From 9da66ecafc286d0d65ba11f4f3ded3f8ec25359a Mon Sep 17 00:00:00 2001 From: DavidVentura Date: Fri, 26 Jan 2024 17:47:41 +0100 Subject: [PATCH] small cleanup --- Makefile | 4 ++-- README.md | 11 +++++++++-- asd.js => frida-hooks.js | 0 3 files changed, 11 insertions(+), 4 deletions(-) rename asd.js => frida-hooks.js (100%) diff --git a/Makefile b/Makefile index a889ec4..eee8a3a 100644 --- a/Makefile +++ b/Makefile @@ -1,7 +1,7 @@ .PHONY: run hook install-wireshark-dissector test -bundle.js: asd.js func_replacements.js - ~/node_modules/.bin/frida-compile -o $@ asd.js +bundle.js: frida-hooks.js func_replacements.js + ~/node_modules/.bin/frida-compile -o $@ frida-hooks.js venv: requirements.txt python3.11 -m venv venv diff --git a/README.md b/README.md index 3b4925a..b255d6f 100644 --- a/README.md +++ b/README.md @@ -1,4 +1,4 @@ -Reversing a camera +Re-implementation of the "ilnk" protocol used on some cheap chinese cameras (sometimes branded as 'A9'). * Bought [here](https://www.aliexpress.com/item/1005006287788979.html). * App is [YsxLite](https://play.google.com/store/apps/details?id=com.ysxlite.cam&hl=en&gl=US) @@ -6,8 +6,15 @@ Reversing a camera Per [pictures](https://github.com/DavidVentura/cam-reverse/blob/master/pics/pcb.jpg?raw=true) the main chip is TXW817 ([chinese](https://www.taixin-semi.com/Product/ProductDetail?productId=306), [eng, google translate](https://www-taixin--semi-com.translate.goog/Product/ProductDetail?productId=306&_x_tr_sl=auto&_x_tr_tl=en&_x_tr_hl=en&_x_tr_pto=wapp)) -The interesting implementation is in `libvdp.so`, part of the apk bundle. This repo uses Frida for live analysis of the .so file. +The interesting implementation is in `libvdp.so`, part of the apk bundle. +Protocol reversing was done with a combination of static analysis of the shared object with [Ghidra](https://ghidra-sre.org/) and dynamic analysis with [Frida](https://frida.re/docs/javascript-api/). + +The headers reversed with Ghidra are at `types/all.h`. They are almost not used by this minimal implementation though. + +The hooks used with frida are at `frida-hooks.js`, but it's mostly a playground - some useful functions got deleted once I understood the protocol. + +To execute the server, run `make run`; JPEG files will be created in a folder named `captures`. ### Take APK from emulator/sacrificial device ``` diff --git a/asd.js b/frida-hooks.js similarity index 100% rename from asd.js rename to frida-hooks.js