With Frida I print the SSL_write
Interceptor.attach(Module.findExportByName("libssl.so", "SSL_write"), {
onEnter: function (args) {
console.log(args[1].readByteArray(args[2].toInt32()));
}
});
I want to replace the buffer to write to SSL , if buffer contain Ascii of AAAAAA replace with BBBBBB
How can I do that ?
Steps:
Uint8Array with the same size as the function receives (you can check the size_t argument).unwrap().const sslWritePtr = Module.getExportByName(null, "ssl_write");
function str2ab(str) {
let buf = new ArrayBuffer(str.length);
let bufView = new Uint8Array(buf);
for (var i=0, strLen=str.length; i < strLen; i++) {
bufView[i] = str.charCodeAt(i);
}
return buf;
}
Interceptor.attach(sslWritePtr, {
onEnter: function (args) {
// Get the buffer size by checking the third argument.
const buffer_size = args[2].toInt32() + 1;
// Read the contents of the buffer and get an ArrayBuffer.
let buffer = args[1].readByteArray(buffer_size);
// Convert it to a string object.
let buffer_string = String.fromCharCode.apply(null, new Uint8Array(buffer));
// Replace the contents.
buffer_string = buffer_string.replace("AAAAAA", "BBBBBB");
// Convert `buffer_string` back to an ArrayBuffer.
// .unwrap() returns a pointer to the first element of the Uint8Array
args[1] = str2ab(str).unwrap(); // Assign the pointer of our new Uint8Array.
},
});
This link might be useful to understand better how to operate in this situation: https://learnfrida.info/intermediate_usage/#operating-with-arraybuffers