首页| 论坛| 搜索| 消息
主题:秒盗账号钱包!伪装Electron程序暗藏后门窃取加密数据
z3960发表于 2026-05-16 18:03
$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$PATH拉取 V8 源码:
mkdir ~/v8cd ~/v8fetch v8cd v8切换到与目标字节码匹配的版本。本文样本分析时使用的是:
git checkout refs/tags/10.4.132.24gclient sync -D这里版本必须尽量对齐目标 Electron/Node 所携带 V8。版本不匹配时,即使能绕过部分校验,输出结构也很容易错位。2.3 修改 V8 以打印字节码结构V8 内部本来就具备 Disassemble()、对象打印和 SharedFunctionInfoPrint() 能力,但默认这些能力主要服务于调试构建和源码调试。为了让它直接消费 .jsc 并吐出结构,我们需要做几处定点修改:1. 放宽反序列化检查并打印 SharedFunctionInfo修改 src/snapshot/code-serializer.cc:● CodeSerializer::Deserialize 成功拿到结果后打印 SharedFunctionInfo● SerializedCodeData::SanityCheck() 中临时直接返回成功,绕过一部分缓存校验。插入的核心打印逻辑如下:
std::cout SharedFunctionInfoPrint(std::cout); std::cout
上一页  (2/2)
回帖(1):
1 # 爱我中华
05-16 20:02
安全第一

全部回帖(1)»
最新回帖
收藏本帖
发新帖