当前位置:网站首页>Textplus - reverse engineering of textplus
Textplus - reverse engineering of textplus
2022-06-24 01:18:00 【franket】
Textplus It's like textfree The same free SMS and call app . And Textfree Different ,Textplus No network client is provided . This limits our ability to interact with mobile applications . No problem , Let's start our Android Simulators and agents . I decided to start using charles agent , Because it provides a better layout , And I found it easy to use , Even if it's not free . Like mine textfree hack equally , Let us Start by viewing the application , See if we can find anything that could sabotage the deal ( I look for recaptchas、 Anti robot software , And whether the application is related to TOR In combination with ).
When creating an account , You need to fill in recaptcha. This is a deal breaker . It seems impossible to create accounts programmatically . Don't judge a book by its cover .recaptcha And registration data . This means that we do not need to complete revalidation . Let me be clear , I did bypass google recaptcha,textplus It's just not completely coded .
After creating an account , The server will generate the post exploit operation ( For example, send text ) Vital information . For some reason , The server will respond to your registration request with your account data in the header . I don't understand why I did it , Because they have been using json Transfer data between the client and the server for the entire communication . This makes me a little disappointed , Because I want to retrieve data from the server in the same way as sending data . Looking around , I found it .
Textplus It uses a form of authentication that I've never seen before . Maybe it's because it's so bad . They use some kind of two-step verification . You provide your user name and password to “ https://cas.prd.gii.me/v2/ticket/ticketgranting/service”, It returns a “ ticket ”. This is a PHP Program , It will get you a ticket .
With this ticket , We have moved on to the second part of authentication . You provide tickets to “ https://cas.prd.gii.me/v2/ticket/service”, It returns another “ Authenticated ” ticket . This is a PHP Program , Can provide you with “ Authenticated tickets ”( Ensure that all information is provided ).
Every request after login needs “ Tickets granted ”. This is their form of user authentication . Use the ticket granted , We move on to the next part of the process , I.e. assigned number . We first get a list of available phone number locations . We will pay close attention to “ Zone setup ” value , As shown below :
Now we have “ Zone setup ” Information , We can continue to register our devices . This is how we assign a number .
as far as I am concerned , Google push token seems to be static . In the past few weeks , I don't have the problem of reusing it . On the other hand , This step is not really necessary . We don't need to register the device , Because when we create an account ,textplus Will automatically assign us a temporary number , Even in applications , If you have not registered a number , You cannot send text messages . The next part is how we can bypass device registration . Even if there is no number , We can still send messages or emails “ The invitation ” people . Our interest is to invite... Through text , By the way ,textplus Allow us to customize the invitation . A few things to remember : please remember , When you invite others , You will make money in the application itself , The money can be used to make phone calls …… please remember , Each account is assigned a different number .
As you can see , We can set custom text . This is through the text :
边栏推荐
- Server performance monitoring: Best Practices for server monitoring
- Installation and use of winscp and putty
- Alibaba interview question: multi thread related
- 【机器学习】线性回归预测
- Open source model library of flying propeller industry: accelerating the development and application of enterprise AI tasks
- Dart series: creating a library package
- 【小程序】相对路径和绝对路径的表示符
- Map design
- [technology planting grass] skillfully use cloud function to create wechat web page authorization public service
- Sockfwd a data forwarding gadget
猜你喜欢

【Flutter】如何使用Flutter包和插件

Isn't this another go bug?

苹果Iphone14搭载北斗导航系统,北斗VS GPS有哪些优势?

LMS Virtual. Derivation method of lab acoustic simulation results

Installation and use of winscp and putty

Perhaps the greatest romance of programmers is to commemorate their dead mother with a software

所见之处都是我精准定位的范畴!显著图可视化新方法开源
![[shutter] how to use shutter packages and plug-ins](/img/a6/e494dcdb2d3830b6d6c24d0ee05af2.png)
[shutter] how to use shutter packages and plug-ins

js输入输出语句,变量
![[applet] when compiling the preview applet, a -80063 error prompt appears](/img/4e/722d76aa0ca3576164fbed4e2c4db2.png)
[applet] when compiling the preview applet, a -80063 error prompt appears
随机推荐
Ctfhub miscellaneous --icmp
【SPRS J P & RS 2022】小目标检测模块:A Normalized Gaussian Wasserstein Distance for Tiny Object Detection
用一个软件纪念自己故去的母亲,这或许才是程序员最大的浪漫吧
A review of Tencent digital ecology conference · wechat low code special session
Map design
. Net core cross platform development bbs forum (connotation source code + complete operation video)
Esp8266 OTA remote and wireless upgrade
13 `bs_duixiang.tag标签`得到一个tag对象
[CVPR 2020 oral] a physics based noise formation model for extreme low light raw denoising
CSDN auto sign in
CODING CD
Cvpr2022 𞓜 thin domain adaptation
The best Base64 encoding and decoding tutorial in the whole network, with 6 examples!
实时计算框架:Spark集群搭建与入门案例
[CVPR 2022] high resolution small object detection: cascaded sparse query for accelerating high resolution smal object detection
Is it safe to open an account for shares of tongdaxin?
numpy.linalg.lstsq(a,b,rcond=-1)解析
Everything I see is the category of my precise positioning! Open source of a new method for saliency map visualization
这不会又是一个Go的BUG吧?
GNN上分利器!与其绞尽脑汁炼丹,不如给你的GNN撒点trick吧