No description
  • Smali 99.8%
  • HTML 0.2%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
2026-10-04 16:49:50 +02:00
com.pay4vend.bapp-debuggable-aligned PATCH: dump pwdauth and cogeskey 2026-10-04 16:27:09 +02:00
slop first commit 2026-10-04 14:18:36 +02:00
.envrc first commit 2026-10-04 14:18:36 +02:00
.gitignore first commit 2026-10-04 14:18:36 +02:00
android-studio-project-structure-modules.png first commit 2026-10-04 14:18:36 +02:00
android-studio-project-structure.png first commit 2026-10-04 14:18:36 +02:00
debug.keystore first commit 2026-10-04 14:18:36 +02:00
flake.lock first commit 2026-10-04 14:18:36 +02:00
flake.nix first commit 2026-10-04 14:18:36 +02:00
hello.js first commit 2026-10-04 14:18:36 +02:00
readme.md added secrets 2026-10-04 16:49:50 +02:00

bapp reversing

get the apk:

apkeep --app com.pay4vend.bapp /tmp
unzip com.pay4vend.bapp.xapk -d og

merge the split apks:

APKEditor m -i /tmp/og -o /tmp/com.pay4vend.bapp-merged.apk

decompile:

apktool d /tmp/com.pay4vend.bapp-merged.apk -o /tmp/out

make debuggable adding android:debuggable="true" to the application tag in out/AndroidManifest.xml

rebuild:

apktool b /tmp/out -o /tmp/com.pay4vend.bapp-debuggable.apk

zipalign:

zipalign -p 4 /tmp/com.pay4vend.bapp-debuggable.apk com.pay4vend.bapp-debuggable-aligned.apk

sign (password is orsettone):

apksigner sign --ks debug.keystore com.pay4vend.bapp-debuggable-aligned.apk

com.pay4vend.bapp-debuggable-aligned.apk is the debuggable version of the application we use as base.

now, a few options:

  • open ^^ in jadx-gui
  • decompile with jadx com.pay4vend.bapp-debuggable-aligned.apk -d /tmp/com.pay4vend.bapp-debuggable-aligned-decompiled
  • profile/debug with android studio
  • keep patching smali and rebuild following same steps as above

extra

lineage

frida

  • curl -LO https://github.com/frida/frida/releases/download/17.19.0/frida-server-17.19.0-android-arm64.xz
  • unxz frida-server-17.19.0-android-arm64.xz
  • adb push frida-server-17.19.0-android-arm64 /data/local/tmp/frida-server
  • adb shell su -c "chmod 755 /data/local/tmp/frida-server"
  • adb shell "su -c 'nohup /data/local/tmp/frida-server >/dev/null 2>&1 &'"
  • frida-ps -Uai
  • frida -U -f com.pay4vend.bapp -l hello.js just frida -U -n B.APP -l hello.js
  • frida-ps -Uai
  • frida -U -f com.pay4vend.bapp -l hello.js just frida -U -n B.APP -l hello.js

if frida makes application crash, embed the gadget instead

frida gadget embedding

  • apktool d /tmp/com.pay4vend.bapp-merged.apk -o /tmp/out
  • curl -LO https://github.com/frida/frida/releases/download/17.19.0/frida-gadget-17.19.0-android-arm64.so.xz
  • unxz frida-gadget-17.19.0-android-arm64.so.xz
  • mv frida-gadget-17.19.0-android-arm64.so /tmp/out/lib/arm64-v8a/libgadget.so
  • echo '{"interaction":{"type":"script","path":"/data/local/tmp/hello.js","on_change":"reload"}}' > /tmp/out/lib/arm64-v8a/libgadget.config.so
  • adb push hello.js /data/local/tmp/hello.js
  • adb shell su -c 'chmod 644 /data/local/tmp/hello.js'

then add these two instructions:

# smali: first line of MyApplication.onCreate →
#   const-string v0, "gadget"
#   invoke-static {v0}, Ljava/lang/System;->loadLibrary(Ljava/lang/String;)V

start capturing logs

adb logcat -c && adb logcat -b crash -c
adb shell am force-stop com.pay4vend.bapp
adb logcat --pid=$(adb shell pidof -s com.pay4vend.bapp) -v threadtime > bapp.log

debugging with android studio

  • decompile with jadx: jadx -d /tmp/aligned aligned.apk
  • create a project in android studio with "profile or debug apk"
  • make sure to configure jdk/sdk (see screenshots)
  • in the left sidebar open java/com/pay4vend/bapp/main/MainActivity.smali
  • click the "attach kotlin/java sources" popup and attach /tmp/aligned/sources
  • profit

notes

  • defpackage/oi contains service discovery and many other cool things, it is setting something related to movimenti so this might be the logic to recharge with coins
  • follow references of the toString method from com.pay4vend.bapp.classes.Movimenti
  • d40 does encryption/decryption
  • interesting:
    • an external service: https://service.pay4vend.com/Dashboard/EWSGateway
    • some kind of token: a!01s
    • some kind of IV: IQ8yi2KiX59J#6Jv5JpH<KN8JypC02

patches

1fa8df1a49 print idCoges and pwdAuth

run: adb logcat -d -s P4VDUMP

10-04 16:25:30.725 14890 15020 I P4VDUMP : W/put  idCoges1 = 97531864
10-04 16:25:30.726 14890 15020 I P4VDUMP : W/put  pwdAuth1 = 51713556
10-04 16:25:30.727 14890 15020 I P4VDUMP : W/put  idCoges2 = 23451245
10-04 16:25:30.728 14890 15020 I P4VDUMP : W/put  pwdAuth2 = 64390773
10-04 16:25:30.729 14890 15020 I P4VDUMP : W/put  idCoges3 = 21321431
10-04 16:25:30.730 14890 15020 I P4VDUMP : W/put  pwdAuth3 = 29384762
10-04 16:25:31.153 14890 15036 I P4VDUMP : W/put  idCoges1 = 97531864
10-04 16:25:31.153 14890 15036 I P4VDUMP : W/put  pwdAuth1 = 51713556
10-04 16:25:31.154 14890 15036 I P4VDUMP : W/put  idCoges2 = 23451245
10-04 16:25:31.154 14890 15036 I P4VDUMP : W/put  pwdAuth2 = 64390773
10-04 16:25:31.154 14890 15036 I P4VDUMP : W/put  idCoges3 = 21321431
10-04 16:25:31.155 14890 15036 I P4VDUMP : W/put  pwdAuth3 = 29384762