apk

package
v0.5.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Aug 8, 2026 License: MIT Imports: 12 Imported by: 0

Documentation

Overview

Package apk opens an APK (ZIP) archive and provides access to its internal sources for secrets scanning.

The package is intentionally narrow: it knows nothing about pattern matching, output formats, or ignore logic. Its only job is "given an APK path, give me the raw bytes of each scannable source."

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func DecodeManifestBytes

func DecodeManifestBytes(raw []byte) ([]byte, error)

DecodeManifestBytes decodes raw AXML bytes into plain XML text without resource ID resolution. Resource ID references are left as raw hex values. This is a standalone variant of DecodeManifest for use when the caller already has the manifest bytes and does not have access to resources.arsc.

func DecodeManifestBytesWithResources added in v0.3.0

func DecodeManifestBytesWithResources(raw []byte, resources *apkparser.ResourceTable) ([]byte, error)

DecodeManifestBytesWithResources decodes raw AXML bytes into plain XML text, resolving resource ID references via the provided resource table. Pass nil for resources to leave resource ID references as raw hex values.

func ExtractStrings

func ExtractStrings(dex []byte) ([]string, error)

ExtractStrings extracts all strings from the DEX string table. It reads the string_ids section and string_data section from the raw DEX bytes and returns the decoded strings in order.

The string data is MUTF-8 encoded in the DEX format. For secrets scanning purposes, we treat it as raw bytes — the important thing is that credential-like strings (API keys, tokens, etc.) appear verbatim in the string table regardless of encoding.

Returns an error if the DEX header is malformed or the string table offsets are out of bounds.

Types

type APK

type APK struct {
	// contains filtered or unexported fields
}

APK represents an opened APK file ready for source extraction.

func Open

func Open(path string) (*APK, error)

Open opens the APK at path and reads its directory of contents. The returned APK must be closed when done.

func (*APK) Assets

func (a *APK) Assets() (map[string][]byte, error)

Assets reads and returns the raw bytes of every file under assets/. The returned map keys are the relative paths within the APK (e.g. "assets/config.json"). Returns nil (not an error) when there are no assets.

func (*APK) Close

func (a *APK) Close() error

Close is a no-op. The zip.Reader does not hold resources that require explicit closing after the file data has been read.

func (*APK) DEXFiles

func (a *APK) DEXFiles() ([][]byte, error)

DEXFiles reads and returns the raw bytes of every classes*.dex file in the APK, ordered by name (classes.dex, classes2.dex, ...). Returns an error if any DEX file cannot be read.

func (*APK) DecodeManifest

func (a *APK) DecodeManifest() ([]byte, error)

DecodeManifest decodes the binary AndroidManifest.xml into plain XML text. The returned bytes are UTF-8 XML that can be scanned directly for secrets. If the APK contains a valid resources.arsc, resource ID references in the manifest are resolved to their string values automatically. If resources.arsc is missing or corrupted, resource references are left as raw hex values.

func (*APK) DecompressedSize

func (a *APK) DecompressedSize(name string) (uint64, error)

DecompressedSize returns the decompressed size of a named file in the APK.

func (*APK) FindFile

func (a *APK) FindFile(name string) *zip.File

FindFile returns the zip.File entry for the given name, or nil if not found.

func (*APK) Manifest

func (a *APK) Manifest() ([]byte, error)

Manifest reads and returns the raw bytes of AndroidManifest.xml. The bytes are in Android Binary XML (AXML) format and must be decoded by the caller before use as text.

func (*APK) Path

func (a *APK) Path() string

Path returns the filesystem path of this APK.

func (*APK) ReadFileRange

func (a *APK) ReadFileRange(name string, offset, length int64) ([]byte, error)

ReadFileRange reads a byte range from a named file in the APK. This is used for DEX string table extraction to read specific sections without loading the entire file into memory.

func (*APK) ResourceStrings added in v0.4.0

func (a *APK) ResourceStrings() (map[string]string, error)

ResourceStrings extracts all string-type resource entries from the APK's binary resource table (resources.arsc). Returns a map of resource key name to its string value for every entry of type "string" across all packages.

This is the primary source of string values in release APKs: aapt2 compiles res/values/strings.xml into the binary resource table and drops the source file. Strings referenced from Java/Kotlin code via R.string.* that never appear as literals in DEX bytecode are surfaced here.

Returns os.ErrNotExist if the APK has no resources.arsc. Returns an error if the resource table cannot be parsed.

func (*APK) ResourceTable added in v0.3.0

func (a *APK) ResourceTable() (*apkparser.ResourceTable, error)

ResourceTable parses and returns the resource table (resources.arsc) for this APK. The result is cached after the first successful call. Returns os.ErrNotExist if the APK does not contain a resources.arsc file. This is not an error—callers should fall back to nil resources for manifest decoding.

func (*APK) StringsXML

func (a *APK) StringsXML() ([]byte, error)

StringsXML reads and returns the raw bytes of res/values/strings.xml. The bytes are plain XML and can be scanned directly.

type Source

type Source struct {
	Name string     // relative path within the APK (e.g. "classes.dex", "assets/config.js")
	Type SourceType // what kind of source this is
	Data []byte     // raw bytes, populated when requested
}

Source is a named, typed reference to raw bytes within an APK.

type SourceType

type SourceType int

SourceType identifies the kind of scannable source within an APK.

const (
	SourceDEX SourceType = iota
	SourceManifest
	SourceStringsXML
	SourceAsset
)

func (SourceType) String

func (st SourceType) String() string

String returns a human-readable label for verbose logging.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL