2024-01-26 17:49:36 +01:00
2024-01-15 15:06:07 +01:00
2024-01-26 17:35:57 +01:00
2024-01-24 22:54:32 +01:00
2024-01-25 00:11:58 +01:00
2024-01-25 10:09:41 +01:00
2024-01-20 18:44:05 +01:00
2024-01-26 17:47:37 +01:00
2024-01-26 00:41:04 +01:00
2024-01-26 17:47:41 +01:00
2024-01-26 17:36:06 +01:00
2024-01-26 17:36:06 +01:00
2024-01-26 17:21:38 +01:00
2024-01-26 17:36:06 +01:00
2024-01-18 12:34:39 +01:00
2024-01-26 17:47:41 +01:00
2024-01-25 00:11:58 +01:00
2024-01-25 00:11:58 +01:00
2024-01-26 17:49:36 +01:00
2024-01-26 17:21:38 +01:00
2024-01-26 17:47:41 +01:00
2024-01-26 17:36:06 +01:00
2024-01-26 17:21:38 +01:00
2024-01-25 00:18:18 +01:00

Re-implementation of the "ilnk" protocol used on some cheap chinese cameras (sometimes branded as 'A9').

Per pictures the main chip is TXW817 (chinese, eng, google translate)

The interesting implementation is in libvdp.so, part of the apk bundle.

Protocol reversing was done with a combination of static analysis of the shared object with Ghidra and dynamic analysis with Frida.

The headers reversed with Ghidra are at types/all.h. They are almost not used by this minimal implementation though.

The hooks used with frida are at frida-hooks.js, but it's mostly a playground - some useful functions got deleted once I understood the protocol.

To execute the server, run make run; JPEG files will be created in a folder named captures.

Take APK from emulator/sacrificial device

adb shell pm list packages | grep ysx
adb shell pm path com.ysxlite.cam
adb shell pm path com.ysxlite.cam | while read -r line ; do adb pull $(echo $line | cut -d: -f2-) ;  done

Push to sacrificial device

adb install-multiple *apk

Frida install Android

docs

S
Description
Implementation of iLnk/iLnkP2P/PPPP protocol for X5/A9 cameras
Readme
3.9 MiB
Languages
JavaScript 38.9%
TypeScript 36.8%
Lua 15%
Python 3.7%
HTML 3.2%
Other 2.4%