Re-implementation of the "ilnk" protocol used on some cheap chinese cameras (sometimes branded as 'A9').
Per pictures the main chip is TXW817 (chinese, eng, google translate)
The interesting implementation is in libvdp.so, part of the apk bundle.
Protocol reversing was done with a combination of static analysis of the shared object with Ghidra and dynamic analysis with Frida.
The headers reversed with Ghidra are at types/all.h. They are almost not used by this minimal implementation though.
The hooks used with frida are at frida-hooks.js, but it's mostly a playground - some useful functions got deleted once I understood the protocol.
There's also a pretty crappy Wireshark dissector at dissector.lua. You can install it with make install-wireshark-dissector.
Running
To execute the server, run make run; JPEG files will be created in a folder named captures.
There's no live-stream server built into this project yet.
Protocol
The protocol is weirdly complex, though very little communication is necessary to use the device
To establish a session, a few control packets are sent.
---
title: Establish session
---
sequenceDiagram
autonumber
App->>+Cam: LanSearch
Cam->>-App: PunchPkt (SerialNo)
App->>+Cam: P2PRdy
Cam->>-App: P2PRdy
App->>+Cam: ConnectUser
Cam->>-App: ConnectUserAck (Video Token)
loop Every 400-500ms
Cam-->>+App: P2PAlive
App-->>-Cam: P2PAliveAck
end
To start a stream, a single control packet is sent.
The received stream is broken up into 1028 byte payloads, along with a sequence number.
Stitching the payloads together yields JPEG frames for video, and (TBD) for audio.
---
title: Stream audio/video
---
sequenceDiagram
App->>Cam: StreamStart (with Token)
loop
Cam-->>+App: Audio/Video Payload
App-->>-Cam: DrwAck
end
Take APK from emulator/sacrificial device
adb shell pm list packages | grep ysx
adb shell pm path com.ysxlite.cam
adb shell pm path com.ysxlite.cam | while read -r line ; do adb pull $(echo $line | cut -d: -f2-) ; done
Push to sacrificial device
adb install-multiple *apk