hook KeyStore 详解
🔑 script.js hook
java.security.KeyStore,捕获证书加载与 Pinning 定位。
📎 源码在线查看:
script.js(KeyStore hook)
hook 目标
javascript
var KeyStore = Java.use("java.security.KeyStore");两类捕获
1. 客户端证书导出
hook setKeyEntry / setCertificateEntry / load(带证书的):
javascript
KeyStore.setKeyEntry.overload('java.lang.String',
'java.security.Key', '[C', '[Ljava.security.cert.Certificate;')
.implementation = function(alias, key, pwd, chain) {
// key 是私钥,chain 是证书链
storeP12(key, chain); // 导出
return this.setKeyEntry(alias, key, pwd, chain);
};详见 storeP12 与 hook-client-cert。
2. Pinning 定位
hook getCertificateChain / Entry 的访问,记录 App 在哪访问证书——用于定位 Pinning 校验位置。详见 hook-pinning-locator。
KeyStore 类型
| 类型 | 含义 |
|---|---|
PKCS12 | .p12 文件 |
BKS | BouncyCastle Keystore |
AndroidCAStore | 系统 CA 库 |
Windows-MY | Windows 个人证书 |
r0capture 主要关注 PKCS12(客户端证书)和 AndroidCAStore(Pinning 校验时访问)。
PrivateKeyEntry
javascript
var PKEntry = Java.use("java.security.KeyStore$PrivateKeyEntry");
PKEntry.getPrivateKey.implementation = function () {
var pri = this.getPrivateKey();
// App 在取私钥做 mTLS,顺便导出
storeP12(pri, this.getCertificateChain());
return pri;
};这是 mTLS 客户端证书导出的关键 hook 点。