LLDB打印swift数组只知道十六进制地址

时间:2017-03-02 12:37:48

标签: swift reverse-engineering lldb disassembly

我试图对使用发布配置构建的应用程序之一进行逆向工程。

我的主题信息如下所示。

* thread #21: tid = 0x876cb, 0x000000010133856c SomeLibSwift`SomeLibSwift.Auth.auth (Swift.Array<Swift.UInt8>) throws -> Swift.Array<Swift.UInt8>, queue = 'com.apple.root.utility-qos', stop reason = breakpoint 1.6
  * frame #0: 0x000000010133856c SomeLibSwift`SomeLibSwift.Auth.auth (Swift.Array<Swift.UInt8>) throws -> Swift.Array<Swift.UInt8> 

寄存器x0(地址0x181ba4174)包含所需的参数

内存阅读显示类似的内容(我尝试过不同的格式)

memory read -s1 -fC -c1000 --force 0x181ba4174

0x181ba4174: ...??._?.......??._?0......??._?
0x181ba4194: P......??._?p......??._?.......?
0x181ba41b4: ?._ְ......??._??......??._?....
0x181ba41d4: ...??._?0......??._?P......??._?
0x181ba41f4: p......??._?.......??._ְ......?
0x181ba4214: ?._??......??._?.......??._?P...
0x181ba4234: ...??._?p......??._?.......??._?
....

我发现auth func有这样的定义

func auth(_ bytes: Array<UInt8>) throws -> Array<UInt8>

所以基本上我想要的只是获得字节&#39;由地址0x181ba4174存储的变量。

我也知道&#39; auth&#39;使用如下参数调用方法:

let key = "somekey".utf8
let result = auth(key)

理想情况下,我想取回钥匙。

1 个答案:

答案 0 :(得分:1)

最后我能够完成这件事。

expr -l Swift  -- String(unsafeBitCast(0x181ba4174, to: Array<UInt8>.self))

它输出如下:

(String) $R0 = "[10, 11, 118, 105, 19, 1]"

然后使用Xcode我得到了密钥:

var arr: [UInt8] = [10, 11, 118, 105, 19, 1]

let data = Data(bytes: arr)
let key = String(data: data, encoding: .ascii)

我还写了一个命令以防有人需要它。

command regex ptrInt8Array 's/(.+)/expr -l Swift  -- String(describing: unsafeBitCast(%1, to: Array<UInt8>.self))/'

执行:

ptrInt8Array 0x181ba4174