meid写入工具_业务安全之典型安卓改机工具分析

本文分析了一款安卓改机工具的工作原理,该工具通过刷指定ROM并修改设备参数实现改机。工具涉及root授权、备份还原、Build/prop改机等多个环节,主要通过SystemProperties.set反射调用修改设备信息。改机痕迹涉及kernel、framework和native libraries,尽管覆盖面广,但维护成本高,为检测提供了挑战。
摘要由CSDN通过智能技术生成
本文主角为一款安卓改机工具, 微?改机 ,这款改机工具去年我们就见过,这一年多的时间已经发展到具有一定的用户规模了。

13a0235b386b242c9a88f8f89bf92573.png

从最初的QQ群打广告,到现在有三个品牌(VS*师、悟*宝、新微?),6个商务,1300+帖子的论坛,3000+用户的社交群组,很明显过去这一年多,微?的小日子过得还挺舒服的…建议各家公司早日盯上它…

7f5dccda613c928700cafe8d25939205.png

抓包分析

这款改机工具与传统的改机工具不太一样,需要先刷指定的ROM,再通过改机工具修改指定的参数。通过抓包解密,我们拿到了其改机相关的数据,相关字段有80多个,主要是设备中需要修改的数据。

抓包解密字段:

{
    
"accountPassword":"",
"androidId":"",
"androidVer":"",
"api":"",
"appInstallTime":"",
"appPackages":"",
"arpMac":"",
"backupFileName":"",
"board":"",
"bootId":"",
"brand":"",
"bssId":"",
"carrier":"=",
"carrierCode":"",
"constructDate":"",
"coreNumber":,
"countryCode":""
"cpuInfo":"",
"cupFile":"",
"dayNumber":,
"density":,
"description":"",
"device":"",
"deviceFile":"",
"deviceFileVersion":"",
"deviceVersion":"",
"display":"",
"dpi":,
"dummy0MAC":"",
"fingerprint":"",
"fromDayNumber":,
"getIp":,
"gjIso":"",
"glRenderer":"",
"glVendor":"",
"hardware":"",
"height":,
"id":,
"imei":"",
"imei1":"",
"imsi":"",
"ipv6":"",
"lat":,
"log":,
"lymac":"",
"manufacture":"",
"meid":"",
"model":"",
"networkInfoType":,
"networkTor":"",
"networkType":,
"newAdd":,
"p2p0MAC":"",
"pathMessage":"",
"phoneNumber":"",
"phoneType":,
"product":"",
"recoveryId0":"",
"recoveryId1":"",
"remainDevice":"",
"scaledDensity":,
"sdCardCid0":"",
"sdCardCid1":"",
"serial":"",
"simSerial":"",
"simState":,
"simopeName":"",
"survivalVersion":"",
"taskId":"",
"taskSubId":"",
"time":,
"type":,
"updateTime":"",
"used":,
"versionId":"",
"whereDay":,
"width":,
"wifiMac":"",
"wifiName":"",

  • 0
    点赞
  • 2
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值