{"id":13434569,"url":"https://github.com/halfkiss/ZjDroid","last_synced_at":"2025-03-17T19:31:00.762Z","repository":{"id":44454379,"uuid":"22253361","full_name":"halfkiss/ZjDroid","owner":"halfkiss","description":"Android app dynamic reverse tool based on Xposed framework.","archived":false,"fork":false,"pushed_at":"2014-07-25T10:22:41.000Z","size":13911,"stargazers_count":1006,"open_issues_count":0,"forks_count":624,"subscribers_count":73,"default_branch":"master","last_synced_at":"2024-10-27T16:10:47.819Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":null,"has_issues":false,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/halfkiss.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2014-07-25T10:30:31.000Z","updated_at":"2024-10-19T04:17:18.000Z","dependencies_parsed_at":"2022-09-21T18:20:25.567Z","dependency_job_id":null,"html_url":"https://github.com/halfkiss/ZjDroid","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/halfkiss%2FZjDroid","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/halfkiss%2FZjDroid/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/halfkiss%2FZjDroid/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/halfkiss%2FZjDroid/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/halfkiss","download_url":"https://codeload.github.com/halfkiss/ZjDroid/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":244096713,"owners_count":20397468,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-07-31T03:00:17.726Z","updated_at":"2025-03-17T19:30:59.597Z","avatar_url":"https://github.com/halfkiss.png","language":null,"funding_links":[],"categories":["Xposed","Others"],"sub_categories":["Utility"],"readme":"ZjDroid\n=======\n\nAndroid app dynamic reverse tool based on Xposed framework.\n\n\n一、ZjDroid工具介绍\n\nZjDroid是基于Xposed Framewrok的动态逆向分析模块，逆向分析者可以通过ZjDroid完成以下工作：\n1、DEX文件的内存dump\n2、基于Dalvik关键指针的内存BackSmali，有效破解主流加固方案\n3、敏感API的动态监控\n4、指定内存区域数据dump\n5、获取应用加载DEX信息。\n6、获取指定DEX文件加载类信息。\n7、dump Dalvik java堆信息。\n8、在目标进程动态运行lua脚本。\n\n\n二、ZjDroid相关命令\n\n1、获取APK当前加载DEX文件信息：\nadb shell am broadcast -a com.zjdroid.invoke --ei target pid --es cmd '{\"action\":\"dump_dexinfo\"}'\n\n2、获取指定DEX文件包含可加载类名：\nadb shell am broadcast -a com.zjdroid.invoke --ei target pid --es cmd '{\"action\":\"dump_class\",\"dexpath\":\"*****\"}'\n\n4、根据Dalvik相关内存指针动态反编译指定DEX，并以文件形式保存。\nadb shell am broadcast -a com.zjdroid.invoke --ei target pid --es cmd '{\"action\":\"backsmali\",\"dexpath\":\"*****\"}'\n\n该方式可以脱壳目前大部分流行的加固防护。(由于手机性能问题，运行较忙)\n例外情况：\n由于ApkProtect特定防修改检测，需要做如下修改即可解固该保护：\n（1）在设备上创建特定目录（如/data/local）并 chmod 为777\n（2）复制zjdroid.apk到该目录，并修改文件名为zjdroid.jar\n (3) 修改/data/data/de.robv.android.xposed.installer/conf/modules.list 模块代码文件修改为\"zjdroid.jar\"\n从启设备即可。\n\n5、Dump指定DEX内存中的数据并保存到文件（数据为odex格式，可在pc上反编译）。\nadb shell am broadcast -a com.zjdroid.invoke --ei target pid --es cmd '{\"action\":\"dump_dex\",\"dexpath\":\"*****\"}'\n\n\n6、Dump指定内存空间区域数据到文件\nadb shell am broadcast -a com.zjdroid.invoke --ei target pid --es cmd '{\"action\":\"dump_mem\",\"start\":1234567,\"length\":123}'\n\n7、Dump Dalvik堆栈信息到文件，文件可以通过java heap分析工具分析处理。\nadb shell am broadcast -a com.zjdroid.invoke --ei target pid --es cmd '{\"action\":\"dump_heap\"}'\n\n8、运行时动态调用Lua脚本\n该功能可以通过Lua脚本动态调用java代码。\n使用场景：\n可以动态调用解密函数，完成解密。\n可以动态触发特定逻辑。\nadb shell am broadcast -a com.zjdroid.invoke --ei target pid --es cmd '{\"action\":\"invoke\",\"filepath\":\"****\"}'\n\nluajava相关使用方法：\nhttp://www.keplerproject.org/luajava/\n\n8、敏感API调用监控\n\n\n三、相关命令执行结果查看：\n\n1、命令执行结果：\nadb shell logcat -s zjdroid-shell-{package name}\n\n2、敏感API调用监控输出结果：\nadb shell logcat -s zjdroid-apimonitor-{package name}\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fhalfkiss%2FZjDroid","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fhalfkiss%2FZjDroid","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fhalfkiss%2FZjDroid/lists"}