INNER CODE UNIT · Shell
APK_DIR
ax/apk.sh · apk.sh:348
APK_DIR=${APK_NAME%.apk} # bash 3.x compliant xD
mkdir -p "$APK_DIR/lib/$ARCH_DIR/"
cp ${FRIDA_SO_XZ::-3} $APK_DIR/lib/$ARCH_DIR/libfrida-gadget.so
if [ ! -z $GADGET_CONF_PATH ]; then
echo "[>] Placing the specified gadget configuration json file...."
cp "$GADGET_CONF_PATH" $APK_DIR/lib/$ARCH_DIR/libfrida-gadget.config.so
fi
# Inject a System.loadLibrary("frida-gadget") call into the smali,
# before any other bytecode executes or any native code is loaded.
# A suitable place is typically the static initializer of the entry point class of the app (e.g. the main application Activity).
# We have to determine the class name for the activity that is launched on application startup.
# In Objection this is done by first trying to parse the output of aapt dump badging, then falling back to manually parsing the AndroidManifest for activity-alias tags.
echo "[>] Searching for a launchable-activity..."
MAIN_ACTIVITY=`$AAPT dump badging $APK_NAME | grep launchable-activity | grep -Po "name='\K.*?(?=')"`
echo "[>] launchable-activity found --> $MAIN_ACTIVITY"
# TODO: If we dont get the activity, we gonna check out activity aliases trying to manually parse the AndroidManifest.
# Try to determine the local path for a target class' smali converting the main activity to a path