From d0336cf28a167414736ae532ea714246fa79cd40 Mon Sep 17 00:00:00 2001 From: tkgstrator Date: Tue, 7 Apr 2026 12:27:12 +0000 Subject: [PATCH] =?UTF-8?q?docs(readme):=20README=E6=A7=8B=E6=88=90?= =?UTF-8?q?=E5=88=B7=E6=96=B0=E3=81=A8=E9=96=8B=E7=99=BA=E7=92=B0=E5=A2=83?= =?UTF-8?q?=E3=83=BB=E5=88=A9=E7=94=A8=E6=89=8B=E9=A0=86=E3=82=92=E8=A9=B3?= =?UTF-8?q?=E7=B4=B0=E5=8C=96?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit リポジトリ名・説明・構成図を刷新し、iOS/Androidリバースエンジニアリング環境の セットアップ・利用手順を大幅に詳述。特にiOS Tweak開発やmacOSホスト設定、 LAN経由プロキシ設定など、実運用に即した情報を追加した。 また、.devcontainerでmitmproxy用ポートを公開し、.vscodeでLAN向けポート公開 設定を追加。README内で各ツールの役割や構成の最新化も行い、初学者や再構築時の 分かりやすさを向上。 --- .devcontainer/devcontainer.json | 9 +- .vscode/settings.json | 1 + README.md | 168 ++++++++++++++++---------------- 3 files changed, 94 insertions(+), 84 deletions(-) diff --git a/.devcontainer/devcontainer.json b/.devcontainer/devcontainer.json index 62f0a6c..856759b 100644 --- a/.devcontainer/devcontainer.json +++ b/.devcontainer/devcontainer.json @@ -44,7 +44,14 @@ "installGradle": false } }, - "forwardPorts": [], + "forwardPorts": [8080, 9080], + "portsAttributes": { + "8080": { "label": "mitmweb", "protocol": "http" }, + "9080": { "label": "mitmproxy", "protocol": "http" } + }, + "otherPortsAttributes": { + "onAutoForward": "ignore" + }, "postAttachCommand": "/bin/sh .devcontainer/postAttachCommand.sh", "postCreateCommand": "/bin/sh .devcontainer/postCreateCommand.sh", "customizations": { diff --git a/.vscode/settings.json b/.vscode/settings.json index 8af5ca1..e030d80 100644 --- a/.vscode/settings.json +++ b/.vscode/settings.json @@ -12,6 +12,7 @@ "gitdoc.pushMode": "push", "gitdoc.timeZone": "Asia/Tokyo", "gitlens.ai.generateCommitMessage.customInstructions": "Generate a commit message in Japanese following the Conventional Commits specification and `commitlint` rules. Use the format `(): ` and choose `` from `build`, `ci`, `docs`, `feat`, `fix`, `perf`, `chore`, `refactor`, `revert`, `format`, `test`. Limit `` to 72 characters. If `` starts with an English word, it must be in lowercase.", + "remote.localPortHost": "allInterfaces", "files.exclude": { "**/__pycache__": true, "**/.venv": true, diff --git a/README.md b/README.md index b4e6170..9a0ead4 100644 --- a/README.md +++ b/README.md @@ -1,43 +1,35 @@ -# Mobile RE Toolkit +# revkit -Frida, Chrome 拡張機能, mitmproxy を使ったモバイルアプリのリバースエンジニアリング環境。 +iOS / Android アプリのリバースエンジニアリングツールキット。 -iOS, Android, Chrome の各プラットフォームにおけるアプリの通信プロトコル・認証フロー・DRM を動的解析するためのツールキット。解析対象ごとのフックスクリプトや解析結果は `targets/` 以下にサブモジュールとして管理し、本リポジトリは汎用ツール基盤として公開可能な構成になっている。 +- **iOS Tweak 開発** — Theos/Orion による Substrate Tweak のビルド・デプロイ (arm64, rootless) +- **Frida フック** — iOS / Android アプリのランタイム解析・動的インストルメンテーション +- **mitmproxy** — HTTPS トラフィックキャプチャ・プロトコルデコード +- **バイナリ解析** — Ghidra, radare2, jadx, ipsw による APK / IPA の静的解析 ## 構成 ``` . ├── packages/ -│ ├── frida/ # Frida フックスクリプト (TypeScript → JS) -│ │ ├── src/ -│ │ │ ├── ios/ # iOS 用フック (ObjC/C++) -│ │ │ ├── android/ # Android 用フック (Java/JNI) -│ │ │ ├── chrome/ # Chrome 用フック (CDM vtable 等) -│ │ │ └── common/ # 共通ユーティリティ -│ │ └── package.json -│ ├── chrome-extension/ # Chrome 拡張 (Web Crypto/EME/HTTP キャプチャ) -│ │ ├── src/ -│ │ └── manifest.json -│ └── proxyman/ # Proxyman アドオン +│ ├── frida/ # Frida フックスクリプト (TypeScript → JS) +│ │ └── src/ +│ │ ├── ios/ # iOS 用フック (ObjC/C++) +│ │ ├── android/ # Android 用フック (Java/JNI) +│ │ └── common/ # 共通ユーティリティ +│ ├── mitmproxy/ # mitmproxy アドオン +│ └── tweak/ # iOS Tweak (Theos/Orion) │ -├── tools/ # Python ユーティリティ -│ ├── run.py # Frida フック実行ランナー (iOS/Android) -│ ├── transformers/ # ログ変換 (Frida → 統一フォーマット) -│ │ ├── base.py # 共通 Transformer 基底クラス -│ │ ├── ios.py # iOS 固有マッピング -│ │ └── android.py # Android 固有マッピング +├── tools/ # Python ユーティリティ +│ ├── run.py # Frida フック実行ランナー +│ ├── transformers/ # ログ変換 (Frida → 統一フォーマット) │ └── ... │ -├── handlers/ # Objection ハンドラ (CommonCrypto, Security 等) -│ -├── targets/ # 解析対象 (サブモジュール, .gitignore) -│ └── / # 対象固有のスクリプト・ドキュメント・ログ -│ -├── docs/ # 解析結果・仕様書 -├── assets/ # IPA/APK バイナリ (.gitignore) -├── raws/ # Frida 生キャプチャログ (.gitignore) -└── logs/ # 変換済みログ (.gitignore) +├── handlers/ # Objection ハンドラ (CommonCrypto, Security 等) +├── docs/ # 解析結果・仕様書 +├── assets/ # IPA/APK バイナリ (.gitignore) +├── raws/ # Frida 生キャプチャログ (.gitignore) +└── logs/ # 変換済みログ (.gitignore) ``` ## 開発環境 @@ -49,10 +41,10 @@ DevContainer で構築済み。`Rebuild Container` で全ツールが揃う。 | ツール | 用途 | |---|---| | Python 3.12 (uv) | ユーティリティ、ログ変換、解析スクリプト | -| Node.js | Frida スクリプトのビルド (frida-compile) | +| Node.js 25.x | Frida スクリプトのビルド (frida-compile) | | Bun | Chrome 拡張のビルド | | Frida 17.x | 動的インストルメンテーション | -| mitmproxy | プログラマブル HTTPS プロキシ (コンテナ内で完結) | +| mitmproxy | プログラマブル HTTPS プロキシ | ### リバースエンジニアリング @@ -65,31 +57,60 @@ DevContainer で構築済み。`Rebuild Container` で全ツールが揃う。 | ipsw | iOS Mach-O 解析・ObjC/Swift クラスダンプ | | lief (Python) | Mach-O/ELF バイナリパーサー | | capstone (Python) | ARM64 ディスアセンブラ | +| unicorn (Python) | CPU エミュレーション | +| pywidevine (Python) | Widevine DRM 解析 | + +### iOS Tweak 開発 + +| ツール | 用途 | +|---|---| +| Theos | Tweak ビルドシステム | +| Orion | Swift Tweak フレームワーク | +| Swift 5.8 (cross-compile) | iOS 向けクロスコンパイル | +| iOS SDK 15.6 / 16.5 | ビルドターゲット | + +## macOS ホスト設定 + +DevContainer はDocker Desktop の Linux VM 内で動作するため、LAN 上のデバイス (iOS/Android) と直接通信できない。以下の設定で macOS を踏み台にして SSH / Frida を中継する。 + +### 1. リモートログインを有効化 + +**システム設定 → 一般 → 共有 → リモートログイン** をオンにする。 + +### 2. SSH 公開鍵を登録 + +コンテナ内の鍵を macOS の authorized_keys に追加する: + +```bash +cat ~/.ssh/id_ed25519.pub >> ~/.ssh/authorized_keys +``` + +### 3. VS Code ポートフォワーディング設定 + +`.vscode/settings.json` に以下を追加して、mitmproxy のポートを LAN に公開する: + +```json +"remote.localPortHost": "allInterfaces" +``` + +### 接続経路 + +| 用途 | 方向 | 経路 | +|------|------|------| +| **SSH** | コンテナ → デバイス | `ssh iPhone` (ProxyJump で macOS を経由) | +| **Frida** | コンテナ → デバイス | SSH の LocalForward で 127.0.0.1:27042 → デバイス:27042 | +| **mitmproxy** | デバイス → コンテナ | デバイスのプロキシを macOS の LAN IP:9080 に設定 | ## 使い方 -### ビルド +### Frida フック ```bash -# Frida フックスクリプト -cd packages/frida -npm run build:ios # → hook_netflix.js -npm run build:android # → hook_netflix_android.js -npm run build:chrome # → hook_chrome_cdm.js - -# Chrome 拡張 -cd packages/chrome-extension -bun run build -``` - -### キャプチャ実行 - -```bash -# iOS (起動中のアプリにアタッチ、未起動なら自動で spawn) -uv run python tools/run.py packages/frida/hook_netflix.js +# iOS (objection 経由で spawn) +uv run python tools/run.py packages/frida/