1.抓包数据
GET http://api.flowbank.sinobyte.cn/v5/login?sign=3FC2F32389A38175E76F42477BE65C52&platform=2&appid=102&type=0&phonenum=15081515272&password=A9C4020FA0FC89C333AFE8FA91228D28&deviceid=864895021913601 HTTP/1.1
ExpiresTime: 20160627052353
tcp: D91185D50EE805B729ED44799C9F99EA
User-Agent: Dalvik/1.6.0 (Linux; U; Android 4.2.2; Droid4X-WIN Build/JDQ39E)
Host: api.flowbank.sinobyte.cn
Connection: Keep-Alive
Accept-Encoding: gzip
{"code":-100,"data":{},"message":"用户不存在。"}
2.搜索Java代码,password 定位到下图2个类,通过分析抓包密码,确定是MD5,判定在aa.class.
3.分析代码
password是MD5(‘123465aaaa‘)
sign
时间: 2024-10-13 01:52:55