ar
Feedback
Dimension of TDO

Dimension of TDO

الذهاب إلى القناة على Telegram

Technical Knowledge For Educational Purposes Not for business, promotion Or releasing, requesting mods Respect Hard Works Don't be Leecher We are Responsible only for our Posts Contact us @TDOhexSupportBot by Team of @MuhammadRidwan87

إظهار المزيد
Buy Ad
لا توجد بيانات
المشتركون
+1224 ساعات
+347 أيام
+17230 أيام

جاري تحميل البيانات...

سحابة العلامات
لا توجد بيانات
هل تواجه مشاكل؟ يرجى تحديث الصفحة أو الاتصال بمدير الدعم الخاص بنا.
الإشارات الواردة والصادرة
---
---
---
---
---
---
جذب المشتركين
يناير '26
يناير '26
+31
في 0 قنوات
ديسمبر '25
+253
في 2 قنوات
Get PRO
نوفمبر '25
+223
في 4 قنوات
Get PRO
أكتوبر '25
+238
في 8 قنوات
Get PRO
سبتمبر '25
+232
في 7 قنوات
Get PRO
أغسطس '25
+223
في 3 قنوات
Get PRO
يوليو '25
+206
في 3 قنوات
Get PRO
يونيو '25
+257
في 4 قنوات
Get PRO
مايو '25
+190
في 2 قنوات
Get PRO
أبريل '25
+236
في 6 قنوات
Get PRO
مارس '25
+256
في 7 قنوات
Get PRO
فبراير '25
+249
في 5 قنوات
Get PRO
يناير '25
+299
في 13 قنوات
Get PRO
ديسمبر '24
+241
في 7 قنوات
Get PRO
نوفمبر '24
+293
في 6 قنوات
Get PRO
أكتوبر '24
+244
في 6 قنوات
Get PRO
سبتمبر '24
+331
في 8 قنوات
Get PRO
أغسطس '24
+328
في 9 قنوات
Get PRO
يوليو '24
+322
في 14 قنوات
Get PRO
يونيو '24
+301
في 9 قنوات
Get PRO
مايو '24
+302
في 9 قنوات
Get PRO
أبريل '24
+260
في 7 قنوات
Get PRO
مارس '24
+288
في 4 قنوات
Get PRO
فبراير '24
+648
في 16 قنوات
Get PRO
يناير '24
+177
في 4 قنوات
Get PRO
ديسمبر '23
+217
في 5 قنوات
Get PRO
نوفمبر '23
+146
في 5 قنوات
Get PRO
أكتوبر '23
+127
في 1 قنوات
Get PRO
سبتمبر '23
+121
في 0 قنوات
Get PRO
أغسطس '23
+131
في 0 قنوات
Get PRO
يوليو '23
+103
في 0 قنوات
Get PRO
يونيو '23
+130
في 0 قنوات
Get PRO
مايو '23
+118
في 0 قنوات
Get PRO
أبريل '23
+80
في 0 قنوات
Get PRO
مارس '23
+83
في 0 قنوات
Get PRO
فبراير '23
+149
في 0 قنوات
Get PRO
يناير '23
+341
في 0 قنوات
Get PRO
ديسمبر '22
+96
في 0 قنوات
Get PRO
نوفمبر '22
+116
في 0 قنوات
Get PRO
أكتوبر '22
+65
في 0 قنوات
Get PRO
سبتمبر '22
+40
في 0 قنوات
Get PRO
أغسطس '22
+100
في 0 قنوات
Get PRO
يوليو '22
+21
في 0 قنوات
Get PRO
يونيو '22
+9
في 0 قنوات
Get PRO
مايو '22
+16
في 0 قنوات
Get PRO
أبريل '22
+52
في 0 قنوات
Get PRO
مارس '22
+15
في 0 قنوات
Get PRO
فبراير '22
+42
في 0 قنوات
Get PRO
يناير '22
+25
في 0 قنوات
Get PRO
ديسمبر '21
+17
في 0 قنوات
Get PRO
نوفمبر '21
+41
في 0 قنوات
Get PRO
أكتوبر '21
+74
في 0 قنوات
Get PRO
سبتمبر '21
+42
في 0 قنوات
Get PRO
أغسطس '21
+132
في 0 قنوات
Get PRO
يوليو '21
+29
في 0 قنوات
Get PRO
يونيو '21
+85
في 0 قنوات
Get PRO
مايو '21
+34
في 0 قنوات
Get PRO
أبريل '21
+48
في 0 قنوات
Get PRO
مارس '21
+164
في 0 قنوات
Get PRO
فبراير '21
+715
في 0 قنوات
Get PRO
يناير '21
+161
في 0 قنوات
Get PRO
ديسمبر '20
+2 954
في 0 قنوات
التاريخ
نمو المشتركين
الإشارات
القنوات
04 يناير+4
03 يناير+12
02 يناير+10
01 يناير+5
منشورات القناة
I thank you all for your support and contributions. I hope to continue receiving your support in the future. ❤️ Last year, I attempted to convey an important principle: Knowledge is not the exclusive property of any individual. The acquisition of knowledge requires two essential qualities—genuine intellectual seeking and sincere appreciation of knowledge itself. A true seeker approaches learning with humility rather than arrogance, and with gratitude rather than ingratitude. From this understanding, I presented the conclusion that: The root cause of all deprivation and stagnation is arrogance and ingratitude. This year, I would like to offer another foundational reflection: To become a better human being, one must embody the qualities of Sadiq (truthfulness) and Ameen (trustworthiness). - A Sadiq is an individual whose speech, intentions, and actions are consistently aligned with truth. - An Ameen is an individual upon whom others can place their trust without fear or hesitation. These two qualities are fundamental to personal excellence. Moreover, no individual can become an effective or ethical leader without truthfulness and trustworthiness. Truthfulness refines and disciplines the individual internally, while trustworthiness equips a person to positively influence society and contribute meaningfully to the wider world. If you want to choose a better leader, look for the qualities of truthfulness and trustworthiness in them. Truthfulness and trustworthiness share a common foundation: Trust. A trustworthy individual does not engage in falsehood, nor does he misuse power, authority, or knowledge. Therefore: One must guard against losing trust through lie or betrayal. - Choose humility over arrogance. - Choose gratitude over ingratitude. - Choose truth over falsehood. - Choose trustworthiness over betrayal. While this subject allows for extensive philosophical and motivational exploration, for those who are prepared to understand and accept these principles, this reflection is sufficient. ❤️ --From MuhammadRizwan-- ❤️ Join us, Follow us! @TDOhex @Android_Patches @TDOhex_Discussion https://github.com/muhammadrizwan87

2
Ban Notice: Leecher News We have permanently banned @imYouarefinished (5949636238) for repeatedly leeching content from our group and channel. Background: He is a moderator on the Mobilism forum and has a history of similar behavior. Previous reports (especially regarding Omar’s content) had already established him as a certified leecher. Only after being reported did he reluctantly credit Omar. Prior complaints were also filed by Marc and others. Latest Incident: Most recently, he stole the patch and idea from "ㅤㅤ5ter1!ngㅤ" without crediting either Sterling or the group. He didn’t even express basic gratitude for the learning he gained. We had previously requested: “At least remember and accept where you learned from” but his arrogance and ingratitude persisted. As we’ve said before: “Arrogance and ingratitude are the roots of all misfortune.” Please revisit these posts: 🔗 Post 1 https://t.me/TDOhex/474 🔗 Post 2 https://t.me/TDOhex_Discussion/20376 Additional Action: Supporter admins @carpedroidiem (67925274) and @keepitlalala (8033524430) have also been banned. Not for leeching, but for enabling and supporting a known leecher. We understand this won’t end leeching entirely. Our intent is to awaken your conscience (if any self-respect remains) so that you reflect on these disgraceful actions. - From Group Admin - ✄---------------------------------------- ✨ APKEditor Update ✨ The Debian package for APKEditor version 1.4.6 has been updated. 📦 Deb Package for APKEditor v1.4.6 https://t.me/TDOhex_Discussion/41644 Visit here to see what's new https://github.com/REAndroid/APKEditor/releases/tag/V1.4.6
3 794
3
Reminder 🔔: The Epic Games Store will reportedly offer 16 Mystery Games from December 11, 2025, to January 8, 2026, starting with a new game every day. And also remember that the Epic Game Store is available on Android. You can play the games. Link: https://store.epicgames.com/free-games First mystery game of epic games store: Hogwarts Legacy https://store.epicgames.com/en-US/p/hogwarts-legacy
3 569
4
HOW TO USE IL2CPP-TOOL What's in this Video: - Implementation of the tool - Dump il2cpp - Inspect the field value and patch it - Unlock ARLOOPA app Video Duration: 02:28 Video Size: 11.15M Demo App: ARLOOPA: AR Augmented Reality Version: 5.0.28(245) Play Store Link: https://play.google.com/store/apps/details?id=com.arloopa.arloopa Link to Download IL2CPP-TOOL: https://t.me/TDOhex_Discussion/78556 Other Parts: https://t.me/TDOhex_Discussion/77764 https://t.me/TDOhex_Discussion/77767 Smali Code: const-string v0, "Tool" invoke-static {v0}, Ljava/lang/System;->loadLibrary(Ljava/lang/String;)V ━━━━━━━━━━━━━━━━━━━ ♻️ Join Channel: @Android_Patches 📣 Main Channel: @TDOhex 💬 Discussion Group: @TDOhex_Discussion ━━━━━━━━━━━━━━━━━━━
5 707
5
🚀 DexDumper v2.0.0 Released! This update brings the biggest leap so far — full runtime configuration, smarter exclusions, and enhanced safety for DEX dumping operations. ✨ Highlights: ⚙️ Runtime Config System DexDumper now supports a flexible runtime configuration system. You can tweak behavior instantly through a .conf file — all without recompiling. It’s perfect for debugging or testing different setups quickly. Configurable Settings: - Second Scan - Scans Limit - Region Filtering - Exclusion List - Output path 👉 For more info https://github.com/muhammadrizwan87/dexdumper?tab=readme-ov-file#runtime-configuration-library_nameconf 🔒 SHA1 Exclusion Control Added a clean way to skip known or unwanted DEX files using their SHA1 hashes. This helps avoid re-dumping system or placeholder files, keeping your output clean and relevant. 🧠 Duplicate Prevention A new SHA1-based duplicate detector ensures that already dumped DEX files are not saved again. It saves both time and storage while maintaining accuracy in large dump sessions. 🧹 Safer Cleanup The cleanup routine now deletes only valid DEX dump files (matching the precise filename pattern). This prevents accidental removal of other files in the output directory — safer and smarter cleanup. 🔗 Github Repository: https://github.com/muhammadrizwan87/dexdumper.git ━━━━━━━━━━━━━━━━━━━ ♻️ Join Channel: @Android_Patches 📣 Main Channel: @TDOhex 💬 Discussion Group: @TDOhex_Discussion ━━━━━━━━━━━━━━━━━━━
2 507
6
🌎 How to Bypass Geo Restrictions in Android Apps and Games 📖 Background: In Android apps and games, geo-related information is commonly retrieved via TelephonyManager methods such as: - getNetworkOperatorName() / getSimOperatorName() — Operator/Carrier Name (e.g., "AT&T Mobility") - getNetworkOperator() / getSimOperator() — PLMN (MCC+MNC, e.g., "310410") - getNetworkCountryIso() / getSimCountryIso() — Country ISO code (e.g., "US") 🔗 TelephonyManager API: https://developer.android.com/reference/android/telephony/TelephonyManager At the smali level we can patch the code right after the invoke-virtual call and the move-result-object so that the register that received the string result is overwritten with a fixed string (dummy/fake values). Below are example regex searches and the replacement snippets to inject constant strings. 🛠️ Smali Patching Instructions 1️⃣ Spoofing Carrier Name 🔍 Search Pattern (Regex): (invoke-virtual\s\{(?:[pv]\d+)\},\sLandroid/telephony/TelephonyManager;->get(?:Network|Sim)OperatorName\(\)Ljava/lang/String;\n(?:\s*(?:[.#][^\n]*)?\n)*\s*move-result-object\s([pv]\d+))(?:\n\n\s*const-string\s\2,\s".*")? ✏️ Replace With: $1\n\n\tconst-string $2, "AT&T Mobility" This overrides the result of getNetworkOperatorName() or getSimOperatorName() with a hardcoded carrier name. 2️⃣ Spoofing PLMN (MCC+MNC) 🔍 Search Pattern (Regex): (invoke-virtual\s\{(?:[pv]\d+)\},\sLandroid/telephony/TelephonyManager;->get(?:Network|Sim)Operator\(\)Ljava/lang/String;\n(?:\s*(?:[.#][^\n]*)?\n)*\s*move-result-object\s([pv]\d+))(?:\n\n\s*const-string\s\2,\s".*")? ✏️ Replace With: $1\n\n\tconst-string $2, "310410" This sets the MCC+MNC code to "310410" (AT&T USA). 3️⃣ Spoofing Country ISO 🔍 Search Pattern (Regex): (invoke-virtual\s\{(?:[pv]\d+)\},\sLandroid/telephony/TelephonyManager;->get(?:Network|Sim)CountryIso\(\)Ljava/lang/String;\n(?:\s*(?:[.#][^\n]*)?\n)*\s*move-result-object\s([pv]\d+))(?:\n\n\s*const-string\s\2,\s".*")? ✏️ Replace With: $1\n\n\tconst-string $2, "US" This forces the app to believe the device is located in the United States. 🧠 Why These Regex Patterns Are Powerful These regexes are designed with advanced smali parsing in mind. Here's what makes them robust and reliable: 1. ✅ Comprehensive Matching: They capture all possible TelephonyManager calls, even if debug directives, annotations, or comments are present or absent. 2. 📏 Multi-line Resilience: Whether debug info appears single line or across multiple lines, the regex still matches accurately without breaking. 3. 🔁 Safe Reapplication: You can apply these regexes repeatedly without stacking duplicate replacements or injecting dummy code fragments. 📝 Notes: 1. Because this modifies smali code (dex disassembly), it will not work if the app uses native code, runtime-decrypted strings, or has tamper-proofing/encryption/packing that prevents straightforward smali patching. 2. This technique changes only the returned string values at the smali level; it does not handle other checks the app may make (e.g., location APIs, server-side verification, or other device identifiers). 3. To obtain MCC+MNC codes, you can check out the following resources. - 🌐 Website: https://mcc-mnc.net — A comprehensive database of Mobile Country Codes (MCC) and Mobile Network Codes (MNC). - 📦 GitHub Repository: https://github.com/P1sec/MCCMNC — An open-source collection of MCC/MNC data maintained by the community. ━━━━━━━━━━━━━━━━━━━ 📣 Main Channel: @TDOhex 📱Second Channel: @Android_Patches 💬 Discussion Group: @TDOhex_Discussion ━━━━━━━━━━━━━━━━━━━
4 275
7
🚀 DexDumper Update! 🚀 📌 What's New: - Added SHA1 Exclusion List to skip unwanted or known DEX files - Easy to configure ENABLE_SECOND_SCAN, THREAD_INITIAL_DELAY, SECOND_SCAN_DELAY, and OUTPUT_DIRECTORY_TEMPLATES - Updated README.md with new configuration details and usage notes 🔗 GitHub Repository: https://github.com/muhammadrizwan87/dexdumper.git 💡 Update now and take advantage of the new features! ━━━━━━━━━━━━━━━━━━━ 📣 Main Channel: @TDOhex 📱Second Channel: @Android_Patches 💬 Discussion Group: @TDOhex_Discussion ━━━━━━━━━━━━━━━━━━━
3 873
8
🎉 NEW RELEASE: DexDumper is Live! 🎉 We're releasing DexDumper - A sophisticated memory analysis library that extracts DEX files from running Android applications without requiring root access. 🔍 Key benefits: - Smart memory scanning - Sandbox/VM compatible - Lightweight resource usage 💡 Why You'll Love It: - No Frida required - No Xposed required - No root required - No adb required - No GameGuardian required - No extra tools, modules, or permissions required - No need to break the target app’s integrity - No PC needed — build directly on the device! - Respects app boundaries — completely legal! - Open source and community-driven! 🚀 Get Started: - Check out the repo - Star it to support the project - Easy to set up, Easy to use - Fork it, improve it, and let’s grow this project together 🔗 Github Repository: https://github.com/muhammadrizwan87/dexdumper.git 🔗 How to Use DexDumper https://t.me/TDOhex_Discussion/75820 📝 Notes: 1. DexDumper is currently in its development phase, so it may not work reliably on apps protected by advanced packers such as: DexProtect, Jiagu360, Ijami, Etc... 2. For Termux-based NDK builds, check out MrIkso’s AndroidIDE-NDK repo. Alternatively, use the GitHub Actions workflow to auto-compile the source — no manual setup needed, handles dependencies, and builds for all architectures. ━━━━━━━━━━━━━━━━━━━ ♻️ Join Channel: @Android_Patches 📣 Main Channel: @TDOhex 💬 Discussion Group: @TDOhex_Discussion ━━━━━━━━━━━━━━━━━━━
3 347
9
We’re currently looking for demo apps that require dex dumping. They should not be packed with high-level protectors like DexProtect, Jiagu360, or Ijami. If possible, keep emulator and debugger security disabled. If you’d like to share such APKs, please send them to our bot @TDOhexSupportBot. Note: This is for our research purposes only, so please do not request dumped dex files.
4 594
10
WebView API Interception: A Technical Demo What's in this Post: - Focus on intercepting and modifying API responses in Android WebView - Understanding raw data interception and fabricated (fake) response injection Note: This post has been rephrased using AI to enhance vocabulary, and due to Telegram’s limitations, it has been shared in markdown format. 👉 How to Bypass SSL Pinning on Android Devices https://t.me/TDOhex/485 ━━━━━━━━━━━━━━━━━━━ 📣 Main Channel: @TDOhex 📱Second Channel: @Android_Patches 💬 Discussion Group: @TDOhex_Discussion ━━━━━━━━━━━━━━━━━━━
4 326
11
How to Bypass Screenshot and Screen Recording Restrictions in Android Apps (This post consolidates previously separate posts into one organized reference.) If you want to disable the secure flag (which prevents screenshots or screen recordings) in Android apps, check out our earlier guides: 👉 Bypassing Flag Secure in Android Apps https://t.me/TDOhex/475 The regex has been updated: it now searches for the constant 0x2000 across the full method boundary and only captures cases where the register is passed into the addFlag or setFlag. 👉 Bypassing Flag Secure in SurfaceView https://t.me/TDOhex/483 The regex has also been improved. Note: If your screen recording results in blank output, it’s because the app uses a secured SurfaceView. In that case, follow the SurfaceView method. 👉 Difference Between These Two Methods https://t.me/TDOhex_Discussion/70225 👉 How to Bypass SSL Pinning on Android Devices https://t.me/TDOhex/485 ━━━━━━━━━━━━━━━━━━━ 📣 Main Channel: @TDOhex 📱Second Channel: @Android_Patches 💬 Discussion Group: @TDOhex_Discussion ━━━━━━━━━━━━━━━━━━━
4 128
12
🔐 How to Bypass SSL Pinning on Android Devices (This post is a compilation of previously scattered and separate posts, now organized and presented in one place.) Depending on your device setup, there are four possible conditions: 1. Rooted Without Magisk 2. Rooted With Magisk 3. Non-Rooted with Virtual Machine 4. Non-Rooted without Virtual Machine 📱 1. Rooted Device with Magisk - Use NVISOsecurity’s AlwaysTrustUserCerts module. Link to the Module: https://github.com/NVISOsecurity/AlwaysTrustUserCerts - This module copies user-installed certificates into the system store. - Supported on Android 7 → 16. - Remember: Certificates must be installed under User Store → CA Certificate. 👉 Alternative: build your own custom Magisk module for more control. 📱 2. Rooted Device without Magisk - Use the same certificate setup commands mentioned in this post, check index 6.1-6.7: 👉 How to Bypass SSL Pinning on Non-Rooted Using VPhoneOS https://t.me/TDOhex/477 - After applying, restart the device. 📱 3. Non-Rooted Device with Virtual Machine (e.g., VPhoneOS) - Follow the same process as in cases 1 & 2. Usage tip: --- Install & run the target app inside the virtual machine. --- Run the interceptor (e.g., ProxyPin) outside the VM and capture the virtual machine’s packets. 📝 Note: No patching or tampering with app integrity needed for cases 1–3. 📱 4. Non-Rooted Device without Virtual Machine - Configure res/xml/network_security_config.xml of target app. - Declare it properly in the AndroidManifest.xml. - Full step-by-step guide: 👉 How to Bypass SSL Pinning on Non-Rooted Devices https://t.me/TDOhex/478 📝 Notes: 1. For OkHttp Patches, check these two posts: 👉 Locating check() and check$okhttp() Methods in Obfuscated Code: A Regex Guide https://t.me/TDOhex/480 👉 HostnameVerifier.verify() Locate & Bypass https://t.me/TDOhex/482 2. For video tutorial: 👉 Bypass SSL Pinning: Video Tutorial https://t.me/TDOhex/481 3. For Flutter apps (BoringSSL), run this script: 👉 flutter_ssl_patch https://t.me/AbhiTheM0dder/1359 🤖 Bonus: Automated Solution with RevEngiBot Don’t want to handle case 4 manually? Use @RevEngiBot on Telegram: 1. Start the bot. 2. Upload your APK file. 3. Quote the uploaded APK and send this command to the bot /ssl_patch. 4. The bot will ask about OkHttp patching. Choose the option according to your app’s situation. 5. The bot will return the patched APK file. ━━━━━━━━━━━━━━━━━━━ 📣 Main Channel: @TDOhex 📱Second Channel: @Android_Patches 💬 Discussion Group: @TDOhex_Discussion ━━━━━━━━━━━━━━━━━━━
4 376
13
Spck NodeJS App Subscription & Token Analysis Through analysis of the subscription and terminal launch logic in the Spck's JavaScript bundle, we'll understand: - How the app verifies active subscriptions (Uv function). - The structure and interpretation of the JWT token. - The terminal launch logic and its dependencies on token validation. 👉 For PDF Format https://t.me/TDOhex_Discussion/70989 👉 For Markdown Format https://t.me/TDOhex_Discussion/70990 👉 For Patched Version https://t.me/fileshare_tg/86 ━━━━━━━━━━━━━━━━━━━ 📣 Main Channel: @TDOhex 📱Second Channel: @Android_Patches 💬 Discussion Group: @TDOhex_Discussion ━━━━━━━━━━━━━━━━━━━
3 666
14
SurfaceView.setSecure(true): Locate & Bypass Purpose: The setSecure(true) method enforces security restrictions on a SurfaceView to prevent unauthorized capture or disclosure of sensitive content. Workflow: When android.view.SurfaceView.setSecure(true) invoked, the method sets WindowManager.LayoutParams.FLAG_SECURE for the SurfaceView's underlying window. Documention: https://developer.android.com/reference/android/view/SurfaceView#setSecure(boolean) Regex to Search: (invoke-virtual \{([pv]\d+), ([pv]\d+)\}, Landroid/view/SurfaceView;->setSecure\(Z\)V) Replace (Optional): const/4 $3, 0x0\n\n\t$1 👉 How to Bypass Screenshot and Screen Recording Restrictions from Android https://t.me/TDOhex/475 ━━━━━━━━━━━━━━━━━━━ 📣 Main Channel: @TDOhex 📱Second Channel: @Android_Patches 💬 Discussion Group: @TDOhex_Discussion ━━━━━━━━━━━━━━━━━━━
3 702
15
HostnameVerifier.verify() Locate & Bypass Purpose: Validates whether the server's hostname matches the certificate presented during an TLS/SSL handshake. Method Signature: boolean verify(String hostname, SSLSession session); Workflow: 1. During the TLS/SSL handshake, the server sends its certificate. 2. verify(hostname, SSLSession) is called. 3. Checks if the certificate’s Subject Alternative Names (SANs) or Common Name (CN) match hostname. 4. If mismatch → Throws SSLPeerUnverifiedException. Bypass Method: To bypass hostname verification, implement the verify() method to unconditionally return true. Search: (\.method public (final )?\S+\(Ljava/lang/String;Ljavax/net/ssl/SSLSession;\)Z)(?:(?!\.end\smethod)[\s\S])*?\.end\smethod Replace: $1\n\t.registers 3\n\n\tconst/4 v0, 0x1\n\n\treturn v0\n.end method Documention: https://docs.oracle.com/javase/7/docs/api/javax/net/ssl/HostnameVerifier.html?is-external=true#verify-java.lang.String-javax.net.ssl.SSLSession- 👉 How to Bypass SSL Pinning on Non-Rooted Devices https://t.me/TDOhex/478 👉 Locating check() and check$okhttp() Methods in Obfuscated Code: A Regex Guide https://t.me/TDOhex/480 👉 Bypass SSL Pinning: Video Tutorial https://t.me/TDOhex/481 👉 How to Bypass SSL Pinning on Non-Rooted Devices Using VPhoneOS https://t.me/TDOhex/477 ━━━━━━━━━━━━━━━━━━━ 📣 Main Channel: @TDOhex 📱Second Channel: @Android_Patches 💬 Discussion Group: @TDOhex_Discussion ━━━━━━━━━━━━━━━━━━━
4 230
16
Bypass SSL Pinning: Video Tutorial This video is based on the following guidelines: 👉 How to Bypass SSL Pinning on Non-Rooted Devices https://t.me/TDOhex/478 👉 Locating check() and check$okhttp() Methods in Obfuscated Code: A Regex Guide https://t.me/TDOhex/480 What's in this Video: - Steps to download and install ProxyPin Certificate. (ProxyPin is just an example. If you have another app, the steps to install its certificate will be the same.) - Four methods for replacing or adding network security configuration in the target app. - Steps to patch check() and check$okhttp() methods of Okhttp. Notes: 1. For security reasons, we have used the demo app of the HTTPToolkit for demonstration. 2. It is possible that a developer has bound the certificate in the /res/raw/ or /assets/ folder of an app. Identify it and replace it with the ProxyPin certificate. ━━━━━━━━━━━━━━━━━━━ 📣 Main Channel: @TDOhex 📱Second Channel: @Android_Patches 💬 Discussion Group: @TDOhex_Discussion ━━━━━━━━━━━━━━━━━━━
5 224
17
Locating check() and check$okhttp() Methods in Obfuscated Code: A Regex Guide We previously discussed a custom implementation of okhttp3 to bypass SSL pinning by clearing the code of check() and check$okhttp() methods to skip the pin verification. If the app isn’t obfuscated, finding these methods is easy. You’ll find both methods in the Lokhttp3/CertificatePinner; class. But if the app is obfuscated, members find it challenging to locate these methods. In this post, we’ll explain the process step by step. Regex Design Methodology Based on immutable characteristics of these methods, we construct a resilient regex pattern using these anchors: 1. Method Declaration - Public modifier: \.method public - Optional final keyword: (final )? - Any method name (handles obfuscation): \S+ 2. Parameter Structure - First parameter: Ljava/lang/String; (hostname) - Second parameter: Any class reference (handles obfuscation): L[^;]+; - Exactly two parameters with void return: \)V 3. Certificate Validation Markers - Inside the method boundaries, the second parameter must be cast to peerCertificates at least once: (?:(?!\.end\smethod)[\s\S])*?check-cast [vp]\d+, Ljava/security/cert/X509Certificate; - If certificate validation fails, it throws SSLPeerUnverifiedException: (?:(?!\.end\smethod)[\s\S])*?Ljavax/net/ssl/SSLPeerUnverifiedException;; 4. Scope Control - Boundary-restricted scanning: (?:(?!\.end\smethod)[\s\S])*? - Method termination: \.end\smethod Final Regex Pattern Search: (\.method public (final )?\S+\(Ljava/lang/String;L[^;]+;\)V)(?:(?!\.end\smethod)[\s\S])*?check-cast [vp]\d+, Ljava/security/cert/X509Certificate;(?:(?!\.end\smethod)[\s\S])*?Ljavax/net/ssl/SSLPeerUnverifiedException;(?:(?!\.end\smethod)[\s\S])*?\.end\smethod Replace: $1\n\t.registers 3\n\n\treturn-void\n.end method Testing & Accuracy: This regex was tested on 40+ banking and OTT apps with 100% accuracy, regardless of obfuscation. Notes: 1. This solution relates to the overridePins method. 2. The regex won’t work on packed/protected apps requiring dex dumping. 3. It is possible that this regex may not work in advanced checks and custom implementation, as its purpose is only to find target methods. 👉 How to Bypass SSL Pinning on Non-Rooted Devices https://t.me/TDOhex/478 👉 How to Bypass SSL Pinning on Non-Rooted Devices Using VPhoneOS https://t.me/TDOhex/477 👉 Bypassing Predefined SSL Pins for Specific Hosts in Android (okhttp3) https://t.me/TDOhex/479 👉 flutter_ssl_patch https://t.me/AbhiTheM0dder/1359 ━━━━━━━━━━━━━━━━━━━ 📣 Main Channel: @TDOhex 📱Second Channel: @Android_Patches 💬 Discussion Group: @TDOhex_Discussion ━━━━━━━━━━━━━━━━━━━
3 802
18
Bypassing Predefined SSL Pins for Specific Hosts in Android (okhttp3) We covered detailed steps to bypass SSL pinning in Android apps in our last two posts. 👉 How to Bypass SSL Pinning on Non-Rooted Devices https://t.me/TDOhex/478 👉 How to Bypass SSL Pinning on Non-Rooted Devices Using VPhoneOS https://t.me/TDOhex/477 However, custom implementations often require manual handling, so in this post we’ll discuss those very techniques. How okhttp3 Pins Certificate There are several ways to configure pins, but here we’ll use an okhttp3 example. In okhttp3, pins for specific hosts are set up like this: CertificatePinner pinner = new CertificatePinner.Builder() // SHA‑256 hashes for example.com (current + backup) .add("example.com", "sha256/YLh1dUR9y6Kja30RrAn7JKnbQG/uEtLMkBgFF2Fuihg=", "sha256/AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA=") // Wildcard pin for subdomains (SHA‑256 only) .add("*.api.example.com", "sha256/BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB=") .build(); OkHttpClient client = new OkHttpClient.Builder() .certificatePinner(pinner) .build(); Here, the CertificatePinner.Builder class is used to configure domain‑specific pins. Point 1: CertificatePinner.Builder is an inner class of CertificatePinner. Point 2: The .add() method takes two parameters: first, the host (or wildcard pattern) as a String. Second, one or more pin hashes as an array of Strings. Point 3: During the TLS handshake, the check() and check$okhttp() methods of CertificatePinner validate the server’s certificate chain. If validation fails, an SSLPeerUnverifiedException is thrown—you’ll recognize it in Smali as Ljavax/net/ssl/SSLPeerUnverifiedException;. Point 4: * check() takes two parameters: a String and a List. * check$okhttp() also takes two parameters: a String and a kotlin.jvm.functions.Function0 (Smali signature: Ljava/lang/String;Lkotlin/jvm/functions/Function0;). Hooking Pins Validation If you remove or patch out the code in these methods (check,check$okhttp), pinning validation is effectively disabled—a simple workaround. If the app is obfuscated, first identify the host that’s causing the TLS handshake error. Then apply the points above to locate the correct classes and methods. Once you find the inner class for CertificatePinner, you’ll also find its enclosing class—and thus the obfuscated check() and check$okhttp() methods. Overriding Pins with ProxyPin Rather than just disable pinning, you can override the existing pins by adding your own (e.g. ProxyPin). The .add() method’s documentation lists four requirements for pins: 1. They must encode the certificate’s public key information. 2. They must be in SHA‑1 or SHA‑256 digest form. 3. They must be Base64‑encoded. 4. They must be prefixed with sha1/ or sha256/. Keeping these rules in mind, we extract both the SHA‑1 and SHA‑256 hashes from the ProxyPin certificate. We choose ProxyPin because it’s free, open‑source, and works on non‑rooted Android devices. Command to extract SHA‑256: openssl x509 -in /storage/emulated/0/Download/ProxyPinCA.crt -pubkey -noout | openssl pkey -pubin -outform der | openssl dgst -sha256 -binary | openssl enc -base64 Result (with prefix): sha256/GfB6ZlY1jVATHuHD9H9FW/NYhPoHU1QGg0rGV/C+2u4= SHA‑1 extraction: openssl x509 -in /storage/emulated/0/Download/ProxyPinCA.crt -pubkey -noout | openssl pkey -pubin -outform der | openssl dgst -sha1 -binary | openssl enc -base64 Result (with prefix): sha1/k1B+6mxfEO7tDT8N+e3ddHi/S0g= Once you have these hashes, you can analyze and override the existing pins—wherever they reside (libraries, resources, or DEX files). Note: We have used these methods on many banking, OTT, and other apps. However, apologies, due to Telegram's rules, we cannot provide practical examples for this. If you become familiar with Matrix, let us know. We can have open discussions there. ━━━━━━━━━━━━━━━ 📣 Main Channel: @TDOhex 📱Second Channel: @Android_Patches 💬 Discussion Group: @TDOhex_Discussion ━━━━━━━━━━━━━━━
4 323
19
How to Bypass SSL Pinning on Non-Rooted Devices overridePins: The overridePins attribute is used within the <certificates> tag under the <trust-anchors> element in an Android network security configuration file. Its purpose is to bypass SSL/TLS certificate pinning. - When set to overridePins="true", it allows the app to trust user-installed certificates even if the app has certificate pinning enabled. Example Context: <certificates     src="user"     overridePins="true" />  Here, the app will trust user-added certificates and bypass any certificate pinning rules defined in the app. Documentation: https://developer.android.com/privacy-and-security/security-config#certificates Step-by-Step Guide: 1. Install and Configure ProxyPin on Your Device: 👉 For ProxyPin: https://play.google.com/store/apps/details?id=com.network.proxy - Open the ProxyPin app. - Tap the three dots in the top-right corner of the first page. - Select HTTPS Proxy from the menu. - Turn on Enable HTTPS Proxy in ProxyPin settings. 2. Install SSL Certificates: - Tap Install Certificate and follow the in-app instructions. - Download and install ProxyPin’s User Certificate from the app. - The file ProxyPinCA.crt should be installed under CA Certificate in the Install a Certificate option. 3. Modify the App’s Network Security Config: - Tool Recommend: MT Manager. 👉 For MT Manager: https://mt2.cn/download/ 3.1 Decompile the Target APK: - Use MT Manager to open the APK. - Navigate to res/xml/network_security_config.xml. 3.2 Update/Create the Config File: - If network_security_config.xml already exists add this configuration: <!-- Add user trust anchor with pin override --> <trust-anchors>     <certificates src="system"/>     <certificates src="user" overridePins="true"/> </trust-anchors> - If the file does NOT exist: A. Create new network_security_config.xml in /res/xml/: <?xml version="1.0" encoding="utf-8"?> <network-security-config>     <base-config         cleartextTrafficPermitted="true">         <trust-anchors>             <certificates                 src="system"/>             <certificates                 overridePins="true"                 src="user"/>         </trust-anchors>     </base-config>     <debug-overrides>         <trust-anchors>             <certificates                 src="system"/>             <certificates                 overridePins="true"                 src="user"/>         </trust-anchors>     </debug-overrides> </network-security-config> B. Add the XML Entry via MT Manager: - Use the Arsc Editor feature in MT Manager and navigate to the XML section of the target app. You will see XML entries there. - To create a new entry, click on the three dots in the top-right corner and select the Add option. - In the first box, the entry ID will be automatically calculated, and in the second box, enter the new entry name network_security_config and click the OK button. A new entry will be created. - Then, to set its path, click on the new entry network_security_config. - Replace the path in the Content box res/xxxx with this path: res/xml/network_security_config.xml. - Finally, click the OK button. - Your new entry has been successfully created. C. Link to AndroidManifest.xml: - Open the AndroidManifest.xml file and add the following line within the <application: android:networkSecurityConfig="@ResourceID". - In ResourceID, use the ID that was automatically calculated when you created the new entry of network_security_config. 4. Now, you can capture traffic from the target app using the ProxyPin app on non-rooted devices 👉 How to Bypass SSL Pinning on Non-Rooted Using VPhoneOS https://t.me/TDOhex/477 👉 HTTP-Basics-Notes https://t.me/TDOhex_Discussion/59768 ━━━━━━━━━━━━━━━━━━━ 📣 Main Channel: @TDOhex 📱Second Channel: @Android_Patches 💬 Discussion Group: @TDOhex_Discussion ━━━━━━━━━━━━━━━━━━━
6 089
20
How to Decrypt SSL Packets on Non-Rooted Devices (SSL Unpinning) Requirements: - ProxyPin: For intercepting traffic. https://play.google.com/store/apps/details?id=com.network.proxy - VPhoneOS: The Android Emulator (Offer root access internally). https://play.google.com/store/apps/details?id=com.yoyo.snake.rush - Termux: To execute Linux commands inside VPhoneOS. https://play.google.com/store/apps/details?id=com.termux Steps: 1. Install and Configure ProxyPin on Host Device (Outside VPhoneOS): - Open the ProxyPin app. - Tap the three dots in the top-right corner of the first page. - Select HTTPS Proxy from the menu. 2. Enable HTTPS Proxy: - Turn on Enable HTTPS Proxy in ProxyPin settings. 3. Install SSL Certificates: - Tap Install Certificate and follow the in-app instructions. 3.1 Install the User Certificate: - Download and install ProxyPin’s User Certificate from the app. - The file ProxyPinCA.crt should be installed under CA Certificate in the Install a Certificate option. 3.2 Install the System Certificate: - Download the system certificate, which will be named 243f0bfb.0, and save it for later use. 4. Install and Run VPhoneOS: - Follow the in-app instructions to set up and launch VPhoneOS. 4.1. Bypass Phantom Process Killer: - Depending on your Android version, follow the appropriate method: 4.1.1 Android 14 or Higher: - Enable Developer Options and then Turn on Disable child process restrictions. 4.1.2 Android 13 or Lower: - Enable Developer Options and pair the device using Wireless Debugging. 5. Import Files into VPhoneOS: - Move both the 243f0bfb.0 file and Termux into VPhoneOS. 6. Move System Certificate to the Required Directory: - After setting up and upgrading Termux (Inside VPhoneOS), execute the following commands: 6.1 Gain Root Access: - First, switch to the root user to execute system-level commands: su 6.2 Set SELinux to Permissive Mode: - Temporarily change SELinux to permissive mode: setenforce 0 6.3 Remount /system as Read-Write: - To make changes to the /system partition, remount it with read-write permissions: mount -o rw,remount /system 6.4 Copy the Certificate: - Move your certificate file to the system's certificate directory: cp -f /path/to/243f0bfb.0 /system/etc/security/cacerts 6.5 Change File Permissions: - Ensure the certificate has the correct permissions: chmod 644 /system/etc/security/cacerts/243f0bfb.0 6.6 Remount /system as Read-Only: - To protect the system from unintended changes, remount /system as read-only: mount -o ro,remount /system 6.7 Restore SELinux to Enforcing Mode: - Finally, revert SELinux back to enforcing mode: setenforce 1 7. Install and Run the Target App Inside VPhoneOS. 8. Configure ProxyPin for VPhoneOS: - In ProxyPin settings, go to Proxy Filter and enable VPhoneOS in App Whitelist. 9. Run ProxyPin to start capturing decrypted SSL traffic. Alternative Method: 👉 Decrypt SSL Packages without Root - Part 1 https://t.me/ApkEditorPr00/995 👉 Decrypt SSL Packages without Root - Part 2 https://t.me/ApkEditorPr00/996 ━━━━━━━━━━━━━━━━━━━ 📣 Main Channel: @TDOhex 📱Second Channel: @Android_Patches 💬 Discussion Group: @TDOhex_Discussion ━━━━━━━━━━━━━━━━━━━
6 020