/** * fake_device_v3.js - Spawn-aware fake device * Waits for the dylib to load, then hooks DriveRequest/PopResponse. * * Usage: frida -q -f "/Applications/Saleae Logic.app/Contents/MacOS/Logic" -l fake_device_v3.js * or: frida -q -p $(pgrep -f "Saleae Logic Helper \(Renderer\)") -l fake_device_v3.js */ console.log("[*] Fake Saleae Device v3 (spawn-aware)"); // Known offsets from r2 static analysis var OFFSETS = { DriveRequest: 0x5e7b8, PopResponse: 0x5f078, }; function installHooks() { var mod = Process.enumerateModules().find(function(m) { return m.name.indexOf("libgraph_server_shared") >= 0; }); if (!mod) { console.log("[*] Waiting for dylib to load..."); setTimeout(installHooks, 500); return; } console.log("[+] Module loaded: " + mod.name + " @ " + mod.base); // Hook DriveRequest var drAddr = mod.base.add(OFFSETS.DriveRequest); Interceptor.attach(drAddr, { onEnter: function(args) { var jsonPtr = args[1]; var jsonLen = args[2].toInt32(); if (jsonLen > 0 && jsonLen < 1000000) { try { var jsonStr = jsonPtr.readUtf8String(jsonLen); console.log("\n>>> REQ (" + jsonLen + "B):"); try { console.log(JSON.stringify(JSON.parse(jsonStr), null, 2)); } catch(e) { console.log(jsonStr.substring(0, 2000)); } } catch(e) {} } } }); console.log("[+] DriveRequest hooked @ " + drAddr); // Hook PopResponse var prAddr = mod.base.add(OFFSETS.PopResponse); Interceptor.attach(prAddr, { onEnter: function(args) { this.outData = args[1]; this.outLen = args[2]; }, onLeave: function(retval) { try { var dp = this.outData.readPointer(); var dl = this.outLen.readU32(); if (dl > 0 && dl < 1000000 && !dp.isNull()) { var s = dp.readUtf8String(dl); console.log("\n<<< RESP (" + dl + "B):"); try { console.log(JSON.stringify(JSON.parse(s), null, 2)); } catch(e) { console.log(s.substring(0, 2000)); } } } catch(e) {} } }); console.log("[+] PopResponse hooked @ " + prAddr); console.log("\n[*] Ready. Watching startup traffic...\n"); } installHooks();