How I defeated an anti-tamper APK with some Python and a homemade Smali emulator
evilsocket.net
evilsocket.net
1. Great link with the Dalvik opcodes manual http://pallergabor.uw.hu/androidblog/dalvik_opcodes.html
This came up with a google search: https://source.android.com/devices/tech/dalvik/dalvik-byteco...
2. If you run in to obfuscated smali filenames in the APK, a simple search replace will help you rename the files.
3. Instead of trying to understand the proprietary encryption/decryption, just run the decryption code without understanding it.
4. OP Created a smali emulator for this task (#3). Only supporting a small subset of dalvik instructions. Which means than for now, the emulator can be defeated using as many dalvik opcodes as possible in your encryption/decryption code. A simple check-cast for example (Throw a ClassCastException if the reference in the given register cannot be cast to the indicated type.) can break the emulator.
5. Being written in python, relying heavily on regular expressions and without much algorithmic improvements (the opcode lookup for example is a for loop instead of a lookup table) - there's a lot to improve the emulator performance, but this is an incredible first step.
When I have encountered this sort of problem in the past, I would drop the encryption module into another Android app and directly call the functions. I would then run the other Android app on a phone or Android emulator. Custom emulation seems unnecessary for most cases.
It has modules which look for patterns in code. Then you can tell it to run some method from the original app to understand what the code should be. Then, you can replace the obfuscated code with whatever you computed.
Even better, as in many legislations a derivate of manually deobfuscated code does not count as derivate of the original source, they even give up their copyright on their code, practically.
I’m surprised that this still happens. By now anyone should know that if you can run a piece of code, you can decompile, deobfuscate, and understand it. DRM and obfuscation only work to waste a week or two of the time of the person taking it apart.
100% protection does not exist, which doesn't mean you shouldn't try to make it a bit difficult
(keeping honest people honest and all that)
I never heard that, source ? It's not really "clean room".
I still don't see how it's a derivative of RE'd code (like https://news.ycombinator.com/item?id=3919250 was). It's just the classic "reverse engineering allowed for compatibility".
I don't think it's that simple. There's some distribution of time wasted that goes from 0 (already prepared tools for automated deobfuscation) to infinity (it's enough of a roadblock to stop the effort). If you automate the obfuscation and just stick it into the publishing pipeline, you effectively stopped >0 people with ~0 effort. So why not do it?
Because automated obfuscation can also be solved automatically. Heuristical deobfuscators like JSnice.org are already getting more popular.
Also - a lot of these techniques are used by malware to evade anti viruses and static code analysis.
But with software and electronic media, only one person needs to care/be smart enough for everyone to reap the benefits.
I remember reading an article featured here that the latest PC video game needed something like 6 months to be cracked and the crackers (Chinese I think) almost abandoned.
Will try to find the link.
https://torrentfreak.com/no-more-pirate-games-in-two-years-g...
Additionally some fun facts for games released with the latest Denuvo iterations:
Rise of the Tomb Raider released 28th of January this year, not cracked to date.
Just Cause 3 released December 1st 2015, not cracked to date.
Thats a lot longer than a week or two :)
For 90 percent of Play Store apps, that would be more effort than the initial development effort for the app (and with 90 percent, I'm being very, very generous).
Or anything similar to that.
For getting inspiration like that, it’s super awesome.
I know several for .NET including SimpleAssemblyExplorer and De4Dot (though de4dot also includes several specific deobs).
EDIT: Looking around you might try something like https://github.com/CalebFenton/simplify or https://github.com/contra/JMD after converting with dex2jar or similar.
(not my product)
It only pushes out the small companies and makes way for an app store environment where only large companies can survive. The exact same thing happened with the music industry over the past decade (filesharing was supposed to help the indy artist..or so many, like you, claimed)
Regarding the ratio of purchases/downloads, the argument goes back to the usual questions: 1) if the torrents didn't exist, how would the number of purchases change (i.e. are those lost sales, or were they never potential sales to begin with); and 2) what's the promotion channel for indie bands? I purchased a lot of music because I heard about it from someone who had a pirated copy. Now at least we've got Spotify discovery, Google music tailored radios, etc. working for us, but it's still not a lot.
2) For the mass audience, streaming solutions (99% of that being youtube), have completely replaced piracy. However, if you noticed, I'm not talking about mass audience, it stopped buying music anyway. I'm talking about Beatport, Juno — shops especially targeted at DJs, who have very different purchasing patterns, and usually different ways of learning about music as well. A significant part of modern electronic music labels have stopped doing digital releases altogether, going vinyl-only, and piracy is one of the main reasons.
In the case of most games, sales are steadily decreasing over time anyway - so it'd need to be a pretty marked step down to remove the possibility that they're simply following trend. It'd be interesting trying to account for that in an analysis.
Anecdotally, I have several friends who torrent games by default - but they legitimately wouldn't buy anyway (to quote "lol at buying videogames in the year of our lord 2016").
Conversely however, I do hear about companies that have taken someone's SaaS app by dumping the front-end code, and building their own backend, and releasing it with absolutely no changes to the elements they've stolen.
This may be due to my filter bubble making it so I hear more about web apps (I write web based apps) but anecdotally it does seem that SaaS is not a protection against piracy.
If you spend years of R&D on algorithms, patent them.
But boilerplate code can neither be patented nor copyrighted (except in its source form, but the binary, for example, can’t), so you never owned anything to begin with.
Disclaimer: This is just a general info about EU law, this is not legal advice, I am not a lawyer.
You realize Farnsworth ripped off Braun?
Also, if you have a patent, you can always sue. That’s not an issue.
Without even looking, if they're against you the chances are they're in the right. I've yet to see them do anything I disagree with as someone who considers those points very important.
This is a very dangerous attitude to have regardless of who it concerns.
We all "mooch" off of other's talents. That's the beauty of our industry. We get inspired, we share, and we base our works on the works of others.
That's why its so important to pair huge investments in R&D with awesome business people. Don't obsess about protecting your inventions. Obsess about getting your inventions out there, selling, supporting, and custom tailoring it for what customers really need.
And it hurts that I careless about the code - it can be rewritten in a million ways. What I care about is what code does, and the multitude of GloboCorps working on the same issue in vane, and their ability to reproduce our work in months once they understand the secret sauce.
Also - keep in mind that "Legal advice" isn't necessarily "Business advice". Lawyers can't tell you how to make money, or how to build a business that survives even when people compete with you. They'll tell you how to try to prevent competition, or protect IP, but they won't tell you how to be a market leader.
As for BigCorp copying your inventions - that can obviously happen. But it's also very likely that if you can solve a problem that BigCorp is failing at, they'll simply give you an M&A offer.
if the secret sause is so simple that they can copy it in months without violating copyright laws, may be it's not so saucy after all!
Data, whether code, or algorithm, is not physical, and therefore, unless you don't give the code out (e.g., sell via SaaS), it's gone as soon as you release it, obfuscated or not.
I don't think people have a problem with enforcing patents in general, just patent 'trolling', i.e. buying someone else's patent or patenting broad ideas.
edit: newline detection fail
You do realise that's not how research, science and engineering work right? Just because you think it's morally justifiable to "own an idea" doesn't mean it is morally justifiable to do so.
Besides, do you really think someone is going to supplant you that easily? If you're really worried, use the GPL and then use their improvements to improve your own work.
I think all these problems arise from the way we pretend that information is property. It is not.