ac-pm / Inspeckage

Android Package Inspector - dynamic analysis with api hooks, start unexported activities and more. (Xposed Module)
Apache License 2.0
2.78k stars 514 forks source link

Crypto issue on some APP #82

Open 4ft35t opened 5 years ago

4ft35t commented 5 years ago

Android:7.1.2 Inspeckage: 2.4 APP: https://download.cc.cmbimg.com/client/cmblife_530.apk

DES and 3DES can get key, but AES can't.

254 , Cipher[AES/ECB/PKCS5Padding]  (......t. 944adc254e087c44b08050732a69b4be , iildMMN7dt4M8UameM4l3KqHexQ/esJbsp1eU/2vHATkpaSaBNj2y6Hzb1bvdZa8)
253 , Cipher[AES/ECB/PKCS5Padding] (9002|ClientRouter|7F138A09169B250E9DCB378140907378 , 4TTr+w8JAJkuzGCmcS2BznIxlmFWATQ6a50yChufBfV7rWwZ »
252 , Cipher[RSA/ECB/PKCS1Padding] (b6bcffa5bae946ef8691fa05491eb743 , cwC7wdCldrbFUBxELYzs1Qm985iPa9hlObF2zosEJAQL9tPztuwrp8VYtfSETS/Ry9 »
251 SecretKeySpec(b6bcffa5bae946ef8691fa05,DESede) , Cipher[DESede] ({"positionProperty":{"latitude":"","altitude":"","province":"......", »
250 SecretKeySpec(3/tdhc7L+wQ=,DES) , Cipher[DES/ECB/PKCS5Padding] (dyU5GodQwP3qN+o9bp8T6On8pDONwIm0d1NQwgITpQh7JPtyLWvzY+bhBz7I+Lh/iw2ig7 »
249 SecretKeySpec(3/tdhc7L+wQ=,DES) , Cipher[DES/ECB/PKCS5Padding] (hxnYQ9phzVDkSb5QtDVHRe7TsT49HECGytVXsPxXZAVw0b66YT4QT/i0APccM8jWpu6zzT »
248 SecretKeySpec(3/tdhc7L+wQ=,DES) , Cipher[DES/ECB/PKCS5Padding]  (LmxRhpjlbRGzlnXgBp7Icw== , 3039776800)
247 [PBEKeySpec] - Password: 284276091 || Salt: i2pDMEwKYW9LsCcvf4Bjgv73WXC9qyYUFRuMNAX4T7w=
246 , Cipher[AES/ECB/PKCS5Padding] (4TTr+w8JAJkuzGCmcS2BztzHwLgn0KtPYF0tbwhZbF+lygo9/qULYKUF/uqb00ZXcIjPEPeTecefoEU23bdL/w== , 9002|Clien »
245 , Cipher[AES/ECB/PKCS5Padding] (s/sgd99451ks88TCA+jtDpVnH3EmeWwNCs5Tu5odH9l2Rr+Dh3N9drxxO1aXLhyNjLeDq8GzRUdD9wcIyJVhroCa/OJn7Cp7wNGEv »