Post Reply

[MOD] PackageParser Patch

OP a9y

10th November 2013, 02:27 PM   |  #1  
OP Junior Member
Thanks Meter: 7
 
14 posts
Join Date:Joined: Nov 2013
More
This patch is against framework.jar for Android 4.4 (KRT16M) and allows you to modify system packages without them being verified.

Why would you want this?

Re-signing isn't possible with many google packages as they check their own certificates at runtime (GooglePlayServices). This patch allows you to make any modifications you like to system packages, while keeping the original certificates.

Isn't it unsafe to not verify packages?

Yes. However, this patch only applies to system packages. Those downloaded from the market are still verified as usual. The /system filesystem is read-only by default. The only way for a package to be infected is if an application has root privileges (via SuperSU or similar). Of course you should assume that after giving an application elevated privileges it could infect packages with or without this patch.

How does it work?

Packages in android are loaded by PackageParser. The method collectCertificates attempts to read the file AndroidManifest.xml from system packages, which causes the underlying JarFile to verify it against the embedded signature. If everything was successful it returns the certificate. This patch changes collectCertificates to load and return the certificate directly, without trying to read AndroidManifest.xml.

You must delete META-INF/CERT.SF and META-INF/MANIFEST.MF from any package you modify. This patch doesn't change the underlying JarFile code, which by default uses those files to check entries as they're read from the archive. You should leave META-INF/CERT.RSA alone as that's the certificate this patch loads.


The patch was produced against framework.jar from the factory image KRT16M using baksmali v2.0 .


SHA1

Code:
433eeec32008015a1f54964bf036f4eaddb3864b framework-jar-KRT16M-raw-certificates.patch
75b5999203f355cf45387a424246e988440c3068 framework.jar
Attached Files
File Type: patch framework-jar-KRT16M-raw-certificates.patch - [Click for QR Code] (5.4 KB, 14 views)
File Type: jar framework.jar - [Click for QR Code] (3.50 MB, 12 views)
Last edited by a9y; 10th November 2013 at 02:50 PM. Reason: smali version
The Following 3 Users Say Thank You to a9y For This Useful Post: [ View ]
10th November 2013, 02:50 PM   |  #2  
OP Junior Member
Thanks Meter: 7
 
14 posts
Join Date:Joined: Nov 2013
More
*reserved*
The Following User Says Thank You to a9y For This Useful Post: [ View ]
30th January 2014, 01:44 PM   |  #3  
Senior Member
Flag São Paulo - SP
Thanks Meter: 389
 
441 posts
Join Date:Joined: Jun 2012
More
Thanks for this great mod.. Modify system packages works but when add new apk system (like sony apps to my CM 11 device), ktkat won't accept as app installed, even when I don't modify anything in apk.
Sent from my Xperia Mini Pro using Tapatalk
Post Reply Subscribe to Thread

Tags
android, baksmali, certificate, framework, nexus
Previous Thread Next Thread
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Top Threads in Nexus 5 Themes and Apps by ThreadRank