吾爱破解 - LCG - LSG |安卓破解|病毒分析|www.52pojie.cn

 找回密码
 注册[Register]

QQ登录

只需一步,快速开始

查看: 8528|回复: 18
收起左侧

[Android 原创] QQ安卓浏览器过签名验证方法.

  [复制链接]
Shizev 发表于 2018-3-11 17:43
本帖最后由 Shizev 于 2018-3-11 17:49 编辑



1.png 重新打包签名会出现这个,调用的是默认浏览器.











打开工具搜索  /mh?from=juggled      





双击进入,自己滑轮向上滑几下来到下面代码处.



[Java] 纯文本查看 复制代码
.method private static a(Ljava/lang/StringBuffer;)Z
    .locals 5

    const/4 v1, 0x0

    const/4 v0, 0x1

    :try_start_0
    invoke-static {}, Lcom/tencent/mtt/ContextHolder;->[color=#ff0000]getAppContex[/color]t()Landroid/content/Context;

    move-result-object v2

    if-nez v2, :cond_1

    :cond_0
    :goto_0
    return v0

    :cond_1
    invoke-virtual {v2}, Landroid/content/Context;->[color=#ff0000]getPackageName[/color]()Ljava/lang/String;

    move-result-object v3

    const/16 v4, 0x40

    invoke-static {v3, v2, v4}, Lcom/tencent/mtt/base/utils/s;->a(Ljava/lang/String;Landroid/content/Context;I)Landroid/content/pm/PackageInfo;

    move-result-object v2

    if-eqz v2, :cond_0

    iget-object v2, v2, Landroid/content/pm/PackageInfo;->[color=#ff0000]signatures:[/color][Landroid/content/pm/Signature;

    const-string/jumbo v3, ""

    if-eqz v2, :cond_0

    array-length v3, v2

    if-lez v3, :cond_0

    const/4 v3, 0x0

    aget-object v2, v2, v3

    invoke-virtual {v2}, Landroid/content/pm/Signature;->toCharsString()Ljava/lang/String;

    move-result-object v2

    if-eqz p0, :cond_2

    invoke-virtual {p0, v2}, Ljava/lang/StringBuffer;-[color=#ff0000]>append[/color](Ljava/lang/String;)Ljava/lang/StringBuffer;

    :cond_2
    if-eqz v2, :cond_3

    invoke-static {}, Lcom/tencent/mtt/boot/browser/f;->D()Ljava/lang/String;

    move-result-object v3

    invoke-virtual {v2, v3}, Ljava/lang/String;->equalsIgnoreCase(Ljava/lang/String;)Z
    :try_end_0
    .catch Ljava/lang/Exception; {:try_start_0 .. :try_end_0} :catch_0

    move-result v2

    if-nez v2, :cond_0

    :cond_3
    move v0, v1

    goto :goto_0

    :catch_0
    move-exception v1

    goto :goto_0
.end method

.method private d(I)V
    .locals 1

    iget-object v0, p0, Lcom/tencent/mtt/boot/browser/f;->a:Lcom/tencent/mtt/boot/browser/f$a;

    iput p1, v0, Lcom/tencent/mtt/boot/browser/f$a;->d:I

    return-void
.end method

.method public static g(Landroid/app/Activity;)V
    .locals 7

    new-instance v0, Ljava/lang/StringBuffer;

    invoke-direct {v0}, Ljava/lang/StringBuffer;-><init>()V

    invoke-static {v0}, Lcom/tencent/mtt/boot/browser/f;->a(Ljava/lang/StringBuffer;)Z

    move-result v1

    if-nez v1, :cond_0            [color=#ff00]  //if - nez V1,改为  goto      就好了.我也不懂代码.试了试这么改可以.我就这么写了.[/color]     

    const-string/jumbo v3, "android.intent.action.VIEW"

    const-string/jumbo v1,[color=#800080] [/color][color=#ffc0cb]"http://mdc.html5.qq.com/mh?from=juggled"
[/color]
    :try_start_0
    invoke-virtual {v0}, Ljava/lang/StringBuffer;->toString()Ljava/lang/String;

    move-result-object v2

    sget-object v0, Lcom/tencent/mtt/AppInfoHolder$AppInfoID;->APP_INFO_CURRENT_CHANNEL_ID:Lcom/tencent/mtt/AppInfoHolder$AppInfoID;

    invoke-static {v0}, Lcom/tencent/mtt/AppInfoHolder;->getAppInfoByID(Lcom/tencent/mtt/AppInfoHolder$AppInfoID;)Ljava/lang/String;

    move-result-object v4

    const-string/jumbo v5, ""

    const-string/jumbo v0, ""

    invoke-static {v2}, Landroid/text/TextUtils;->isEmpty(Ljava/lang/CharSequence;)Z

    move-result v6

    if-nez v6, :cond_1  [color=#ff0000]           [/color]

    invoke-static {v2}, Lcom/tencent/common/utils/Md5Utils;->getMD5(Ljava/lang/String;)Ljava/lang/String;     
    move-result-object v0

    move-object v2, v0

    :goto_0
    new-instance v0, Ljava/lang/StringBuilder;

    invoke-direct {v0}, Ljava/lang/StringBuilder;-><init>()V

    const-string/jumbo v6,[color=#ff0000] "http://mdc.html5.qq.com/mh?from=juggled&version=8.2&buildid=3950&channel="[/color]

    invoke-virtual {v0, v6}, Ljava/lang/StringBuilder;->append(Ljava/lang/String;)Ljava/lang/StringBuilder;

    move-result-object v0

    invoke-virtual {v0, v4}, Ljava/lang/StringBuilder;->append(Ljava/lang/String;)Ljava/lang/StringBuilder;

    move-result-object v0

    const-string/jumbo v4, "[color=#ff0000]&devicename="[/color]

    invoke-virtual {v0, v4}, Ljava/lang/StringBuilder;->append(Ljava/lang/String;)Ljava/lang/StringBuilder;

    move-result-object v0

    sget-object v4, Landroid/os/Build;->MODEL:Ljava/lang/String;

    invoke-virtual {v4}, Ljava/lang/String;->trim()Ljava/lang/String;

    move-result-object v4

    invoke-virtual {v4}, Ljava/lang/String;->toLowerCase()Ljava/lang/String;

    move-result-object v4

    invoke-virtual {v0, v4}, Ljava/lang/StringBuilder;->append(Ljava/lang/String;)Ljava/lang/StringBuilder;

    move-result-object v0

    const-string/jumbo v4, [color=#ff0000]"&sdkversion=[/color]"

    invoke-virtual {v0, v4}, Ljava/lang/StringBuilder;->append(Ljava/lang/String;)Ljava/lang/StringBuilder;

    move-result-object v0

    invoke-static {}, Lcom/tencent/mtt/base/utils/g;->y()I

    move-result v4

    invoke-virtual {v0, v4}, Ljava/lang/StringBuilder;->[color=#ff0000]append([/color]I)Ljava/lang/StringBuilder;

    move-result-object v0

    const-string/jumbo v4, [color=#ff0000]"&lc="[/color]

    invoke-virtual {v0, v4}, Ljava/lang/StringBuilder;->append(Ljava/lang/String;)Ljava/lang/StringBuilder;

    move-result-object v4

    invoke-static {}, Lcom/tencent/mtt/qbcontext/core/QBContext;->a()Lcom/tencent/mtt/qbcontext/core/QBContext;

    move-result-object v0

    const-class v6, Lcom/tencent/mtt/businesscenter/facade/IConfigService;

    invoke-virtual {v0, v6}, Lcom/tencent/mtt/qbcontext/core/QBContext;->a(Ljava/lang/Class;)Ljava/lang/Object;

    move-result-object v0

    check-cast v0, Lcom/tencent/mtt/businesscenter/facade/IConfigService;

    invoke-interface {v0}, Lcom/tencent/mtt/businesscenter/facade/IConfigService;->getLC()Ljava/lang/String;

    move-result-object v0

    invoke-virtual {v4, v0}, Ljava/lang/StringBuilder;->append(Ljava/lang/String;)Ljava/lang/StringBuilder;

    move-result-object v0

    const-string/jumbo v4, "[color=#ff0000]&keymd5="[/color]

    invoke-virtual {v0, v4}, Ljava/lang/StringBuilder;->append(Ljava/lang/String;)Ljava/lang/StringBuilder;

    move-result-object v0

    invoke-virtual {v0, v2}, Ljava/lang/StringBuilder;->append(Ljava/lang/String;)Ljava/lang/StringBuilder;

    move-result-object v0

    const-string/jumbo v2, "[color=#ff0000]&imei=[/color]"

    invoke-virtual {v0, v2}, Ljava/lang/StringBuilder;->append(Ljava/lang/String;)Ljava/lang/StringBuilder;

    move-result-object v0

    invoke-virtual {v0, v5}, Ljava/lang/StringBuilder;->append(Ljava/lang/String;)Ljava/lang/StringBuilder;

    move-result-object v0

    invoke-virtual {v0}, Ljava/lang/StringBuilder;->toString()Ljava/lang/String;
    :try_end_0
    .catch Ljava/lang/Exception; {:try_start_0 .. :try_end_0} :catch_0

    move-result-object v0

    :try_start_1
    invoke-static {v0}, Landroid/net/Uri;->parse(Ljava/lang/String;)Landroid/net/Uri;

    move-result-object v1

    new-instance v2, Landroid/content/Intent;

    invoke-direct {v2}, Landroid/content/Intent;-><init>()V

    if-eqz v1, :cond_0

    invoke-static {v3}, Landroid/text/TextUtils;-[color=#ff0000]>isEmpty([/color]Ljava/lang/CharSequence;)Z

    move-result v4

    if-nez v4, :cond_0

    invoke-virtual {v2, v3}, Landroid/content/Intent;->setAction(Ljava/lang/String;)Landroid/content/Intent;

    invoke-virtual {v2, v1}, Landroid/content/Intent;->setData(Landroid/net/Uri;)Landroid/content/Intent;

    const-string/jumbo v1, "com.android.browser"

    const-string/jumbo v4, "com.android.browser.BrowserActivity"

    invoke-virtual {v2, v1, v4}, Landroid/content/Intent;->setClassName(Ljava/lang/String;Ljava/lang/String;)Landroid/content/Intent;

    invoke-virtual {p0, v2}, Landroid/app/Activity;->startActivity(Landroid/content/Intent;)V

    invoke-virtual {p0}, Landroid/app/Activity;->finish()V

    invoke-static {}, Lcom/tencent/mtt/base/utils/e;->c()V
    :try_end_1
    .catch Ljava/lang/Exception; {:try_start_1 .. :try_end_1} :catch_2

[color=#000000]    :cond_0                                                    [/color]
    :goto_1
    return-void

    :catch_0
    move-exception v0

    move-object v0, v1

    :goto_2
    :try_start_2
    invoke-static {v0}, Landroid/net/Uri;->parse(Ljava/lang/String;)Landroid/net/Uri;

    move-result-object v0

    if-eqz v0, :cond_0

    invoke-static {v3}, Landroid/text/TextUtils;->isEmpty(Ljava/lang/CharSequence;)Z

    move-result v1

    if-nez v1, :cond_0

    new-instance v1, Landroid/content/Intent;

    invoke-direct {v1}, Landroid/content/Intent;-><init>()V

    invoke-virtual {v1, v3}, Landroid/content/Intent;->setAction(Ljava/lang/String;)Landroid/content/Intent;

    invoke-virtual {v1, v0}, Landroid/content/Intent;->setData(Landroid/net/Uri;)Landroid/content/Intent;

    invoke-virtual {p0, v1}, Landroid/app/Activity;->startActivity(Landroid/content/Intent;)V

    invoke-virtual {p0}, Landroid/app/Activity;->finish()V

    invoke-static {}, Lcom/tencent/mtt/base/utils/e;->c()V
    :try_end_2
    .catch Ljava/lang/Exception; {:try_start_2 .. :try_end_2} :catch_1

    goto :goto_1

    :catch_1
    move-exception v0

    goto :goto_1

    :catch_2
    move-exception v1

    goto :goto_2

    :cond_1    
    move-object v2, v0

    goto/16 :goto_0
.end method

免费评分

参与人数 6吾爱币 +8 热心值 +6 收起 理由
小婊砸 + 1 + 1 我很赞同!
qtfreet00 + 3 + 1 感谢发布原创作品,吾爱破解论坛因你更精彩!
寒蝉鸣泣之时 + 1 + 1 热心回复!
vae3489 + 1 + 1 谢谢@Thanks!
缘木求鱼啦 + 1 + 1 热心回复!
tail88 + 1 + 1 鼓励转贴优秀软件安全工具和文档!

查看全部评分

发帖前要善用论坛搜索功能,那里可能会有你要找的答案或者已经有人发布过相同内容了,请勿重复发帖。

北岛未 发表于 2018-3-12 00:31
感谢楼主教程
栀鸳 发表于 2018-3-12 01:41
我才不是狮子喵 发表于 2018-3-12 08:44
江湖传说 发表于 2018-3-12 09:05
感谢楼主分享,这个会不会被人用来做坏事
fuirtst 发表于 2018-3-12 09:42
好东西,感谢分享。。。。
vae3489 发表于 2018-3-12 11:02
学习了,这个办法好啊
漠北左左 发表于 2018-3-12 13:41
非常好的教程,应该很多读者都喜欢,谢谢分享!
df4528 发表于 2018-3-12 14:03
好长一段代码。。。。没耐心看完了,只改了一个判断语句么?
字母 发表于 2018-3-12 15:38
看起来有点意思  先研究一波去
感谢分享
您需要登录后才可以回帖 登录 | 注册[Register]

本版积分规则 警告:本版块禁止灌水或回复与主题无关内容,违者重罚!

快速回复 收藏帖子 返回列表 搜索

RSS订阅|小黑屋|处罚记录|联系我们|吾爱破解 - LCG - LSG ( 京ICP备16042023号 | 京公网安备 11010502030087号 )

GMT+8, 2024-4-24 20:52

Powered by Discuz!

Copyright © 2001-2020, Tencent Cloud.

快速回复 返回顶部 返回列表