当前位置:网站首页>Textplus - reverse engineering of textplus
Textplus - reverse engineering of textplus
2022-06-24 01:18:00 【franket】
Textplus It's like textfree The same free SMS and call app . And Textfree Different ,Textplus No network client is provided . This limits our ability to interact with mobile applications . No problem , Let's start our Android Simulators and agents . I decided to start using charles agent , Because it provides a better layout , And I found it easy to use , Even if it's not free . Like mine textfree hack equally , Let us Start by viewing the application , See if we can find anything that could sabotage the deal ( I look for recaptchas、 Anti robot software , And whether the application is related to TOR In combination with ).
When creating an account , You need to fill in recaptcha. This is a deal breaker . It seems impossible to create accounts programmatically . Don't judge a book by its cover .recaptcha And registration data . This means that we do not need to complete revalidation . Let me be clear , I did bypass google recaptcha,textplus It's just not completely coded .
After creating an account , The server will generate the post exploit operation ( For example, send text ) Vital information . For some reason , The server will respond to your registration request with your account data in the header . I don't understand why I did it , Because they have been using json Transfer data between the client and the server for the entire communication . This makes me a little disappointed , Because I want to retrieve data from the server in the same way as sending data . Looking around , I found it .
Textplus It uses a form of authentication that I've never seen before . Maybe it's because it's so bad . They use some kind of two-step verification . You provide your user name and password to “ https://cas.prd.gii.me/v2/ticket/ticketgranting/service”, It returns a “ ticket ”. This is a PHP Program , It will get you a ticket .
With this ticket , We have moved on to the second part of authentication . You provide tickets to “ https://cas.prd.gii.me/v2/ticket/service”, It returns another “ Authenticated ” ticket . This is a PHP Program , Can provide you with “ Authenticated tickets ”( Ensure that all information is provided ).
Every request after login needs “ Tickets granted ”. This is their form of user authentication . Use the ticket granted , We move on to the next part of the process , I.e. assigned number . We first get a list of available phone number locations . We will pay close attention to “ Zone setup ” value , As shown below :
Now we have “ Zone setup ” Information , We can continue to register our devices . This is how we assign a number .
as far as I am concerned , Google push token seems to be static . In the past few weeks , I don't have the problem of reusing it . On the other hand , This step is not really necessary . We don't need to register the device , Because when we create an account ,textplus Will automatically assign us a temporary number , Even in applications , If you have not registered a number , You cannot send text messages . The next part is how we can bypass device registration . Even if there is no number , We can still send messages or emails “ The invitation ” people . Our interest is to invite... Through text , By the way ,textplus Allow us to customize the invitation . A few things to remember : please remember , When you invite others , You will make money in the application itself , The money can be used to make phone calls …… please remember , Each account is assigned a different number .
As you can see , We can set custom text . This is through the text :
边栏推荐
- The dispute between traditional IT development and low code development is heated, and the technical development rules may be restructured?
- Zhongshanshan: engineers after being blasted will take off | ONEFLOW u
- Data management: business data cleaning and implementation scheme
- 所见之处都是我精准定位的范畴!显著图可视化新方法开源
- 【Redis进阶之ZipList】如果再有人问你什么是压缩列表?请把这篇文章直接甩给他。
- 【ICCV Workshop 2021】基于密度图的小目标检测:Coarse-grained Density Map Guided Object Detection in Aerial Images
- DML操作
- Talk to Wu Jiesheng, head of Alibaba cloud storage: my 20 years of data storage (unlimited growth)
- Skywalking installation and deployment practice
- JS stack memory
猜你喜欢

An accident caused by a MySQL misoperation, and the "high availability" cannot withstand it!

Everything I see is the category of my precise positioning! Open source of a new method for saliency map visualization

对抗训练理论分析:自适应步长快速对抗训练

Arm learning (7) symbol table and debugging

Cvpr2022 𞓜 thin domain adaptation

skywalking 安装部署实践

【Flutter】如何使用Flutter包和插件

阿里巴巴面试题:多线程相关

【ICPR 2021】遥感图中的密集小目标检测:Tiny Object Detection in Aerial Images

【机器学习】线性回归预测
随机推荐
985 Android programmers won the oral offer of Alibaba P6 in 40 days. After the successful interview, they sorted out these interview ideas
【Flutter】如何使用Flutter包和插件
Architecture solutions
同行评议论文怎么写
[planting grass by technology] 13 years' record of the prince of wool collecting on the cloud moving to Tencent cloud
Openstack
跨域和JSONP
Is it safe to open an account online? What conditions need to be met?
[OSG] OSG development (04) - create multiple scene views
GNN上分利器!与其绞尽脑汁炼丹,不如给你的GNN撒点trick吧
ctfhub---SSRF
[technical grass planting] take you to Tencent cloud's private cloud disk in ten minutes
Version ` zlib 1.2.9 "not found (required by / lib64 / libpng16.so.16)
CSDN articles crawl the top ten bloggers' articles and convert them to MD
js输入输出语句,变量
Real time preview of RTSP video based on webrtc
[solution] how to realize AI automatic recognition of high altitude parabolic behavior?
DML操作
机器学习中 TP FP TN FN的概念
Messy knowledge points