
Voll ausgestatteter APK-Parser
Ein voll ausgestatteter apk-Parser.
BadPack-Technik;APK Signature Block 42:
# type: ignore mehr;cargo install apk-info-cli
A command-line tool to inspect and extract APK files
Usage: apk-info [COMMAND]
Commands:
show Show basic information about apk file
extract Unpack apk files as zip archive [aliases: x]
axml Read and pretty-print binary AndroidManifest.xml
completion Generate shell completion
help Print this message or the help of the given subcommand(s)
Options:
-h, --help Print help
-V, --version Print version
uv pip install apk-info
from apk_info import APK
apk = APK("./path-to-file.apk")
package_name = apk.get_package_name()
main_activities = apk.get_main_activities()
min_sdk = apk.get_min_sdk_version()
print(f"Package Name: {package_name}")
print(f"Minimal SDK: {min_sdk}")
if not main_activities:
print("apk is not launchable!")
exit()
print(f"Main Activity: {package_name}/{main_activities[0]}")
import sys
from apk_info import APK, Signature
if len(sys.argv) < 2:
print(f"usage: {sys.argv[0]} <apk>")
sys.exit(1)
file = sys.argv[1]
apk = APK(file)
signatures = apk.get_signatures()
for signature in signatures:
match signature:
case Signature.V1() | Signature.V2() | Signature.V3() | Signature.V31():
for cert in signature.certificates:
print(f"{cert.subject=} {cert.issuer=} {cert.valid_from=} {cert.valid_until=}")
case Signature.ApkChannelBlock():
print(f"got apk channel block: {signature.value}")
case _:
print(f"oh, cool, library added some new feature - {signature}")
Umgebung:
Das Skript:
apk-info-Bibliothek:
release-lto;Testfall (saubere Sammlung):
| # | apk-info | androguard |
|---|---|---|
| 1 |
Testfall (Malware-Sammlung):
[!IMPORTANT] In dieser Sammlung gibt es viele bösartige Beispiele, die androguard einfach nicht parsen kann.
| # | apk-info | androguard |
|---|---|---|
| 1 |
Im Durchschnitt beträgt der Geschwindigkeitsgewinn etwa das Zehnfache.
Der Hauptvorteil ist, dass apk-info viele weitere bösartige Dateien parsen kann als androguard.
Fast alle meine Projekte entstehen aus etwas, das umständlich zu verwenden ist. Androguard ist an sich ein großartiges Werkzeug, aber es ist (meiner Meinung nach) einfach nicht möglich, es zu warten, und es ist nicht für produktionsreifen Code geeignet. Es ist auch nicht für die Analyse einer großen Anzahl von Dateien geeignet, da die gesamte Logik auf nicht sehr optimierte Weise geschrieben ist.
Die Bibliothek ist nur für den schreibgeschützten Modus ausgelegt, weil ich ein gutes Werkzeug brauche, mit dem ich einfach und schnell Informationen aus der APK extrahieren kann. Es gibt viele andere gute Werkzeuge da draußen.
| 0.98s user 4.32s system 80% cpu 6.584 total |
| 57.39s user 4.88s system 97% cpu 1:03.85 total |
| 2 | 0.96s user 4.23s system 79% cpu 6.486 total | 57.98s user 5.04s system 97% cpu 1:04.80 total |
| 3 | 0.95s user 4.15s system 79% cpu 6.422 total | 55.56s user 4.48s system 97% cpu 1:01.55 total |
| 2.49s user 4.74s system 73% cpu 9.840 total |
| 141.29s user 6.86s system 98% cpu 2:31.09 total |
| 2 | 2.50s user 4.77s system 75% cpu 9.641 total | 138.04s user 6.32s system 97% cpu 2:27.33 total |
| 3 | 2.49s user 4.78s system 75% cpu 9.650 total | 139.33s user 6.65s system 98% cpu 2:28.87 total |