Android mount: Read-only file system
新版的x86-android-4.4虛擬機(jī)只有在開(kāi)機(jī)的短時(shí)間內(nèi)具有mount的讀寫(xiě)權(quán)限,所以應(yīng)該在開(kāi)機(jī)之后的瞬間完成寫(xiě)入操作,使用以下的命令:
adb root && adb shell mount -o rw,remount /system && adb push libdvm_x86.so /system/lib/libdvm.so
操作結(jié)果:

image.png
DumpDex腳本
idc
static main(void)
{
auto fp,dex_addr,end_addr;
//路徑中兩個(gè) //代表/,根目錄可能沒(méi)有讀寫(xiě)權(quán)限
fp = fopen("G:\\dexs\\dump.dex","wb");
end_addr = r0 +r1;
for (dex_addr = r0;dex_addr<end_addr;dex_addr ++)
fputc(Byte(dex_addr),fp);
}
python
import idaapi
start_address = 0x51B1C008
data_length = 0x0074BF60
data = idaapi.dbg_read_memory(start_address, data_length)
fp = open('G:\\dexs\\dump.dex', 'wb')
fp.write(data)
fp.close()
安卓日志打印堆棧
Log.getStackTraceString(new Exception());
Log.d(TAG,"Activity",new Exception());
動(dòng)態(tài)調(diào)試
adb forward tcp:23946 tcp:23946
adb shell am start -D -n com.xxx.xxx/com.xxx.SplashActivity
jdb -connect com.sun.jdi.SocketAttach:hostname=127.0.0.1,port=8700