2.8 KiB
Re-implementation of the "ilnk" protocol used on some cheap chinese cameras (sometimes branded as 'A9').
- Bought here.
- Waiting for this A9 camera to validate support.
- App is YsxLite
Per pictures the main chip is TXW817 (chinese, eng, google translate)
The interesting implementation is in libvdp.so, part of the apk bundle.
Protocol reversing was done with a combination of static analysis of the shared object with Ghidra and dynamic analysis with Frida.
The headers reversed with Ghidra are at types/all.h. They are almost not used by this minimal implementation though.
The hooks used with frida are at frida-hooks.js, but it's mostly a playground - some useful functions got deleted once I understood the protocol.
There's also a pretty crappy Wireshark dissector at dissector.lua. You can install it with make install-wireshark-dissector.
Running
To execute the server, run make run; JPEG files will be created in a folder named captures.
There's no live-stream server built into this project yet.
Protocol
The protocol is weirdly complex, though very little communication is necessary to use the device
To establish a session, a few control packets are sent.
---
title: Establish session
---
sequenceDiagram
autonumber
App->>+Cam: LanSearch
Cam->>-App: PunchPkt (SerialNo)
App->>+Cam: P2PRdy
Cam->>-App: P2PRdy
App->>+Cam: ConnectUser
Cam->>-App: ConnectUserAck (Video Token)
loop Every 400-500ms
Cam-->>+App: P2PAlive
App-->>-Cam: P2PAliveAck
end
To start a stream, a single control packet is sent.
The received stream is broken up into 1028 byte payloads, along with a sequence number.
Stitching the payloads together yields JPEG frames for video, and (TBD) for audio.
---
title: Stream audio/video
---
sequenceDiagram
App->>Cam: StreamStart (with Token)
loop
Cam-->>+App: Audio/Video Payload
App-->>-Cam: DrwAck
end
Take APK from emulator/sacrificial device
adb shell pm list packages | grep ysx
adb shell pm path com.ysxlite.cam
adb shell pm path com.ysxlite.cam | while read -r line ; do adb pull $(echo $line | cut -d: -f2-) ; done
Push to sacrificial device
adb install-multiple *apk