Skiptracing: Reversing Spotify.app
medium.com
medium.com
> The most common type of hook is the interpose hook.
Note that dyld has built-in support for interposing; you don't need to mess around with dlsym and RTLD_NEXT (which requires disabling the two-level namespace anyways, as you seem to have figured out, which can cause some programs to misbehave): https://opensource.apple.com/source/dyld/dyld-210.2.3/includ...
> As stated earlier, an interpose hook can only be created for an external function, so we’ll look for a function in the libc or in the Objective-C runtime.
Yes, but the Objective-C runtime lets you swizzle anything :) No need to dig around for an external C function to patch.
> Spotify opened fine but Apple’s System Integrity Protection (SIP) didn’t let us load our unsigned library :(.
No, this is not System Integrity Protection: it's Library Validation, which prevents loading libraries signed with a different Team ID than the main binary was signed with. You can remove the binary's code signature to get around this.
> We’ll first set a hook on sub_10006DE40 and then we will trigger a breakpoint from within our code. We can do this by executing the assembly instruction int 3 which is what debuggers like GDB and LLDB use to trigger breakpoints.
Or, compile with debug symbols and put a breakpoint at your function as you normally would.
> Notice that the PC will be at an offset address from the one shown in IDA (honestly, I don’t have the best grasp as to why this happens but I assume it’s due to where the process is loaded into memory).
Most binaries are compiled position-independently on macOS, and get loaded at a randomized address (but the debugger should usually turn off the randomization).
Regarding the Apple code signing requirement: is it the case then for all hooks of this sort that one is effectively required to be in the Developer program?
So I was curious if LD_PRELOAD is prevented from working, but seems there's a simple work around:
> On macOS there is an additional problem. Newer versions of macOS have a security subsystem called System Integrity Protection. For our purposes the problem is that it prevents injecting code via DYLD_INSERT_LIBRARIES (the macOS equivalent of LD_PRELOAD) into any binary in /bin, /sbin, /usr/bin and /usr/sbin.
> Luckily, there’s an easy workaround. Just create a new directory, copy all the binaries from /bin, /sbin, /usr/bin and /usr/sbin into that directory, and then add it to the start of your $PATH environment variable. Once the binaries are out of those special directories code injection works just fine, and since they’re only 100MB copying them is quite fast.
From https://www.datawire.io/code-injection-on-linux-and-macos/
I just want Spotify to give me better recommendations instead of the same songs over and over.
But for sure the interesting part of this is the method, not the purpose.
This should do just that: https://developer.spotify.com/documentation/web-api/referenc...
My current implementation is a hack that just keeps polling Spotify with ‘shpotify’ to grab data. This article is more the implementation I actually wanted.
Edit: Doesn't look like this would be practical for distribution to others but I still might make it for myself.
if application "Spotify" is running then
tell application "Spotify"
if player state is playing then
return (get artist of current track) & " - " & (get name of current track)
else
return ""
end if
end tell
end if
source:
https://vas3k.com/blog/touchbar/#scroll60You can also install a collection of scripts from here: https://goldenchaos.net/goldenchaos-btt.html
You will need Better Touch Tool for that: https://folivora.ai/
Applescript is actually a lot of fun if you decide to look into it