en
Feedback
Dimension of TDO

Dimension of TDO

Open in Telegram

Technical Knowledge For Educational Purposes Not for business, promotion Or releasing, requesting mods Respect Hard Works Don't be Leecher We are Responsible only for our Posts Contact us @TDOhexSupportBot by Team of @MuhammadRidwan87

Show more
The country is not specifiedTechnologies & Applications12 420
Buy Ad
No data
Subscribers
+1224 hours
+347 days
+17230 days

Data loading in progress...

Tags Cloud
No data
Any problems? Please refresh the page or contact our support manager.
Incoming and Outgoing Mentions
---
---
---
---
---
---
Attracting Subscribers
January '26
January '26
+31
in 0 channels
December '25
+253
in 2 channels
Get PRO
November '25
+223
in 4 channels
Get PRO
October '25
+238
in 8 channels
Get PRO
September '25
+232
in 7 channels
Get PRO
August '25
+223
in 3 channels
Get PRO
July '25
+206
in 3 channels
Get PRO
June '25
+257
in 4 channels
Get PRO
May '25
+190
in 2 channels
Get PRO
April '25
+236
in 6 channels
Get PRO
March '25
+256
in 7 channels
Get PRO
February '25
+249
in 5 channels
Get PRO
January '25
+299
in 13 channels
Get PRO
December '24
+241
in 7 channels
Get PRO
November '24
+293
in 6 channels
Get PRO
October '24
+244
in 6 channels
Get PRO
September '24
+331
in 8 channels
Get PRO
August '24
+328
in 9 channels
Get PRO
July '24
+322
in 14 channels
Get PRO
June '24
+301
in 9 channels
Get PRO
May '24
+302
in 9 channels
Get PRO
April '24
+260
in 7 channels
Get PRO
March '24
+288
in 4 channels
Get PRO
February '24
+648
in 16 channels
Get PRO
January '24
+177
in 4 channels
Get PRO
December '23
+217
in 5 channels
Get PRO
November '23
+146
in 5 channels
Get PRO
October '23
+127
in 1 channels
Get PRO
September '23
+121
in 0 channels
Get PRO
August '23
+131
in 0 channels
Get PRO
July '23
+103
in 0 channels
Get PRO
June '23
+130
in 0 channels
Get PRO
May '23
+118
in 0 channels
Get PRO
April '23
+80
in 0 channels
Get PRO
March '23
+83
in 0 channels
Get PRO
February '23
+149
in 0 channels
Get PRO
January '23
+341
in 0 channels
Get PRO
December '22
+96
in 0 channels
Get PRO
November '22
+116
in 0 channels
Get PRO
October '22
+65
in 0 channels
Get PRO
September '22
+40
in 0 channels
Get PRO
August '22
+100
in 0 channels
Get PRO
July '22
+21
in 0 channels
Get PRO
June '22
+9
in 0 channels
Get PRO
May '22
+16
in 0 channels
Get PRO
April '22
+52
in 0 channels
Get PRO
March '22
+15
in 0 channels
Get PRO
February '22
+42
in 0 channels
Get PRO
January '22
+25
in 0 channels
Get PRO
December '21
+17
in 0 channels
Get PRO
November '21
+41
in 0 channels
Get PRO
October '21
+74
in 0 channels
Get PRO
September '21
+42
in 0 channels
Get PRO
August '21
+132
in 0 channels
Get PRO
July '21
+29
in 0 channels
Get PRO
June '21
+85
in 0 channels
Get PRO
May '21
+34
in 0 channels
Get PRO
April '21
+48
in 0 channels
Get PRO
March '21
+164
in 0 channels
Get PRO
February '21
+715
in 0 channels
Get PRO
January '21
+161
in 0 channels
Get PRO
December '20
+2 954
in 0 channels
Date
Subscriber Growth
Mentions
Channels
04 January+4
03 January+12
02 January+10
01 January+5
Channel Posts
I thank you all for your support and contributions. I hope to continue receiving your support in the future. ❀️ Last year, I attempted to convey an important principle: Knowledge is not the exclusive property of any individual. The acquisition of knowledge requires two essential qualitiesβ€”genuine intellectual seeking and sincere appreciation of knowledge itself. A true seeker approaches learning with humility rather than arrogance, and with gratitude rather than ingratitude. From this understanding, I presented the conclusion that: The root cause of all deprivation and stagnation is arrogance and ingratitude. This year, I would like to offer another foundational reflection: To become a better human being, one must embody the qualities of Sadiq (truthfulness) and Ameen (trustworthiness). - A Sadiq is an individual whose speech, intentions, and actions are consistently aligned with truth. - An Ameen is an individual upon whom others can place their trust without fear or hesitation. These two qualities are fundamental to personal excellence. Moreover, no individual can become an effective or ethical leader without truthfulness and trustworthiness. Truthfulness refines and disciplines the individual internally, while trustworthiness equips a person to positively influence society and contribute meaningfully to the wider world. If you want to choose a better leader, look for the qualities of truthfulness and trustworthiness in them. Truthfulness and trustworthiness share a common foundation: Trust. A trustworthy individual does not engage in falsehood, nor does he misuse power, authority, or knowledge. Therefore: One must guard against losing trust through lie or betrayal. - Choose humility over arrogance. - Choose gratitude over ingratitude. - Choose truth over falsehood. - Choose trustworthiness over betrayal. While this subject allows for extensive philosophical and motivational exploration, for those who are prepared to understand and accept these principles, this reflection is sufficient. ❀️ --From MuhammadRizwan-- ❀️ Join us, Follow us! @TDOhex @Android_Patches @TDOhex_Discussion https://github.com/muhammadrizwan87

2
Ban Notice: Leecher News We have permanently banned @imYouarefinished (5949636238) for repeatedly leeching content from our group and channel. Background: He is a moderator on the Mobilism forum and has a history of similar behavior. Previous reports (especially regarding Omar’s content) had already established him as a certified leecher. Only after being reported did he reluctantly credit Omar. Prior complaints were also filed by Marc and others. Latest Incident: Most recently, he stole the patch and idea from "γ…€γ…€5ter1!ngγ…€" without crediting either Sterling or the group. He didn’t even express basic gratitude for the learning he gained. We had previously requested: β€œAt least remember and accept where you learned from” but his arrogance and ingratitude persisted. As we’ve said before: β€œArrogance and ingratitude are the roots of all misfortune.” Please revisit these posts: πŸ”— Post 1 https://t.me/TDOhex/474 πŸ”— Post 2 https://t.me/TDOhex_Discussion/20376 Additional Action: Supporter admins @carpedroidiem (67925274) and @keepitlalala (8033524430) have also been banned. Not for leeching, but for enabling and supporting a known leecher. We understand this won’t end leeching entirely. Our intent is to awaken your conscience (if any self-respect remains) so that you reflect on these disgraceful actions. - From Group Admin - βœ„---------------------------------------- ✨ APKEditor Update ✨ The Debian package for APKEditor version 1.4.6 has been updated. πŸ“¦ Deb Package for APKEditor v1.4.6 https://t.me/TDOhex_Discussion/41644 Visit here to see what's new https://github.com/REAndroid/APKEditor/releases/tag/V1.4.6
3 794
3
Reminder πŸ””: The Epic Games Store will reportedly offer 16 Mystery Games from December 11, 2025, to January 8, 2026, starting with a new game every day. And also remember that the Epic Game Store is available on Android. You can play the games. Link: https://store.epicgames.com/free-games First mystery game of epic games store: Hogwarts Legacy https://store.epicgames.com/en-US/p/hogwarts-legacy
3 569
4
HOW TO USE IL2CPP-TOOL What's in this Video: - Implementation of the tool - Dump il2cpp - Inspect the field value and patch it - Unlock ARLOOPA app Video Duration: 02:28 Video Size: 11.15M Demo App: ARLOOPA: AR Augmented Reality Version: 5.0.28(245) Play Store Link: https://play.google.com/store/apps/details?id=com.arloopa.arloopa Link to Download IL2CPP-TOOL: https://t.me/TDOhex_Discussion/78556 Other Parts: https://t.me/TDOhex_Discussion/77764 https://t.me/TDOhex_Discussion/77767 Smali Code: const-string v0, "Tool" invoke-static {v0}, Ljava/lang/System;->loadLibrary(Ljava/lang/String;)V ━━━━━━━━━━━━━━━━━━━ ♻️ Join Channel: @Android_Patches πŸ“£ Main Channel: @TDOhex πŸ’¬ Discussion Group: @TDOhex_Discussion ━━━━━━━━━━━━━━━━━━━
5 707
5
πŸš€ DexDumper v2.0.0 Released! This update brings the biggest leap so far β€” full runtime configuration, smarter exclusions, and enhanced safety for DEX dumping operations. ✨ Highlights: βš™οΈ Runtime Config System DexDumper now supports a flexible runtime configuration system. You can tweak behavior instantly through a .conf file β€” all without recompiling. It’s perfect for debugging or testing different setups quickly. Configurable Settings: - Second Scan - Scans Limit - Region Filtering - Exclusion List - Output path πŸ‘‰ For more info https://github.com/muhammadrizwan87/dexdumper?tab=readme-ov-file#runtime-configuration-library_nameconf πŸ”’ SHA1 Exclusion Control Added a clean way to skip known or unwanted DEX files using their SHA1 hashes. This helps avoid re-dumping system or placeholder files, keeping your output clean and relevant. 🧠 Duplicate Prevention A new SHA1-based duplicate detector ensures that already dumped DEX files are not saved again. It saves both time and storage while maintaining accuracy in large dump sessions. 🧹 Safer Cleanup The cleanup routine now deletes only valid DEX dump files (matching the precise filename pattern). This prevents accidental removal of other files in the output directory β€” safer and smarter cleanup. πŸ”— Github Repository: https://github.com/muhammadrizwan87/dexdumper.git ━━━━━━━━━━━━━━━━━━━ ♻️ Join Channel: @Android_Patches πŸ“£ Main Channel: @TDOhex πŸ’¬ Discussion Group: @TDOhex_Discussion ━━━━━━━━━━━━━━━━━━━
2 507
6
🌎 How to Bypass Geo Restrictions in Android Apps and Games πŸ“– Background: In Android apps and games, geo-related information is commonly retrieved via TelephonyManager methods such as: - getNetworkOperatorName() / getSimOperatorName() β€” Operator/Carrier Name (e.g., "AT&T Mobility") - getNetworkOperator() / getSimOperator() β€” PLMN (MCC+MNC, e.g., "310410") - getNetworkCountryIso() / getSimCountryIso() β€” Country ISO code (e.g., "US") πŸ”— TelephonyManager API: https://developer.android.com/reference/android/telephony/TelephonyManager At the smali level we can patch the code right after the invoke-virtual call and the move-result-object so that the register that received the string result is overwritten with a fixed string (dummy/fake values). Below are example regex searches and the replacement snippets to inject constant strings. πŸ› οΈ Smali Patching Instructions 1️⃣ Spoofing Carrier Name πŸ” Search Pattern (Regex): (invoke-virtual\s\{(?:[pv]\d+)\},\sLandroid/telephony/TelephonyManager;->get(?:Network|Sim)OperatorName\(\)Ljava/lang/String;\n(?:\s*(?:[.#][^\n]*)?\n)*\s*move-result-object\s([pv]\d+))(?:\n\n\s*const-string\s\2,\s".*")? ✏️ Replace With: $1\n\n\tconst-string $2, "AT&T Mobility" This overrides the result of getNetworkOperatorName() or getSimOperatorName() with a hardcoded carrier name. 2️⃣ Spoofing PLMN (MCC+MNC) πŸ” Search Pattern (Regex): (invoke-virtual\s\{(?:[pv]\d+)\},\sLandroid/telephony/TelephonyManager;->get(?:Network|Sim)Operator\(\)Ljava/lang/String;\n(?:\s*(?:[.#][^\n]*)?\n)*\s*move-result-object\s([pv]\d+))(?:\n\n\s*const-string\s\2,\s".*")? ✏️ Replace With: $1\n\n\tconst-string $2, "310410" This sets the MCC+MNC code to "310410" (AT&T USA). 3️⃣ Spoofing Country ISO πŸ” Search Pattern (Regex): (invoke-virtual\s\{(?:[pv]\d+)\},\sLandroid/telephony/TelephonyManager;->get(?:Network|Sim)CountryIso\(\)Ljava/lang/String;\n(?:\s*(?:[.#][^\n]*)?\n)*\s*move-result-object\s([pv]\d+))(?:\n\n\s*const-string\s\2,\s".*")? ✏️ Replace With: $1\n\n\tconst-string $2, "US" This forces the app to believe the device is located in the United States. 🧠 Why These Regex Patterns Are Powerful These regexes are designed with advanced smali parsing in mind. Here's what makes them robust and reliable: 1. βœ… Comprehensive Matching: They capture all possible TelephonyManager calls, even if debug directives, annotations, or comments are present or absent. 2. πŸ“ Multi-line Resilience: Whether debug info appears single line or across multiple lines, the regex still matches accurately without breaking. 3. πŸ” Safe Reapplication: You can apply these regexes repeatedly without stacking duplicate replacements or injecting dummy code fragments. πŸ“ Notes: 1. Because this modifies smali code (dex disassembly), it will not work if the app uses native code, runtime-decrypted strings, or has tamper-proofing/encryption/packing that prevents straightforward smali patching. 2. This technique changes only the returned string values at the smali level; it does not handle other checks the app may make (e.g., location APIs, server-side verification, or other device identifiers). 3. To obtain MCC+MNC codes, you can check out the following resources. - 🌐 Website: https://mcc-mnc.net β€” A comprehensive database of Mobile Country Codes (MCC) and Mobile Network Codes (MNC). - πŸ“¦ GitHub Repository: https://github.com/P1sec/MCCMNC β€” An open-source collection of MCC/MNC data maintained by the community. ━━━━━━━━━━━━━━━━━━━ πŸ“£ Main Channel: @TDOhex πŸ“±Second Channel: @Android_Patches πŸ’¬ Discussion Group: @TDOhex_Discussion ━━━━━━━━━━━━━━━━━━━
4 275
7
πŸš€ DexDumper Update! πŸš€ πŸ“Œ What's New: - Added SHA1 Exclusion List to skip unwanted or known DEX files - Easy to configure ENABLE_SECOND_SCAN, THREAD_INITIAL_DELAY, SECOND_SCAN_DELAY, and OUTPUT_DIRECTORY_TEMPLATES - Updated README.md with new configuration details and usage notes πŸ”— GitHub Repository: https://github.com/muhammadrizwan87/dexdumper.git πŸ’‘ Update now and take advantage of the new features! ━━━━━━━━━━━━━━━━━━━ πŸ“£ Main Channel: @TDOhex πŸ“±Second Channel: @Android_Patches πŸ’¬ Discussion Group: @TDOhex_Discussion ━━━━━━━━━━━━━━━━━━━
3 873
8
πŸŽ‰ NEW RELEASE: DexDumper is Live! πŸŽ‰ We're releasing DexDumper - A sophisticated memory analysis library that extracts DEX files from running Android applications without requiring root access. πŸ” Key benefits: - Smart memory scanning - Sandbox/VM compatible - Lightweight resource usage πŸ’‘ Why You'll Love It: - No Frida required - No Xposed required - No root required - No adb required - No GameGuardian required - No extra tools, modules, or permissions required - No need to break the target app’s integrity - No PC needed β€” build directly on the device! - Respects app boundaries β€” completely legal! - Open source and community-driven! πŸš€ Get Started: - Check out the repo - Star it to support the project - Easy to set up, Easy to use - Fork it, improve it, and let’s grow this project together πŸ”— Github Repository: https://github.com/muhammadrizwan87/dexdumper.git πŸ”— How to Use DexDumper https://t.me/TDOhex_Discussion/75820 πŸ“ Notes: 1. DexDumper is currently in its development phase, so it may not work reliably on apps protected by advanced packers such as: DexProtect, Jiagu360, Ijami, Etc... 2. For Termux-based NDK builds, check out MrIkso’s AndroidIDE-NDK repo. Alternatively, use the GitHub Actions workflow to auto-compile the source β€” no manual setup needed, handles dependencies, and builds for all architectures. ━━━━━━━━━━━━━━━━━━━ ♻️ Join Channel: @Android_Patches πŸ“£ Main Channel: @TDOhex πŸ’¬ Discussion Group: @TDOhex_Discussion ━━━━━━━━━━━━━━━━━━━
3 347
9
We’re currently looking for demo apps that require dex dumping. They should not be packed with high-level protectors like DexProtect, Jiagu360, or Ijami. If possible, keep emulator and debugger security disabled. If you’d like to share such APKs, please send them to our bot @TDOhexSupportBot. Note: This is for our research purposes only, so please do not request dumped dex files.
4 594
10
WebView API Interception: A Technical Demo What's in this Post: - Focus on intercepting and modifying API responses in Android WebView - Understanding raw data interception and fabricated (fake) response injection Note: This post has been rephrased using AI to enhance vocabulary, and due to Telegram’s limitations, it has been shared in markdown format. πŸ‘‰ How to Bypass SSL Pinning on Android Devices https://t.me/TDOhex/485 ━━━━━━━━━━━━━━━━━━━ πŸ“£ Main Channel: @TDOhex πŸ“±Second Channel: @Android_Patches πŸ’¬ Discussion Group: @TDOhex_Discussion ━━━━━━━━━━━━━━━━━━━
4 326
11
How to Bypass Screenshot and Screen Recording Restrictions in Android Apps (This post consolidates previously separate posts into one organized reference.) If you want to disable the secure flag (which prevents screenshots or screen recordings) in Android apps, check out our earlier guides: πŸ‘‰ Bypassing Flag Secure in Android Apps https://t.me/TDOhex/475 The regex has been updated: it now searches for the constant 0x2000 across the full method boundary and only captures cases where the register is passed into the addFlag or setFlag. πŸ‘‰ Bypassing Flag Secure in SurfaceView https://t.me/TDOhex/483 The regex has also been improved. Note: If your screen recording results in blank output, it’s because the app uses a secured SurfaceView. In that case, follow the SurfaceView method. πŸ‘‰ Difference Between These Two Methods https://t.me/TDOhex_Discussion/70225 πŸ‘‰ How to Bypass SSL Pinning on Android Devices https://t.me/TDOhex/485 ━━━━━━━━━━━━━━━━━━━ πŸ“£ Main Channel: @TDOhex πŸ“±Second Channel: @Android_Patches πŸ’¬ Discussion Group: @TDOhex_Discussion ━━━━━━━━━━━━━━━━━━━
4 128
12
πŸ” How to Bypass SSL Pinning on Android Devices (This post is a compilation of previously scattered and separate posts, now organized and presented in one place.) Depending on your device setup, there are four possible conditions: 1. Rooted Without Magisk 2. Rooted With Magisk 3. Non-Rooted with Virtual Machine 4. Non-Rooted without Virtual Machine πŸ“± 1. Rooted Device with Magisk - Use NVISOsecurity’s AlwaysTrustUserCerts module. Link to the Module: https://github.com/NVISOsecurity/AlwaysTrustUserCerts - This module copies user-installed certificates into the system store. - Supported on Android 7 β†’ 16. - Remember: Certificates must be installed under User Store β†’ CA Certificate. πŸ‘‰ Alternative: build your own custom Magisk module for more control. πŸ“± 2. Rooted Device without Magisk - Use the same certificate setup commands mentioned in this post, check index 6.1-6.7: πŸ‘‰ How to Bypass SSL Pinning on Non-Rooted Using VPhoneOS https://t.me/TDOhex/477 - After applying, restart the device. πŸ“± 3. Non-Rooted Device with Virtual Machine (e.g., VPhoneOS) - Follow the same process as in cases 1 & 2. Usage tip: --- Install & run the target app inside the virtual machine. --- Run the interceptor (e.g., ProxyPin) outside the VM and capture the virtual machine’s packets. πŸ“ Note: No patching or tampering with app integrity needed for cases 1–3. πŸ“± 4. Non-Rooted Device without Virtual Machine - Configure res/xml/network_security_config.xml of target app. - Declare it properly in the AndroidManifest.xml. - Full step-by-step guide: πŸ‘‰ How to Bypass SSL Pinning on Non-Rooted Devices https://t.me/TDOhex/478 πŸ“ Notes: 1. For OkHttp Patches, check these two posts: πŸ‘‰ Locating check() and check$okhttp() Methods in Obfuscated Code: A Regex Guide https://t.me/TDOhex/480 πŸ‘‰ HostnameVerifier.verify() Locate & Bypass https://t.me/TDOhex/482 2. For video tutorial: πŸ‘‰ Bypass SSL Pinning: Video Tutorial https://t.me/TDOhex/481 3. For Flutter apps (BoringSSL), run this script: πŸ‘‰ flutter_ssl_patch https://t.me/AbhiTheM0dder/1359 πŸ€– Bonus: Automated Solution with RevEngiBot Don’t want to handle case 4 manually? Use @RevEngiBot on Telegram: 1. Start the bot. 2. Upload your APK file. 3. Quote the uploaded APK and send this command to the bot /ssl_patch. 4. The bot will ask about OkHttp patching. Choose the option according to your app’s situation. 5. The bot will return the patched APK file. ━━━━━━━━━━━━━━━━━━━ πŸ“£ Main Channel: @TDOhex πŸ“±Second Channel: @Android_Patches πŸ’¬ Discussion Group: @TDOhex_Discussion ━━━━━━━━━━━━━━━━━━━
4 376
13
Spck NodeJS App Subscription & Token Analysis Through analysis of the subscription and terminal launch logic in the Spck's JavaScript bundle, we'll understand: - How the app verifies active subscriptions (Uv function). - The structure and interpretation of the JWT token. - The terminal launch logic and its dependencies on token validation. πŸ‘‰ For PDF Format https://t.me/TDOhex_Discussion/70989 πŸ‘‰ For Markdown Format https://t.me/TDOhex_Discussion/70990 πŸ‘‰ For Patched Version https://t.me/fileshare_tg/86 ━━━━━━━━━━━━━━━━━━━ πŸ“£ Main Channel: @TDOhex πŸ“±Second Channel: @Android_Patches πŸ’¬ Discussion Group: @TDOhex_Discussion ━━━━━━━━━━━━━━━━━━━
3 666
14
SurfaceView.setSecure(true): Locate & Bypass Purpose: The setSecure(true) method enforces security restrictions on a SurfaceView to prevent unauthorized capture or disclosure of sensitive content. Workflow: When android.view.SurfaceView.setSecure(true) invoked, the method sets WindowManager.LayoutParams.FLAG_SECURE for the SurfaceView's underlying window. Documention: https://developer.android.com/reference/android/view/SurfaceView#setSecure(boolean) Regex to Search: (invoke-virtual \{([pv]\d+), ([pv]\d+)\}, Landroid/view/SurfaceView;->setSecure\(Z\)V) Replace (Optional): const/4 $3, 0x0\n\n\t$1 πŸ‘‰ How to Bypass Screenshot and Screen Recording Restrictions from Android https://t.me/TDOhex/475 ━━━━━━━━━━━━━━━━━━━ πŸ“£ Main Channel: @TDOhex πŸ“±Second Channel: @Android_Patches πŸ’¬ Discussion Group: @TDOhex_Discussion ━━━━━━━━━━━━━━━━━━━
3 702
15
HostnameVerifier.verify() Locate & Bypass Purpose: Validates whether the server's hostname matches the certificate presented during an TLS/SSL handshake. Method Signature: boolean verify(String hostname, SSLSession session); Workflow: 1. During the TLS/SSL handshake, the server sends its certificate. 2. verify(hostname, SSLSession) is called. 3. Checks if the certificate’s Subject Alternative Names (SANs) or Common Name (CN) match hostname. 4. If mismatch β†’ Throws SSLPeerUnverifiedException. Bypass Method: To bypass hostname verification, implement the verify() method to unconditionally return true. Search: (\.method public (final )?\S+\(Ljava/lang/String;Ljavax/net/ssl/SSLSession;\)Z)(?:(?!\.end\smethod)[\s\S])*?\.end\smethod Replace: $1\n\t.registers 3\n\n\tconst/4 v0, 0x1\n\n\treturn v0\n.end method Documention: https://docs.oracle.com/javase/7/docs/api/javax/net/ssl/HostnameVerifier.html?is-external=true#verify-java.lang.String-javax.net.ssl.SSLSession- πŸ‘‰ How to Bypass SSL Pinning on Non-Rooted Devices https://t.me/TDOhex/478 πŸ‘‰ Locating check() and check$okhttp() Methods in Obfuscated Code: A Regex Guide https://t.me/TDOhex/480 πŸ‘‰ Bypass SSL Pinning: Video Tutorial https://t.me/TDOhex/481 πŸ‘‰ How to Bypass SSL Pinning on Non-Rooted Devices Using VPhoneOS https://t.me/TDOhex/477 ━━━━━━━━━━━━━━━━━━━ πŸ“£ Main Channel: @TDOhex πŸ“±Second Channel: @Android_Patches πŸ’¬ Discussion Group: @TDOhex_Discussion ━━━━━━━━━━━━━━━━━━━
4 230
16
Bypass SSL Pinning: Video Tutorial This video is based on the following guidelines: πŸ‘‰ How to Bypass SSL Pinning on Non-Rooted Devices https://t.me/TDOhex/478 πŸ‘‰ Locating check() and check$okhttp() Methods in Obfuscated Code: A Regex Guide https://t.me/TDOhex/480 What's in this Video: - Steps to download and install ProxyPin Certificate. (ProxyPin is just an example. If you have another app, the steps to install its certificate will be the same.) - Four methods for replacing or adding network security configuration in the target app. - Steps to patch check() and check$okhttp() methods of Okhttp. Notes: 1. For security reasons, we have used the demo app of the HTTPToolkit for demonstration. 2. It is possible that a developer has bound the certificate in the /res/raw/ or /assets/ folder of an app. Identify it and replace it with the ProxyPin certificate. ━━━━━━━━━━━━━━━━━━━ πŸ“£ Main Channel: @TDOhex πŸ“±Second Channel: @Android_Patches πŸ’¬ Discussion Group: @TDOhex_Discussion ━━━━━━━━━━━━━━━━━━━
5 224
17
Locating check() and check$okhttp() Methods in Obfuscated Code: A Regex Guide We previously discussed a custom implementation of okhttp3 to bypass SSL pinning by clearing the code of check() and check$okhttp() methods to skip the pin verification. If the app isn’t obfuscated, finding these methods is easy. You’ll find both methods in the Lokhttp3/CertificatePinner; class. But if the app is obfuscated, members find it challenging to locate these methods. In this post, we’ll explain the process step by step. Regex Design Methodology Based on immutable characteristics of these methods, we construct a resilient regex pattern using these anchors: 1. Method Declaration - Public modifier: \.method public - Optional final keyword: (final )? - Any method name (handles obfuscation): \S+ 2. Parameter Structure - First parameter: Ljava/lang/String; (hostname) - Second parameter: Any class reference (handles obfuscation): L[^;]+; - Exactly two parameters with void return: \)V 3. Certificate Validation Markers - Inside the method boundaries, the second parameter must be cast to peerCertificates at least once: (?:(?!\.end\smethod)[\s\S])*?check-cast [vp]\d+, Ljava/security/cert/X509Certificate; - If certificate validation fails, it throws SSLPeerUnverifiedException: (?:(?!\.end\smethod)[\s\S])*?Ljavax/net/ssl/SSLPeerUnverifiedException;; 4. Scope Control - Boundary-restricted scanning: (?:(?!\.end\smethod)[\s\S])*? - Method termination: \.end\smethod Final Regex Pattern Search: (\.method public (final )?\S+\(Ljava/lang/String;L[^;]+;\)V)(?:(?!\.end\smethod)[\s\S])*?check-cast [vp]\d+, Ljava/security/cert/X509Certificate;(?:(?!\.end\smethod)[\s\S])*?Ljavax/net/ssl/SSLPeerUnverifiedException;(?:(?!\.end\smethod)[\s\S])*?\.end\smethod Replace: $1\n\t.registers 3\n\n\treturn-void\n.end method Testing & Accuracy: This regex was tested on 40+ banking and OTT apps with 100% accuracy, regardless of obfuscation. Notes: 1. This solution relates to the overridePins method. 2. The regex won’t work on packed/protected apps requiring dex dumping. 3. It is possible that this regex may not work in advanced checks and custom implementation, as its purpose is only to find target methods. πŸ‘‰ How to Bypass SSL Pinning on Non-Rooted Devices https://t.me/TDOhex/478 πŸ‘‰ How to Bypass SSL Pinning on Non-Rooted Devices Using VPhoneOS https://t.me/TDOhex/477 πŸ‘‰ Bypassing Predefined SSL Pins for Specific Hosts in Android (okhttp3) https://t.me/TDOhex/479 πŸ‘‰ flutter_ssl_patch https://t.me/AbhiTheM0dder/1359 ━━━━━━━━━━━━━━━━━━━ πŸ“£ Main Channel: @TDOhex πŸ“±Second Channel: @Android_Patches πŸ’¬ Discussion Group: @TDOhex_Discussion ━━━━━━━━━━━━━━━━━━━
3 802
18
Bypassing Predefined SSL Pins for Specific Hosts in Android (okhttp3) We covered detailed steps to bypass SSL pinning in Android apps in our last two posts. πŸ‘‰ How to Bypass SSL Pinning on Non-Rooted Devices https://t.me/TDOhex/478 πŸ‘‰ How to Bypass SSL Pinning on Non-Rooted Devices Using VPhoneOS https://t.me/TDOhex/477 However, custom implementations often require manual handling, so in this post we’ll discuss those very techniques. How okhttp3 Pins Certificate There are several ways to configure pins, but here we’ll use an okhttp3 example. In okhttp3, pins for specific hosts are set up like this: CertificatePinner pinner = new CertificatePinner.Builder() // SHA‑256 hashes for example.com (current + backup) .add("example.com", "sha256/YLh1dUR9y6Kja30RrAn7JKnbQG/uEtLMkBgFF2Fuihg=", "sha256/AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA=") // Wildcard pin for subdomains (SHA‑256 only) .add("*.api.example.com", "sha256/BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB=") .build(); OkHttpClient client = new OkHttpClient.Builder() .certificatePinner(pinner) .build(); Here, the CertificatePinner.Builder class is used to configure domain‑specific pins. Point 1: CertificatePinner.Builder is an inner class of CertificatePinner. Point 2: The .add() method takes two parameters: first, the host (or wildcard pattern) as a String. Second, one or more pin hashes as an array of Strings. Point 3: During the TLS handshake, the check() and check$okhttp() methods of CertificatePinner validate the server’s certificate chain. If validation fails, an SSLPeerUnverifiedException is thrownβ€”you’ll recognize it in Smali as Ljavax/net/ssl/SSLPeerUnverifiedException;. Point 4: * check() takes two parameters: a String and a List. * check$okhttp() also takes two parameters: a String and a kotlin.jvm.functions.Function0 (Smali signature: Ljava/lang/String;Lkotlin/jvm/functions/Function0;). Hooking Pins Validation If you remove or patch out the code in these methods (check,check$okhttp), pinning validation is effectively disabledβ€”a simple workaround. If the app is obfuscated, first identify the host that’s causing the TLS handshake error. Then apply the points above to locate the correct classes and methods. Once you find the inner class for CertificatePinner, you’ll also find its enclosing classβ€”and thus the obfuscated check() and check$okhttp() methods. Overriding Pins with ProxyPin Rather than just disable pinning, you can override the existing pins by adding your own (e.g. ProxyPin). The .add() method’s documentation lists four requirements for pins: 1. They must encode the certificate’s public key information. 2. They must be in SHA‑1 or SHA‑256 digest form. 3. They must be Base64‑encoded. 4. They must be prefixed with sha1/ or sha256/. Keeping these rules in mind, we extract both the SHA‑1 and SHA‑256 hashes from the ProxyPin certificate. We choose ProxyPin because it’s free, open‑source, and works on non‑rooted Android devices. Command to extract SHA‑256: openssl x509 -in /storage/emulated/0/Download/ProxyPinCA.crt -pubkey -noout | openssl pkey -pubin -outform der | openssl dgst -sha256 -binary | openssl enc -base64 Result (with prefix): sha256/GfB6ZlY1jVATHuHD9H9FW/NYhPoHU1QGg0rGV/C+2u4= SHA‑1 extraction: openssl x509 -in /storage/emulated/0/Download/ProxyPinCA.crt -pubkey -noout | openssl pkey -pubin -outform der | openssl dgst -sha1 -binary | openssl enc -base64 Result (with prefix): sha1/k1B+6mxfEO7tDT8N+e3ddHi/S0g= Once you have these hashes, you can analyze and override the existing pinsβ€”wherever they reside (libraries, resources, or DEX files). Note: We have used these methods on many banking, OTT, and other apps. However, apologies, due to Telegram's rules, we cannot provide practical examples for this. If you become familiar with Matrix, let us know. We can have open discussions there. ━━━━━━━━━━━━━━━ πŸ“£ Main Channel: @TDOhex πŸ“±Second Channel: @Android_Patches πŸ’¬ Discussion Group: @TDOhex_Discussion ━━━━━━━━━━━━━━━
4 323
19
How to Bypass SSL Pinning on Non-Rooted Devices overridePins: The overridePins attribute is used within the <certificates> tag under the <trust-anchors> element in an Android network security configuration file. Its purpose is to bypass SSL/TLS certificate pinning. - When set to overridePins="true", it allows the app to trust user-installed certificates even if the app has certificate pinning enabled. Example Context: <certificates Β Β Β  src="user" Β Β Β  overridePins="true" />Β  Here, the app will trust user-added certificates and bypass any certificate pinning rules defined in the app. Documentation: https://developer.android.com/privacy-and-security/security-config#certificates Step-by-Step Guide: 1. Install and Configure ProxyPin on Your Device: πŸ‘‰ For ProxyPin: https://play.google.com/store/apps/details?id=com.network.proxy - Open the ProxyPin app. - Tap the three dots in the top-right corner of the first page. - Select HTTPS Proxy from the menu. - Turn on Enable HTTPS Proxy in ProxyPin settings. 2. Install SSL Certificates: - Tap Install Certificate and follow the in-app instructions. - Download and install ProxyPin’s User Certificate from the app. - The file ProxyPinCA.crt should be installed under CA Certificate in the Install a Certificate option. 3. Modify the App’s Network Security Config: - Tool Recommend: MT Manager. πŸ‘‰ For MT Manager: https://mt2.cn/download/ 3.1 Decompile the Target APK: - Use MT Manager to open the APK. - Navigate to res/xml/network_security_config.xml. 3.2 Update/Create the Config File: - If network_security_config.xml already exists add this configuration: <!-- Add user trust anchor with pin override --> <trust-anchors> Β Β Β  <certificates src="system"/> Β Β Β  <certificates src="user" overridePins="true"/> </trust-anchors> - If the file does NOT exist: A. Create new network_security_config.xml in /res/xml/: <?xml version="1.0" encoding="utf-8"?> <network-security-config> Β Β Β  <base-config Β Β Β Β Β Β Β  cleartextTrafficPermitted="true"> Β Β Β Β Β Β Β  <trust-anchors> Β Β Β Β Β Β Β Β Β Β Β  <certificates Β Β Β Β Β Β Β Β Β Β Β Β Β Β Β  src="system"/> Β Β Β Β Β Β Β Β Β Β Β  <certificates Β Β Β Β Β Β Β Β Β Β Β Β Β Β Β  overridePins="true" Β Β Β Β Β Β Β Β Β Β Β Β Β Β Β  src="user"/> Β Β Β Β Β Β Β  </trust-anchors> Β Β Β  </base-config> Β Β Β  <debug-overrides> Β Β Β Β Β Β Β  <trust-anchors> Β Β Β Β Β Β Β Β Β Β Β  <certificates Β Β Β Β Β Β Β Β Β Β Β Β Β Β Β  src="system"/> Β Β Β Β Β Β Β Β Β Β Β  <certificates Β Β Β Β Β Β Β Β Β Β Β Β Β Β Β  overridePins="true" Β Β Β Β Β Β Β Β Β Β Β Β Β Β Β  src="user"/> Β Β Β Β Β Β Β  </trust-anchors> Β Β Β  </debug-overrides> </network-security-config> B. Add the XML Entry via MT Manager: - Use the Arsc Editor feature in MT Manager and navigate to the XML section of the target app. You will see XML entries there. - To create a new entry, click on the three dots in the top-right corner and select the Add option. - In the first box, the entry ID will be automatically calculated, and in the second box, enter the new entry name network_security_config and click the OK button. A new entry will be created. - Then, to set its path, click on the new entry network_security_config. - Replace the path in the Content box res/xxxx with this path: res/xml/network_security_config.xml. - Finally, click the OK button. - Your new entry has been successfully created. C. Link to AndroidManifest.xml: - Open the AndroidManifest.xml file and add the following line within the <application: android:networkSecurityConfig="@ResourceID". - In ResourceID, use the ID that was automatically calculated when you created the new entry of network_security_config. 4. Now, you can capture traffic from the target app using the ProxyPin app on non-rooted devices πŸ‘‰ How to Bypass SSL Pinning on Non-Rooted Using VPhoneOS https://t.me/TDOhex/477 πŸ‘‰ HTTP-Basics-Notes https://t.me/TDOhex_Discussion/59768 ━━━━━━━━━━━━━━━━━━━ πŸ“£ Main Channel: @TDOhex πŸ“±Second Channel: @Android_Patches πŸ’¬ Discussion Group: @TDOhex_Discussion ━━━━━━━━━━━━━━━━━━━
6 089
20
How to Decrypt SSL Packets on Non-Rooted Devices (SSL Unpinning) Requirements: - ProxyPin: For intercepting traffic. https://play.google.com/store/apps/details?id=com.network.proxy - VPhoneOS: The Android Emulator (Offer root access internally). https://play.google.com/store/apps/details?id=com.yoyo.snake.rush - Termux: To execute Linux commands inside VPhoneOS. https://play.google.com/store/apps/details?id=com.termux Steps: 1. Install and Configure ProxyPin on Host Device (Outside VPhoneOS): - Open the ProxyPin app. - Tap the three dots in the top-right corner of the first page. - Select HTTPS Proxy from the menu. 2. Enable HTTPS Proxy: - Turn on Enable HTTPS Proxy in ProxyPin settings. 3. Install SSL Certificates: - Tap Install Certificate and follow the in-app instructions. 3.1 Install the User Certificate: - Download and install ProxyPin’s User Certificate from the app. - The file ProxyPinCA.crt should be installed under CA Certificate in the Install a Certificate option. 3.2 Install the System Certificate: - Download the system certificate, which will be named 243f0bfb.0, and save it for later use. 4. Install and Run VPhoneOS: - Follow the in-app instructions to set up and launch VPhoneOS. 4.1. Bypass Phantom Process Killer: - Depending on your Android version, follow the appropriate method: 4.1.1 Android 14 or Higher: - Enable Developer Options and then Turn on Disable child process restrictions. 4.1.2 Android 13 or Lower: - Enable Developer Options and pair the device using Wireless Debugging. 5. Import Files into VPhoneOS: - Move both the 243f0bfb.0 file and Termux into VPhoneOS. 6. Move System Certificate to the Required Directory: - After setting up and upgrading Termux (Inside VPhoneOS), execute the following commands: 6.1 Gain Root Access: - First, switch to the root user to execute system-level commands: su 6.2 Set SELinux to Permissive Mode: - Temporarily change SELinux to permissive mode: setenforce 0 6.3 Remount /system as Read-Write: - To make changes to the /system partition, remount it with read-write permissions: mount -o rw,remount /system 6.4 Copy the Certificate: - Move your certificate file to the system's certificate directory: cp -f /path/to/243f0bfb.0 /system/etc/security/cacerts 6.5 Change File Permissions: - Ensure the certificate has the correct permissions: chmod 644 /system/etc/security/cacerts/243f0bfb.0 6.6 Remount /system as Read-Only: - To protect the system from unintended changes, remount /system as read-only: mount -o ro,remount /system 6.7 Restore SELinux to Enforcing Mode: - Finally, revert SELinux back to enforcing mode: setenforce 1 7. Install and Run the Target App Inside VPhoneOS. 8. Configure ProxyPin for VPhoneOS: - In ProxyPin settings, go to Proxy Filter and enable VPhoneOS in App Whitelist. 9. Run ProxyPin to start capturing decrypted SSL traffic. Alternative Method: πŸ‘‰ Decrypt SSL Packages without Root - Part 1 https://t.me/ApkEditorPr00/995 πŸ‘‰ Decrypt SSL Packages without Root - Part 2 https://t.me/ApkEditorPr00/996 ━━━━━━━━━━━━━━━━━━━ πŸ“£ Main Channel: @TDOhex πŸ“±Second Channel: @Android_Patches πŸ’¬ Discussion Group: @TDOhex_Discussion ━━━━━━━━━━━━━━━━━━━
6 020