46 ms·
Reverse Engineering Snapchat (Part II): Debofuscating the Undeobfuscatable
- drfuchs 6y ago“Debofuscating”???
- gruez 6y agoI'm not sure what you're asking. Obfsucating means making the code unreadable/unintelligible. Think minimfy js on steroids. Debofuscating just means undoing the obfuscation.
- moscovium 6y ago'Debo' or 'Deob'?
- wfme 6y agoI can't find any formal definitions after a quick google search, but there seem to be a ton of uses of "debofuscating" in different research papers.
- mmm_grayons 6y agoIt's just a typo, and we're all human. Maybe focus on the really interesting research instead?
- moscovium 6y agoi was just clarifying the poster above lol
- Google234 6y agoNice contribution to the discussion /s
- craftinator 6y agoMaybe you don't understand Latin root words as prefixes and suffixes, in which case I highly recommend doing a bit of research into it. It really makes the English language more understandable when you can parse words based on their roots rather than on rote memorization.
- KMag 6y agoThey were commenting on "bofuscate" vs. "obfuscate". I suspect they've got a healthy understanding of what the prefix "de" means here.
- saagarjha 6y agoIt's a typo in the article title, relax. The <title> has the correct spelling.
- mbrevda1 6y agoHe obfuscated the title!
- 3eed 6y agoThat guy gets it
- hackernewsn00b 6y agoHey OP, since you're here: I find this pretty hard to follow. Would you be open to writing a longform version of this aimed at the tutorial level? Reading between the lines, I would guess you're trying to demonstrate that you really know what you're doing. Maybe as a proof of concept for possible employment opportunities. If so, that's great! Good luck. But if I were interested in reverse engineering some other app, I don't think I could understand what you've done well enough to use these techniques on that app. Except maybe the breakpointing within `fuck_debug`, that was pretty slick and easy to follow.
- masteruvpuppetz 6y ago+1. Need a simpler version if possible.
- saagarjha 6y agoI found it fairly reasonable, although you'd have to have a general idea of the subject beforehand. I read it as a being aimed at reverse engineers who are looking for some general techniques to bypass common anti-debugging/obfuscation features rather than "how to reverse engineer apps 101".
- reagent_finder 6y ago"Reasonable" is a stretch, "interesting" is the right word. Personally I'd put this in the "Oh, huh" box along with quantum crypto. It's interesting, it's complex and it's got way too many engineering hours behind it... but ultimately for 99% of people or even 99% of computer scientists or HN readers, it's just fascinating trivia. I absolutely appreciate these posts, this guy spent WEEKS delving into the depths of SnapChat just for the joy of discovery. Maybe a good classification would be that part 1 is detailing a number of obfuscation techniques and the key thing to take away is that all of them CAN be bypassed.
- drudu 6y agoObviously not the OP but I think that a longform version of this would be an entire book/college level course. I wish I could learn how to reverse state of the art obfuscation in a single, long post but that's just not how it works.
- wayne 6y agoThis level of API obfuscation reminds me of forever ago when MSN Messenger figured out AOL's AIM API, so MSN Messenger could send AIM messages, which annoyed AOL. AOL would make API changes to break MSN, but MSN would update the client and stay ahead. Eventually to make the API uncloneable, AOL changed their payload to exploit a buffer overrun in their own AIM clients that wouldn't be in the MSN clients. https://nplusonemag.com/issue-19/essays/chat-wars/ https://nplusonemag.com/issue-19/essays/chat-wars/
- spideymans 6y agoInteresting time that was. I don't believe that any of these internet giants would ship a feature that is effectively a hack, in this day and age. HTC and Palm also engaged in the back-and-forth, when Palm attempted to get their OS to sync with iTunes. https://www.wired.com/2009/10/palm-pre-itunes/ https://www.wired.com/2009/10/palm-pre-itunes/
- Roritharr 6y agoYou will be scared to find out that a lot of Fintech has webscraping as an accepted part of their stack...
- piva00 6y agoYup, not only as accepted part of their stack but also offered as a product that sometimes users need to input their bank details in 3rd party applications from some fintechs. If you look under the hood there is a lot of grey areas being exploited by fintech, all around...
- saltedonion 6y agoVery interesting. I think this would likely lead to lawsuits today, under a complaint violating DMCA.
- xmprt 6y agoIs there legal precedent for copyrighting APIs?
- stephc_int13 6y agoAs someone who wrote similar obfuscators (manually) back in 2003-2006 to protect a few indie games distributed on PocketPC (ARM7/WinCE) I found it quite conforting to see that the techniques are still similar. I wonder about something, how long did it take?
- saagarjha 6y agoI’m surprised that Snapchat doesn’t check for the mere presence of a debugger and instead tries to look for breakpoints. Or perhaps you’ve already found and patched those checks out?
- 3eed 6y agoIt does check for a debugger. But that would be through sysctl, or the csops sys call, which would be trivial to patch and a single point of failure.
- dang 6y agoThe related previous thread: https://news.ycombinator.com/item?id=23557998 https://news.ycombinator.com/item?id=23557998
- coolspot 6y agoShouldn’t you be able to find any code that scans for breakpoints easily and patch it to be blind?
- underdeserver 6y agoFor fuckup_debugging, can't you use hardware breakpoints instead? Also, why not patch the binary? I think iteratively patching out protections (in a repeatable, versioned way) would be my approach. It is then applicable to other binaries as well.
- bluesign 6y agoNot the OP, but I can answer I guess. Hardware breakpoints are very limited (number of breakpoints you can put). Usually when you are debugging a decent target, number of breakpoints you use easily reach 50-60.
- underdeserver 6y agoNo doubt, but it's better than pausing every time. I guess with scripting it isn't really different.
- saagarjha 6y agoHardware breakpoints are a little complicated on iOS. And patching the binary would of course only work if no other code verified the validity of the page you touched.
- 3eed 6y agoAre hardware breakpoints even possible on iOS? And correct, you can't patch the binary because there many anti-tampering measures, you could probably bypass those, but that's going a different route.
- Method5440 6y agoAnyone else picture Deebo from “Friday” (Zeus from “No Holds Barred”) smashing apart source code after reading the title? Prediction: Just me. By the way, love both articles. Thanks for taking the time to share.
- zimmerfrei 6y agoBoth iOS and recent Androids have by now a form of app attestation: the server can tell if the caller is the legitimate app or not (with good enough confidence - as everything, it's not unbreakable). Doesn't that make obfuscation kind of pointless? Even if your knock-off app knows everything about the API of the original service, it won't be able to use it because it is not the genuine app or maybe it is but it is not running in a real iOS/Android device. Or maybe this is only meant to include non-Android certified phones (= China)?
- zemnmez 6y agoseems like something having a rooted os would fix pretty quickly
- power78 6y agoSeems like the creator of Magisk Manager could not get around Android's implementation: https://twitter.com/topjohnwu/status/1245956080779198464?s=19 https://twitter.com/topjohnwu/status/1245956080779198464?s=1...
- 3eed 6y agoDeviceCheck on iOS support iOS 11 and up. Which would cut off 7% of users[1], a bit extreme. But when the time comes when you don't have to cut off anyone, it'll be very interesting to see what'll happen on iOS. Someone will bypass it? Death of reverse engineering? Who knows. On Android, an HN user mentioned in the previous post that it's a solved problem[2]. [1]: https://developer.apple.com/support/app-store/ https://developer.apple.com/support/app-store/ [2]: https://magiskmanager.com/ https://magiskmanager.com/
- whs 6y agoI tried adding safetynet attestation on launch for all Android clients and ran into rate limit pretty fast. (iirc it's about 10k/hr) Devicecheck have no such problem though, but it doesn't really feel designed for the use case - you need to implement an anti replay system yourself.
- sintax 6y agoFor MBA, there's also Arybo[1] from Quarkslab. Never used it and seeing the reference to SSPAM, I assume the author is aware of the tool. [1] https://github.com/quarkslab/arybo https://github.com/quarkslab/arybo
- 3eed 6y agoI came across Arybo while working on the binary but I can't remember why I didn't use it, this is vague memory now. Anyway it does the job in one go, I added an edit.
- raverbashing 6y agoI wonder if the Android version uses the same technique and if not, if it would be harder/easier to break
- sarabande 6y agoThe title is misspelled (s/Debofusc/Deobfusc/).