5 ms·
This was a few years back but I had token generation working with something much simpler than Corellium using https://github.com/unicorn-engine/unicorn https://
by sprite 6y ago
This was a few years back but I had token generation working with something much simpler than Corellium using https://github.com/unicorn-engine/unicorn https://github.com/unicorn-engine/unicorn emulator [You will need to set up CommPage, handle system and mach traps, load dyld, etc]. They've probably added more security since then but back when I looked at it some of the data that was encrypted in the token off the top of my head was:
- Request Path
- Timestamp
- Snapchat Binary Size
- Bit Flags for various hack checks such as jailbreak, checks for various tweaks, etc.
- Device Type
- iOS Version
- A pair of counters, I believe these were being used to detect real devices being used as signature proxies.
- A unique device ID generated at startup
I can't remember which one of the tokens this was for. There is a X-Snapchat-Client-Token used at login if I remember correctly and X-Snapchat-Client-Auth-Token which is used for every request.
I never ended up using it for anything but it was a lot of fun getting token generation working through emulation. I'm not sure if I was actually able to bypass all their checks or if it would have been detected had I actually tried to deploy it for something in production.