No description
- Smali 99.8%
- HTML 0.2%
| Filename | Latest commit message | Latest commit date |
|---|---|---|
| com.pay4vend.bapp-debuggable-aligned | ||
| slop | ||
| .envrc | ||
| .gitignore | ||
| android-studio-project-structure-modules.png | ||
| android-studio-project-structure.png | ||
| debug.keystore | ||
| flake.lock | ||
| flake.nix | ||
| hello.js | ||
| readme.md | ||
bapp reversing
get the apk:
apkeep --app com.pay4vend.bapp /tmp
unzip com.pay4vend.bapp.xapk -d og
merge the split apks:
APKEditor m -i /tmp/og -o /tmp/com.pay4vend.bapp-merged.apk
decompile:
apktool d /tmp/com.pay4vend.bapp-merged.apk -o /tmp/out
make debuggable adding android:debuggable="true" to the application tag in out/AndroidManifest.xml
rebuild:
apktool b /tmp/out -o /tmp/com.pay4vend.bapp-debuggable.apk
zipalign:
zipalign -p 4 /tmp/com.pay4vend.bapp-debuggable.apk com.pay4vend.bapp-debuggable-aligned.apk
sign (password is orsettone):
apksigner sign --ks debug.keystore com.pay4vend.bapp-debuggable-aligned.apk
com.pay4vend.bapp-debuggable-aligned.apk is the debuggable version of the application we use as base.
now, a few options:
- open ^^ in jadx-gui
- decompile with
jadx com.pay4vend.bapp-debuggable-aligned.apk -d /tmp/com.pay4vend.bapp-debuggable-aligned-decompiled - profile/debug with android studio
- keep patching smali and rebuild following same steps as above
extra
lineage
- https://wiki.lineageos.org/devices/grus/install/
- https://github.com/MindTheGapps/15.0.0-arm64/releases/tag/MindTheGapps-15.0.0-arm64-20260915_032013
- https://github.com/topjohnwu/Magisk/releases/tag/v30.7
- install magisk module: https://github.com/heddxh/userdebug-without-debug-magisk https://stackoverflow.com/a/79727270
- enable zygisk (magisk settings), install https://github.com/JingMatrix/Vector/releases/tag/v2.2, install fake location
- https://mixplorer.com/
- https://f-droid.org install NetGuard and block
- firebaseinstallations.googleapis.com
- firebase-settings.crashlytics.com
- app-measurement.com
- mtalk.google.com
frida
curl -LO https://github.com/frida/frida/releases/download/17.19.0/frida-server-17.19.0-android-arm64.xzunxz frida-server-17.19.0-android-arm64.xzadb push frida-server-17.19.0-android-arm64 /data/local/tmp/frida-serveradb shell su -c "chmod 755 /data/local/tmp/frida-server"adb shell "su -c 'nohup /data/local/tmp/frida-server >/dev/null 2>&1 &'"frida-ps -Uaifrida -U -f com.pay4vend.bapp -l hello.jsjustfrida -U -n B.APP -l hello.jsfrida-ps -Uaifrida -U -f com.pay4vend.bapp -l hello.jsjustfrida -U -n B.APP -l hello.js
if frida makes application crash, embed the gadget instead
frida gadget embedding
apktool d /tmp/com.pay4vend.bapp-merged.apk -o /tmp/outcurl -LO https://github.com/frida/frida/releases/download/17.19.0/frida-gadget-17.19.0-android-arm64.so.xzunxz frida-gadget-17.19.0-android-arm64.so.xzmv frida-gadget-17.19.0-android-arm64.so /tmp/out/lib/arm64-v8a/libgadget.soecho '{"interaction":{"type":"script","path":"/data/local/tmp/hello.js","on_change":"reload"}}' > /tmp/out/lib/arm64-v8a/libgadget.config.soadb push hello.js /data/local/tmp/hello.jsadb shell su -c 'chmod 644 /data/local/tmp/hello.js'
then add these two instructions:
# smali: first line of MyApplication.onCreate →
# const-string v0, "gadget"
# invoke-static {v0}, Ljava/lang/System;->loadLibrary(Ljava/lang/String;)V
start capturing logs
adb logcat -c && adb logcat -b crash -c
adb shell am force-stop com.pay4vend.bapp
adb logcat --pid=$(adb shell pidof -s com.pay4vend.bapp) -v threadtime > bapp.log
debugging with android studio
- decompile with jadx:
jadx -d /tmp/aligned aligned.apk - create a project in android studio with "profile or debug apk"
- make sure to configure jdk/sdk (see screenshots)
- in the left sidebar open
java/com/pay4vend/bapp/main/MainActivity.smali - click the "attach kotlin/java sources" popup and attach
/tmp/aligned/sources - profit
notes
defpackage/oicontains service discovery and many other cool things, it is setting something related tomovimentiso this might be the logic to recharge with coins- follow references of the
toStringmethod fromcom.pay4vend.bapp.classes.Movimenti d40does encryption/decryption- interesting:
- an external service:
https://service.pay4vend.com/Dashboard/EWSGateway - some kind of token:
a!01s - some kind of IV:
IQ8yi2KiX59J#6Jv5JpH<KN8JypC02
- an external service:
patches
1fa8df1a49 print idCoges and pwdAuth
run: adb logcat -d -s P4VDUMP
10-04 16:25:30.725 14890 15020 I P4VDUMP : W/put idCoges1 = 97531864
10-04 16:25:30.726 14890 15020 I P4VDUMP : W/put pwdAuth1 = 51713556
10-04 16:25:30.727 14890 15020 I P4VDUMP : W/put idCoges2 = 23451245
10-04 16:25:30.728 14890 15020 I P4VDUMP : W/put pwdAuth2 = 64390773
10-04 16:25:30.729 14890 15020 I P4VDUMP : W/put idCoges3 = 21321431
10-04 16:25:30.730 14890 15020 I P4VDUMP : W/put pwdAuth3 = 29384762
10-04 16:25:31.153 14890 15036 I P4VDUMP : W/put idCoges1 = 97531864
10-04 16:25:31.153 14890 15036 I P4VDUMP : W/put pwdAuth1 = 51713556
10-04 16:25:31.154 14890 15036 I P4VDUMP : W/put idCoges2 = 23451245
10-04 16:25:31.154 14890 15036 I P4VDUMP : W/put pwdAuth2 = 64390773
10-04 16:25:31.154 14890 15036 I P4VDUMP : W/put idCoges3 = 21321431
10-04 16:25:31.155 14890 15036 I P4VDUMP : W/put pwdAuth3 = 29384762