标签:over 五步 stat 思想 etc string 插件 源码 下载
@Override
public void startActivity(Intent intent, Bundle options) {
warnIfCallingFromSystemProcess();
if ((intent.getFlags()&Intent.FLAG_ACTIVITY_NEW_TASK) == 0) {
throw new AndroidRuntimeException(
"Calling startActivity() from outside of an Activity "
+ " context requires the FLAG_ACTIVITY_NEW_TASK flag."
+ " Is this really what you want?");
}
mMainThread.getInstrumentation().execStartActivity(
getOuterContext(), mMainThread.getApplicationThread(), null,
(Activity)null, intent, -1, options);
}// 先获取到当前的ActivityThread对象
Class<?> activityThreadClass = Class.forName("android.app.ActivityThread");
Method currentActivityThreadMethod = activityThreadClass.getDeclaredMethod("currentActivityThread");
currentActivityThreadMethod.setAccessible(true);
Object currentActivityThread = currentActivityThreadMethod.invoke(null);package com.example.hookstartactivity;
import java.lang.reflect.Method;
import android.app.Activity;
import android.app.Instrumentation;
import android.app.Instrumentation.ActivityResult;
import android.content.Context;
import android.content.Intent;
import android.os.Bundle;
import android.os.IBinder;
import android.util.Log;
public class InstrumentationProxy extends Instrumentation {
public static final String TAG = "InstrumentationProxy";
public static final String EXEC_START_ACTIVITY = "execStartActivity";
// ActivityThread里面原始的Instrumentation对象,这里千万不能写成mInstrumentation,这样写
//抛出异常,已亲测试,所以这个地方就要注意了
public Instrumentation oldInstrumentation;
//通过构造函数来传递对象
public InstrumentationProxy(Instrumentation mInstrumentation) {
oldInstrumentation = mInstrumentation;
}
//这个方法是由于原始方法里面的Instrumentation有execStartActivity方法来定的
public ActivityResult execStartActivity(Context who, IBinder contextThread, IBinder token, Activity target,
Intent intent, int requestCode, Bundle options) {
Log.d(TAG, "\n打印调用startActivity相关参数: \n" + "who = [" + who + "], " +
"\ncontextThread = [" + contextThread + "], \ntoken = [" + token + "], " +
"\ntarget = [" + target + "], \nintent = [" + intent +
"], \nrequestCode = [" + requestCode + "], \noptions = [" + options + "]");
Log.i(TAG, "------------hook success------------->");
Log.i(TAG, "这里可以做你在打开StartActivity方法之前的事情");
Log.i(TAG, "------------hook success------------->");
Log.i(TAG, "");
//由于这个方法是隐藏的,所以需要反射来调用,先找到这方法
try {
Method execStartActivity = Instrumentation.class.getDeclaredMethod(
EXEC_START_ACTIVITY,
Context.class, IBinder.class, IBinder.class, Activity.class,
Intent.class, int.class, Bundle.class);
execStartActivity.setAccessible(true);
return (ActivityResult) execStartActivity.invoke(oldInstrumentation, who,
contextThread, token, target, intent, requestCode, options);
} catch (Exception e) {
//如果你在这个类的成员变量Instrumentation的实例写错mInstrument,代码讲会执行到这里来
throw new RuntimeException("if Instrumentation paramerter is mInstrumentation, hook will fail");
}
}
}package com.example.hookstartactivity;
import java.lang.reflect.Field;
import java.lang.reflect.Method;
import android.app.Application;
import android.app.Instrumentation;
import android.util.Log;
public class MyApplication extends Application {
public static final String TAG = "MyApplication";
public static final String ACTIVIT_THREAD = "android.app.ActivityThread";
public static final String CURRENT_ACTIVITY_THREAD = "currentActivityThread";
public static final String INSTRUMENTATION = "mInstrumentation";
@Override
public void onCreate() {
try {
//这个方法一般是写在Application的oncreate函数里面,如果你写在activity里面的oncrate函数里面就已经晚了
attachContext();
} catch (Exception e) {
e.printStackTrace();
}
}
public static void attachContext() throws Exception{
//获取当前的ActivityThread对象
Class<?> activityThreadClass = Class.forName(ACTIVIT_THREAD);
Method currentActivityThreadMethod = activityThreadClass.getDeclaredMethod(CURRENT_ACTIVITY_THREAD);
currentActivityThreadMethod.setAccessible(true);
Object currentActivityThread = currentActivityThreadMethod.invoke(null);
//拿到在ActivityThread类里面的原始mInstrumentation对象
Field mInstrumentationField = activityThreadClass.getDeclaredField(INSTRUMENTATION);
mInstrumentationField.setAccessible(true);
Instrumentation mInstrumentation = (Instrumentation) mInstrumentationField.get(currentActivityThread);
//构建我们的代理对象
Instrumentation evilInstrumentation = new InstrumentationProxy(mInstrumentation);
//通过反射,换掉字段,注意,这里是反射的代码,不是Instrumentation里面的方法
mInstrumentationField.set(currentActivityThread, evilInstrumentation);
//做个标记,方便后面查看
Log.i(TAG, "has go in MyApplication attachContext method");
}
}package com.example.hookstartactivity;
import android.content.Intent;
import android.os.Bundle;
import android.support.v7.app.ActionBarActivity;
import android.util.Log;
import android.view.Menu;
import android.view.MenuItem;
import android.view.View;
import android.view.View.OnClickListener;
import android.widget.TextView;
public class MainActivity extends ActionBarActivity {
public static final String TAG = "MainActivity";
public TextView tv;
@Override
protected void onCreate(Bundle savedInstanceState) {
super.onCreate(savedInstanceState);
setContentView(R.layout.activity_main);
tv = (TextView)findViewById(R.id.start);
tv.setOnClickListener(new OnClickListener(){
@Override
public void onClick(View v) {
try {
Intent intent = new Intent(MainActivity.this, SecondActivity.class);
Bundle bundle = new Bundle();
Log.i(TAG, "-------------------------------->");
Log.i(TAG, "startActivity before");
Log.i(TAG, "-------------------------------->");
startActivity(intent, bundle);
Log.i(TAG, "-------------------------------->");
Log.i(TAG, "startActivity after");
Log.i(TAG, "-------------------------------->");
} catch (Exception e) {
e.printStackTrace();
}
}
} );
}
}package com.example.hookstartactivity;
import android.os.Bundle;
import android.support.v7.app.ActionBarActivity;
public class SecondActivity extends ActionBarActivity{
@Override
protected void onCreate(Bundle savedInstanceState) {
super.onCreate(savedInstanceState);
setContentView(R.layout.activity_second);
}
}pidcat.py 包名
Android插件化开发之Hook StartActivity方法
标签:over 五步 stat 思想 etc string 插件 源码 下载
原文地址:http://blog.csdn.net/u011068702/article/details/53208825