gengjf / dingtalkdylib Goto Github PK
View Code? Open in Web Editor NEW非越狱环境劫持app的GPS和WIFI信息
非越狱环境劫持app的GPS和WIFI信息
您好,大神,我目前在注入动态库到钉钉(分享逍客)的时候,会闪退,但是 此动态库在其他 app 注入的时候都是可以正常运行,是否因为钉钉做了防止动态注入的保护 我一直卡顿在这里,不知道您是否有遇见过,如果有的话可否指点小弟一下
按照文档执行了以下命令
./insert_dylib @executable_path/libDingTalkDylib.dylib DingTalk.app/DingTalk
代码里JFBundleIdentifier设成了*
然后用 iOS App Signer 改了签名,使用了com.ding.iphone,安装到iPhone上闪退
Last Exception Backtrace:
0 CoreFoundation 0x1812dfd38 __exceptionPreprocess + 124
1 libobjc.A.dylib 0x1807f4528 objc_exception_throw + 55
2 CoreFoundation 0x1812dfc80 +[NSException raise:format:] + 115
3 Foundation 0x181c61990 -[NSData+ 653712 (NSData) initWithContentsOfFile:options:maxLength:error:] + 111
4 DingTalk 0x106e179bc 0x104e58000 + 33290684
5 DingTalk 0x106e17d60 0x104e58000 + 33291616
6 DingTalk 0x10547fcfc 0x104e58000 + 6454524
7 DingTalk 0x105b09778 0x104e58000 + 13309816
8 DingTalk 0x105b09530 0x104e58000 + 13309232
9 libDingTalkDylib.dylib 0x109102874 -[UIResponder(JFUtil) jf_application:didFinishLaunchingWithOptions:] + 43124 (UIResponder+JFUtil.m:29)
10 UIKit 0x18a75f050 -[UIApplication _handleDelegateCallbacksWithOptions:isSuspended:restoreState:] + 383
11 UIKit 0x18a952898 -[UIApplication _callInitializationDelegatesForMainScene:transitionContext:] + 3427
12 UIKit 0x18a9576e4 -[UIApplication _runWithMainScene:transitionContext:completion:] + 1711
13 UIKit 0x18abe5454 __111-[__UICanvasLifecycleMonitor_Compatability _scheduleFirstCommitForScene:transition:firstActivation:completion:]_block_invoke + 799
14 UIKit 0x18aeb51f0 +[_UICanvas _enqueuePostSettingUpdateTransactionBlock:] + 159
15 UIKit 0x18abe50b8 -[__UICanvasLifecycleMonitor_Compatability _scheduleFirstCommitForScene:transition:firstActivation:completion:] + 251
16 UIKit 0x18abe5928 -[__UICanvasLifecycleMonitor_Compatability activateEventsOnly:withContext:completion:] + 747
17 UIKit 0x18b34e6e8 __82-[_UIApplicationCanvas _transitionLifecycleStateWithTransitionContext:completion:]_block_invoke + 259
18 UIKit 0x18b34e58c -[_UIApplicationCanvas _transitionLifecycleStateWithTransitionContext:completion:] + 447
19 UIKit 0x18b0ca9c0 __125-[_UICanvasLifecycleSettingsDiffAction performActionsForCanvas:withUpdatedScene:settingsDiff:fromSettings:transitionContext:]_block_invoke + 219
20 UIKit 0x18b25ffc8 _performActionsWithDelayForTransitionContext + 111
21 UIKit 0x18b0ca870 -[_UICanvasLifecycleSettingsDiffAction performActionsForCanvas:withUpdatedScene:settingsDiff:fromSettings:transitionContext:] + 251
22 UIKit 0x18aeb4850 -[_UICanvas scene:didUpdateWithDiff:transitionContext:completion:] + 363
23 UIKit 0x18a955e28 -[UIApplication workspace:didCreateScene:withTransitionContext:completion:] + 539
24 UIKit 0x18ad596ec -[UIApplicationSceneClientAgent scene:didInitializeWithEvent:completion:] + 363
25 FrontBoardServices 0x183981768 -[FBSSceneImpl _didCreateWithTransitionContext:completion:] + 363
26 FrontBoardServices 0x18398a070 __56-[FBSWorkspace client:handleCreateScene:withCompletion:]_block_invoke_2 + 223
27 libdispatch.dylib 0x180c65048 _dispatch_client_callout + 15
28 libdispatch.dylib 0x180c6c6c8 _dispatch_block_invoke_direct$VARIANT$mp + 287
29 FrontBoardServices 0x1839b5a04 FBSSERIALQUEUE_IS_CALLING_OUT_TO_A_BLOCK + 35
30 FrontBoardServices 0x1839b56a8 -[FBSSerialQueue _performNext] + 403
31 FrontBoardServices 0x1839b5c44 -[FBSSerialQueue _performNextFromRunLoopSource] + 55
32 CoreFoundation 0x181288358 CFRUNLOOP_IS_CALLING_OUT_TO_A_SOURCE0_PERFORM_FUNCTION + 23
33 CoreFoundation 0x1812882d8 __CFRunLoopDoSource0 + 87
34 CoreFoundation 0x181287b60 __CFRunLoopDoSources0 + 203
35 CoreFoundation 0x181285738 __CFRunLoopRun + 1047
36 CoreFoundation 0x1811a62d8 CFRunLoopRunSpecific + 435
37 GraphicsServices 0x183037f84 GSEventRunModal + 99
38 UIKit 0x18a753880 UIApplicationMain + 207
39 DingTalk 0x105153664 0x104e58000 + 3126884
40 libdyld.dylib 0x180cca56c start + 3
Thread 0 name: 994 Dispatch queue: com.apple.main-thread
Thread 0 Crashed:
0 libsystem_kernel.dylib 0x0000000180df9348 __pthread_kill + 8
1 libsystem_pthread.dylib 0x0000000180f0d354 pthread_kill$VARIANT$mp + 396
2 libsystem_c.dylib 0x0000000180d68fd8 abort + 140
3 DingTalk 0x00000001066b0d78 0x104e58000 + 25529720
4 CoreFoundation 0x00000001812e00ac __handleUncaughtException + 628
5 libobjc.A.dylib 0x00000001807f4804 _objc_terminate+ 34820 () + 112
6 libc++abi.dylib 0x00000001807e454c std::__terminate(void (*)+ 107852 ()) + 16
7 libc++abi.dylib 0x00000001807e45b8 std::terminate+ 107960 () + 60
8 libdispatch.dylib 0x0000000180c6505c _dispatch_client_callout + 36
9 libdispatch.dylib 0x0000000180c6c6c8 _dispatch_block_invoke_direct$VARIANT$mp + 288
10 FrontBoardServices 0x00000001839b5a04 FBSSERIALQUEUE_IS_CALLING_OUT_TO_A_BLOCK + 36
11 FrontBoardServices 0x00000001839b56a8 -[FBSSerialQueue _performNext] + 404
12 FrontBoardServices 0x00000001839b5c44 -[FBSSerialQueue _performNextFromRunLoopSource] + 56
13 CoreFoundation 0x0000000181288358 CFRUNLOOP_IS_CALLING_OUT_TO_A_SOURCE0_PERFORM_FUNCTION + 24
14 CoreFoundation 0x00000001812882d8 __CFRunLoopDoSource0 + 88
15 CoreFoundation 0x0000000181287b60 __CFRunLoopDoSources0 + 204
16 CoreFoundation 0x0000000181285738 __CFRunLoopRun + 1048
17 CoreFoundation 0x00000001811a62d8 CFRunLoopRunSpecific + 436
18 GraphicsServices 0x0000000183037f84 GSEventRunModal + 100
19 UIKit 0x000000018a753880 UIApplicationMain + 208
20 DingTalk 0x0000000105153664 0x104e58000 + 3126884
21 libdyld.dylib 0x0000000180cca56c start + 4
IOS 11,钉钉3.5.3环境下,照片替换功能失效了,老大能不能辛苦更新下代码啊?
现在哪里还有这种泛型证书,不是企业证书么
我这边,有公司账号,我自己重新签名即可。
3.4.10版本的钉钉不行了
帮我指点一下
现在因为改了定位,导致每次一进钉钉就自动急速打卡了。。有的时候并不想打卡都自动打了 很是蛋疼,有办法搞一下吗?我能力有限 试了下不行
如题 第一次用钉钉,点了考勤打卡 就急速打卡了。没找到哪边设置坐标啊
在越狱环境下,是否有更简单的方式呢?
求3.5.1或者3.4.N版本的钉钉ipa去壳文件,[email protected],感谢
给踢出到,登录页面,是签名的问题吗?
系统版本:iOS10.3.1,钉钉3.4.11
直接注入钉钉,设置按钮没有出现。
修改了初始化代码,延时60秒加载设置按钮,按钮就出现了。
GPS功能测试成功,但是签到设置图片设置了,拍摄没有替换,能帮忙看看嘛?
文档里没有啊
新版的钉钉(4.2.0)在打卡时候会提示,“你正在使用非官方版钉钉,无法进行打开。请到应用市场重新下载” 请问这个问题怎么解决
请教下 “因此最好的防止被发现办法是:签名时,使用*或com.*的证书,不要修改app的bundleIdentifier”是什么意思
hi 你好。您的第一篇关于GPS的文章 显示在审核,查看不了呢。最近正在学习 ,请指教 。
修改完JFBundleIdentifier的内容后,进行注入(使用的是insert_dylib),重签生成ipa(使用的是ios-app-signer),安装ipa,但是点击ipa就发生闪退为何,求指导
老大iOS版最新版本钉钉4.3.5不行,提示"你正在使用非官方版本的钉钉,存在安全风险,请到应用市场下载官方版本",有什么解决办法吗?
close
1.处理LAPluginInstanceCollector的buildActionRequest方法forbidMock参数失效了
2.设置下面三个定位方法也失效了
A declarative, efficient, and flexible JavaScript library for building user interfaces.
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
An Open Source Machine Learning Framework for Everyone
The Web framework for perfectionists with deadlines.
A PHP framework for web artisans
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
Some thing interesting about web. New door for the world.
A server is a program made to process requests and deliver data to clients.
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
Some thing interesting about visualization, use data art
Some thing interesting about game, make everyone happy.
We are working to build community through open source technology. NB: members must have two-factor auth.
Open source projects and samples from Microsoft.
Google ❤️ Open Source for everyone.
Alibaba Open Source for everyone
Data-Driven Documents codes.
China tencent open source team.