted.c dumpdecrypted.o README dumpdecrypted.dylib
$ scp dumpdecrypted.dylib root@192.168.xxx.xxx:/var/tmp root@192.168.xxx.xxx's password: dumpdecrypted.dylib 100% 81KB 81.0KB/s 00:00
$ ssh root@192.168.xxx.xxx root@192.168.xxx.xxx's password: root# cd /var/tmp/ root# ls FlipswitchCache/ com.apple.audio.hogmode.plist L65ancd.sock= com.apple.tccd/ L65d.sock= com.apple.timed.plist MediaCache/ cydia.log RestoreFromBackupLock* dumpdecrypted.dylib* SpringBoard_reboot_flag launchd/ com.apple.assistant.bundleservicecache.plist mobile_assertion_agent.log
root# DYLD_INSERT_LIBRARIES=dumpdecrypted.dylib /var/mobile/Applications/EBBD26E9-DDBA-481E-9403-84D159436889/HBGC.app/HBGC mach-o decryption dumper DISCLAIMER: This tool is only meant for security research purposes, not for application crackers. [+] detected 32bit ARM binary in memory. [+] offset to cryptid found: @0xd5a90(from 0xd5000) = a90 [+] Found encrypted data at address 00004000 of length 3047424 bytes - type 1. [+] Opening /private/var/mobile/Applications/EBBD26E9-DDBA-481E-9403-84D159436889/HBGC.app/HBGC for reading. [+] Reading header [+] Detecting header type [+] Executable is a FAT image - searching for right architecture [+] Correct arch is at offset 16384 in the file [+] Opening HBGC.decrypted for writing. [+] Copying the not encrypted start of the file [+] Dumping the decrypted data into the file [+] Copying the not encrypted remainder of the file [+] Setting the LC_ENCRYPTION_INFO->cryptid to 0 at offset 4a90 [+] Closing original file [+] Closing dump file
root# ls FlipswitchCache/ com.apple.audio.hogmode.plist HBGC.decrypted com.apple.tccd/ L65ancd.sock= com.apple.timed.plist L65d.sock= cydia.log MediaCache/ dumpdecrypted.dylib* RestoreFromBackupLock* launchd/ SpringBoard_reboot_flag mobile_assertion_agent.log com.apple.assistant.bundleservicecache.plist其中的HBGC.decrypted就是目标产物,接下来IDA各种斧头水果刀上吧。
$ xcrun -h Usage: xcrun [options] <tool name> ... arguments ... Find and execute the named command line tool from the active developer directory. The active developer directory can be set using `xcode-select`, or via the DEVELOPER_DIR environment variable. See the xcrun and xcode-select manual pages for more information. Options: -h, --help show this help message and exit --version show the xcrun version -v, --verbose show verbose logging output --sdk <sdk name> find the tool for the given SDK name --toolchain <name> find the tool for the given toolchain -l, --log show commands to be executed (with --run) -f, --find only find and print the tool path -r, --run find and execute the tool (the default behavior) -n, --no-cache do not use the lookup cache -k, --kill-cache invalidate all existing cache entries --show-sdk-path show selected SDK install path --show-sdk-version show selected SDK version --show-sdk-platform-path show selected SDK platform path --show-sdk-platform-version show selected SDK platform version
例如上面的Makefile中: GCC_BIN=`xcrun --sdk iphoneos --find gcc`
(1)xcrun --find gcc
$ xcrun --find gcc /Applications/Xcode 5.1.1.app/Contents/Developer/usr/bin/gcc这一步获取了gcc这个tool的路径,设为cmd_tool_path。
(2)xcrun --sdk iphoneos cmd_tool_path
再如: xcrun --sdk iphoneos --show-sdk-path
它的作用就是查找对应于iphoneos SDK的SDK并执行。
$ xcrun --show-sdk-path /Applications/Xcode 5.1.1.app/Contents/Developer/Platforms/MacOSX.platform/Developer/SDKs/MacOSX10.9.sdk $ xcrun --sdk iphoneos --show-sdk-path /Applications/Xcode 5.1.1.app/Contents/Developer/Platforms/iPhoneOS.platform/Developer/SDKs/iPhoneOS7.1.sdk
$ xcode-select -h Usage: xcode-select [options] Print or change the path to the active developer directory. This directory controls which tools are used for the Xcode command line tools (for example, xcodebuild) as well as the BSD development commands (such as cc and make). Options: -h, --help print this help message and exit -p, --print-path print the path of the active developer directory -s <path>, --switch <path> set the path for the active developer directory -v, --version print the xcode-select version -r, --reset reset to the default command line tools path
/Applications/Xcode 5.1.1.app/Contents/Developer
$ ls BuildStrings gcc ndisasm CpMac gcov-4.2 opendiff DeRez git projectInfo GetFileInfo git-cvsserver resolveLinks ImageUnitAnalyzer git-receive-pack scntool MergePef git-shell sdef MvMac git-upload-archive sdp ResMerger git-upload-pack svn Rez gnumake svnadmin RezDet hdxml2manxml svndumpfilter RezWack headerdoc2html svnlook SetFile ibtool svnrdump SplitForks ibtool3 svnserve TextureAtlas ibtoold svnsync UnRezWack ictool svnversion actool instruments symbols agvtool iprofiler xcodebuild amlint ld xcrun以上只是部分输出。