feat(huya): C2新钥表8x24B发现 + AppLoginData真布局(流程穿透2691c0) + 全爆破零命中定界

This commit is contained in:
yml2213
2026-08-29 02:34:01 +08:00
parent 702c6276fc
commit b60c7b78d1
2 changed files with 32 additions and 9 deletions
+11
View File
@@ -828,3 +828,14 @@ hypasswordLogin/MsgLoginReq/LogLoginReq → mid 各异, tail 恒定 8b38f1 → a
### 堆窗 pre/post 差分法就绪 (getOtp-pre/post 双扫描框架)
### R10: ① hook 2691a4 读 x20 (分支条件) + 读 0x26916c-0x2691a4 前导定 AppLoginData 布局
### ② 布局修正 → getOtp 走到 269324 → hook 抓 OTP 实参+OUT
## §11.33 C2 新钥表 + AppLoginData 真布局 + getOtp 流程走通 (R10)
### C2(getInstance) 注入的 AESkeyMgr 新钥表 (堆 0x127ddbe0, 8×24B, 与已知11钥族完全不同!):
SHBfgytjtoikooru+hogji7ER / KNSDNjfohweeromn+mkladj3g / xnkdDFIERRIPT5df+hfgiJ0FD
NDFiroqpmvd4JDIJ+hidtiwex / fNoMrJhbEMXm8nHc+HXTNovaL / novwSHidrhDg1ADU+KLkejnHR
hgtuiouilbsdjwEH+HMYU5gjt / masldDSIFGJjdfio+5hkhsSDF
→ 新钥 × enc/decode/md5/sha1/hmac 对 ed0db8 = 全零
### AppLoginData 真布局 (jadx): hyOpenId@0(8B) + userId@8(24B) + userIdState@0x20(4B) + emailMask@0x28 + ...
→ 重构后 getOtp 流程穿透: 26916c→…→2691c0 (x20=0 首串校验过) 不再早退!
### 未捕获: OTP 调用点 269324 hook 未触发 (流程在 2691c4-2692fb 未hook窗口内或 4542c0 getServiceTime 段)
### 状态: appSign 生成复刻仍未完成 - 差距仅剩"抓到 getOtp 内部真实 OTP 输出"