🔨 Break Java Reverse Engineering form Memory World!
Project description
Wallbreaker
馃敤 Break Java Reverse Engineering form Memory World!
WTF?
Wallbreaker is a useful tool to live analyzing Java heap, powered by frida. Provide some commands to search object or class from the memory, and beautifully visualize the real structure of the target.
Want to know real data content? list item? map entries? Want to know about implementation of the interface? Try it! What you see is what you get!
How to start?
1. Install objection
pip3 install objection
2. Download wallbreaker
mkdir -p ~/.objection/plugins/
git clone https://github.com/hluwa/Wallbreaker ~/.objection/plugins/Wallbreaker
3. Loading as objection plugin
objection -g com.app.name explore -P ~/.objection/plugins
or
objection -g com.app.name explore
plugin load ~/.objection/plugins/Wallbreaker
4. Use wallbreaker command
plugin wallbreaker objectsearch java.util.HashMap
plugin wallbreaker objectdump <object-handle>
Commands
Search
wallbreaker classsearch <type-pattern>
[return all matched class]
wallbreaker objectsearch <instance-class-name>
[return all matched object-handle and toString]
Dump
wallbreaker classdump <class-name> [--fullname]
[
pretty print class structure: fields declare, static field value, methods declare.
set --fullname to display package name of type name.
]
wallbreaker objectdump <object-handle> [--fullname] [--as-class class-name]
[
pretty print object structure: fields declare and value, methods declare.
set --fullname to display package name of type name;
set --as-class to cast instance type(super class, not interface).
if instance is a collection or map, dump all entries.
]
Demo
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Hashes for wallbreaker-1.0.1-py3-none-any.whl
Algorithm | Hash digest | |
---|---|---|
SHA256 | 9b3636890253ef0a0e0b5c0d534f8335380fd60208f4822bf75ad0bc36b0e1c7 |
|
MD5 | 3ddc82ba25e098953d6c794f487fcaac |
|
BLAKE2b-256 | 8d61a14190c8e905801eb0c7d6f8a31156b4df3d976c7bca65b0b5efa478189c |