From 4c6a6d8da7c50b2ef5816c0ee1a4efd99d542ab3 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E2=96=84=EF=B8=BB=E3=83=87A=2ES=CE=B1=C9=B1=CE=B9=C9=BE?= =?UTF-8?q?=E2=95=90=E2=95=90=E2=94=81=E4=B8=80?= <110791478+cTFk1ller@users.noreply.github.com> Date: Wed, 5 Jul 2023 10:01:27 +0300 Subject: [PATCH 1/2] Updated script to find and attach to open processes without reopening the application This commit includes changes to the script that enable it to locate and attach to open processes without the need to reopen the application. Instead of relying on the script to specifically target a predefined application, it now searches for any open applications and attaches to the appropriate one. This enhancement improves the script's flexibility and efficiency, allowing it to seamlessly interact with different processes without requiring manual intervention. --- __pycache__/dumper.cpython-310.pyc | Bin 0 -> 1114 bytes __pycache__/utils.cpython-310.pyc | Bin 0 -> 1368 bytes dumper.py | 4 ++-- fridump.py | 14 ++++++++++++-- utils.py | 1 + 5 files changed, 15 insertions(+), 4 deletions(-) create mode 100644 __pycache__/dumper.cpython-310.pyc create mode 100644 __pycache__/utils.cpython-310.pyc diff --git a/__pycache__/dumper.cpython-310.pyc b/__pycache__/dumper.cpython-310.pyc new file mode 100644 index 0000000000000000000000000000000000000000..8c866bb1d8d0b0f8a82a4ff609bf9b6da3d9a960 GIT binary patch literal 1114 zcmYjQO>fgc5Zzs`9Vboc2b7i%fm^{LsA}#NLWq`YIrM-iLXqR$ByMf5S#R1Vau8BD z@H1M83;d)#!l~jPAc2^1Xz5z}W_CRDJoX!_`S}Kc_4CCS@y#XV2Oh3328ZXci$?&0 z2%3oR!SOwW0c>{e<{15*AKYKz?NXy+DH#%aN=362(p=BrCvGaEQ-T1*P zl^2^qDpRFLK^R4{D1zfyC83E`w%%%5r!d;iX&H*nEX#70%gi!WSe}PwVELhnGwYt{ z*huR}i7KS6zdVg(jvTg@sD3}r`qmY)I|P&KI5Vxfb;G{QjOE=B3V0EZp;~IKw5^L+ z%g8`W*6+oM%)%5huzgE=mddY0uff;-^|(DyscgrlKOD7pWpQLw-tOrbGusGKZ{;J~ zM7Lv92e~}d<}LuEO}K8+2KA{&Z_s71i`4(fervoPVdCXNVQa7}VZVb@veLOnCLY?` z1f>)7i0L&05({Qn=?Q0*Tnd!c|Hm(5#wlSerYz*f1>c*(nCy~w4<~+=%V9u3)Kwzf zRf2wbjn8-`!3Yk|)P(`4?uPvRX4QwI)fGn#S+4QGxvXJlSAER5YL{FB1`c=2+tU=@ zbiA}TOuJGCsux6qVRlq(UsUntet0Z{?#ReuI~aR`iIXH~`ML>3dLF?6unvfA{b;B= zmCmjXv%ajpuyqFVv{ly&n7fFugav*Yo_25=^fJb7V$3yhDq-G4-0NA6hiU+3aHpy& z@+3A!>J>N@_W^v+)2C~6nKjrV+W>7rY4!vZ=YKT*<}I#K<5|Nfc@@1zj5DTZ>`zlA RhKYQJZ(jHSKJxSC!e8=!2weaG literal 0 HcmV?d00001 diff --git a/__pycache__/utils.cpython-310.pyc b/__pycache__/utils.cpython-310.pyc new file mode 100644 index 0000000000000000000000000000000000000000..4e9908059994096d65362f2bef616b21b363b318 GIT binary patch literal 1368 zcmZ8h-D(?06rMBttF@%KK}|xFwrW#Rmg1;}UWGOUl0q+vDWp&$W895qB(J^NRcA&d z7NZhSZcAQ4g5LD9FVY8?+g|w<3{85@T5e5dIR9tP&dhgat5z#vIF^ro7k~PU{Y}Qz z;i2&mN&kpUFaZS{Tu2x|ZSw)Ir8n?u=?{FAya*=YAOt2_A{5ap7(}8i8X`e07F(kE ziVYe9p0M=V8CGU{DLB8H%F?kjj`o>AHVi4W88J$tM@af5GQ$kmz_JcA+`h+t1@N~66oZUe{Dhv#tj9Cqg0J>A{!>4R=hqt?@{bLcrp(%5-H$8Q&`lCOnYOJKz4P2N(4Ji}gLLu!u8LHR^AJb$5L z*fFdS7y)a(@GdRO(DIFkpwK1z))!oOzwy`KA{@agL@3d= z0`pxP^MAgYPdNzod`laIWvuU+7iJ!PpP9Ve*~Pw%WjU+_M&{9ecjwoGFPMW&(PgAf z$1CmpX=aX`e_Z9IdJo--I^1z3T{Ox|krjpWmCS_m3VZ-jQH{q~%>_a}n~l{qD%5Z> zqASa6B3(n|N)An>PMtT&OV`}&>yR?kCsaGkOEO%Hp~E8A#&INUHabAv6c_9^B}bd} z9W-chVxI~s9j7N(jhJf=>bxW{&iFg{wgf~2Jm6} z7f&Yj_U7;JSLGo#w9dxzpu17-&jXQ}?0yRM<)qw2n~3u%@a}e#|7*}$HGTU!sIO3@ zzM`JIVAP_DHid;hB$22VxxOU!Ik7IWyT}~Rs~VKLx$EQA^{#xH9+IlBEB<;?iCG~Z V0J=0CHfAy26HUA;FWG9g{so1SK5zg4 literal 0 HcmV?d00001 diff --git a/dumper.py b/dumper.py index 3e04e0e..4e580c0 100644 --- a/dumper.py +++ b/dumper.py @@ -21,7 +21,7 @@ def dump_to_file(agent,base,size,error,directory): def splitter(agent,base,size,max_size,error,directory): times = size/max_size diff = size % max_size - if diff is 0: + if diff == 0: logging.debug("Number of chunks:"+str(times+1)) else: logging.debug("Number of chunks:"+str(times)) @@ -33,7 +33,7 @@ def splitter(agent,base,size,max_size,error,directory): dump_to_file(agent, cur_base, max_size, error, directory) cur_base = cur_base + max_size - if diff is not 0: + if diff != 0: logging.debug("Save bytes: "+str(hex(cur_base))+" till "+str(hex(cur_base+diff))) dump_to_file(agent, cur_base, diff, error, directory) diff --git a/fridump.py b/fridump.py index e9a5dc2..a986cff 100644 --- a/fridump.py +++ b/fridump.py @@ -57,6 +57,7 @@ def MENU(): STRINGS = arguments.strings MAX_SIZE = 20971520 PERMS = 'rw-' +pid = 0 if arguments.read_only: PERMS = 'r--' @@ -69,11 +70,20 @@ def MENU(): # Start a new Session session = None try: + for a in frida.get_usb_device().enumerate_applications(): + if a.identifier == APP_NAME: + pid = a.pid + print(f"[+] Woo I found the process id : {pid}") + break + if USB: - session = frida.get_usb_device().attach(APP_NAME) + session = frida.get_usb_device().attach(pid) + print(session) else: - session = frida.attach(APP_NAME) + session = frida.attach(pid) + except Exception as e: + print(e) print("Can't connect to App. Have you connected the device?") logging.debug(str(e)) sys.exit() diff --git a/utils.py b/utils.py index be6c0f6..ccb285d 100644 --- a/utils.py +++ b/utils.py @@ -20,6 +20,7 @@ def printProgress (times, total, prefix ='', suffix ='', decimals = 2, bar = 100 def strings(filename, directory, min=4): strings_file = os.path.join(directory, "strings.txt") path = os.path.join(directory, filename) + print(path) with open(path, encoding='Latin-1') as infile: str_list = re.findall("[\x20-\x7E]+\x00", infile.read()) with open(strings_file, "a") as st: From 1edb041ee72da506254938eea5d6177367883be5 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E2=96=84=EF=B8=BB=E3=83=87A=2ES=CE=B1=C9=B1=CE=B9=C9=BE?= =?UTF-8?q?=E2=95=90=E2=95=90=E2=94=81=E4=B8=80?= <110791478+cTFk1ller@users.noreply.github.com> Date: Wed, 5 Jul 2023 11:18:28 +0300 Subject: [PATCH 2/2] adding the -p for direct addition of the process ID and changing the name of the process to app-name. --- fridump.py | 44 ++++++++++++++++++++++++-------------------- 1 file changed, 24 insertions(+), 20 deletions(-) diff --git a/fridump.py b/fridump.py index a986cff..e96113e 100644 --- a/fridump.py +++ b/fridump.py @@ -27,8 +27,7 @@ def MENU(): formatter_class=argparse.RawDescriptionHelpFormatter, description=textwrap.dedent("")) - parser.add_argument('process', - help='the process that you will be injecting to') + parser.add_argument('-A', '--appname', help='the application name that you will be injecting to', required=False) parser.add_argument('-o', '--out', type=str, metavar="dir", help='provide full output directory path. (def: \'dump\')') parser.add_argument('-U', '--usb', action='store_true', @@ -39,6 +38,7 @@ def MENU(): help="dump read-only parts of memory. More data, more errors") parser.add_argument('-s', '--strings', action='store_true', help='run strings on all dump files. Saved in output dir.') + parser.add_argument('-p', '--pid', help='attach direct to a process id', required=False) parser.add_argument('--max-size', type=int, metavar="bytes", help='maximum size of dump file in bytes (def: 20971520)') args = parser.parse_args() @@ -50,7 +50,7 @@ def MENU(): arguments = MENU() # Define Configurations -APP_NAME = arguments.process +APP_NAME = arguments.appname DIRECTORY = "" USB = arguments.usb DEBUG_LEVEL = logging.INFO @@ -70,21 +70,25 @@ def MENU(): # Start a new Session session = None try: - for a in frida.get_usb_device().enumerate_applications(): - if a.identifier == APP_NAME: - pid = a.pid - print(f"[+] Woo I found the process id : {pid}") - break - + if arguments.pid is not None: + pid = arguments.pid + pass + else: + for a in frida.get_usb_device().enumerate_applications(): + if a.identifier == APP_NAME: + pid = a.pid + break + pass + + print(f"[+] attaching to process with Id of {pid}") if USB: - session = frida.get_usb_device().attach(pid) - print(session) + session = frida.get_usb_device().attach(int(pid)) else: - session = frida.attach(pid) + session = frida.attach(int(pid)) except Exception as e: print(e) - print("Can't connect to App. Have you connected the device?") + print("[-] Can't connect to App. Have you connected the device?") logging.debug(str(e)) sys.exit() @@ -93,22 +97,22 @@ def MENU(): if arguments.out is not None: DIRECTORY = arguments.out if os.path.isdir(DIRECTORY): - print("Output directory is set to: " + DIRECTORY) + print("[*] Output directory is set to: " + DIRECTORY) else: - print("The selected output directory does not exist!") + print("[*] The selected output directory does not exist!") sys.exit(1) else: - print("Current Directory: " + str(os.getcwd())) + print("[*] Current Directory: " + str(os.getcwd())) DIRECTORY = os.path.join(os.getcwd(), "dump") - print("Output directory is set to: " + DIRECTORY) + print("[*] Output directory is set to: " + DIRECTORY) if not os.path.exists(DIRECTORY): - print("Creating directory...") + print("[*] Creating directory...") os.makedirs(DIRECTORY) mem_access_viol = "" -print("Starting Memory dump...") +print("[+] Starting Memory dump...") script = session.create_script( """'use strict'; @@ -126,7 +130,7 @@ def MENU(): script.on("message", utils.on_message) script.load() -agent = script.exports +agent = script.exports_sync ranges = agent.enumerate_ranges(PERMS) if arguments.max_size is not None: