Capture, decrypt, and restream toolkit with compiled-in app modules (RTE, TG4, BBC), on-device MITM proxy, streamd control plane, and www. BBC module.yaml is published (clear streams); other module values stay local. |
||
|---|---|---|
| .. | ||
| device | ||
| proxyctlcmd | ||
| go.mod | ||
| README.md | ||
| rteproxy-ca.crt | ||
proxy — on-device HTTPS MITM (appproxy)
Host CLI plus the Android binary that MITMs phone HTTPS, so a capture can see license URLs, manifests and auth headers.
apps/proxy/
proxyctlcmd/ host CLI, hosted by bin/drm as `drm proxy`
device/ linux/arm64 MITM source (module: appproxy)
rteproxy-ca.crt MITM CA (subject hash 6c3578b4)
The process name on the phone is appproxy. Some on-disk names still say
rteproxy-*, and those paths are still read, so an already-provisioned phone keeps
working.
Build
go -C apps/cli build -o ../../bin/drm . # host CLI
./bin/drm proxy build # cross-compile the device binary
proxy build compiles device/ for linux/arm64 into
apps/proxy/proxy-android-arm64 and copies it to bin/proxy-android-arm64.
Use
# trust the MITM CA (needs Magisk; mounts into the system store)
./bin/drm proxy install-ca --reinject
./bin/drm proxy reinject-ca # mount only, CA already pushed
# structured capture proxy
./bin/drm proxy start --install-ca --reinject
./bin/drm proxy stop
# record everything while you explore an unknown app
./bin/drm proxy discover --install-ca --reinject
./bin/drm proxy discover --force-stop <package> # so it inherits the CA mount
# pull artifacts without re-running, and release the phone
./bin/drm proxy pull
./bin/drm proxy clear-proxy
Always clear the proxy when done, or the phone keeps pointing at a dead listener.
Transparent mode (UK VPN OK — no Wi‑Fi HTTP proxy)
Root iptables redirects only one app’s TCP/443 into on-device appproxy. The
phone can stay on NordVPN UK; nothing sets http_proxy.
# leave UK VPN connected on the phone, then:
./bin/drm proxy transparent --package bbc.iplayer.android --reinject
# open the app / play — Ctrl+C stops iptables and pulls files
Writes on device (adb-readable):
/data/local/tmp/capture/<package>/cap.json
/data/local/tmp/capture/<package>/traffic.jsonl
/data/local/tmp/capture/<package>/appproxy.log
Pull anytime:
adb pull /data/local/tmp/capture/bbc.iplayer.android ./bbc-cap
Force-stop the target app once after CA reinject so it inherits the Magisk CA mount.
The device binary cannot read an app module's values file, so a module's
manifest-scoring hosts are passed to it as flags (--match, --score-host,
--score-deny). drm capture does this automatically.
Artifacts
| File | What |
|---|---|
appproxy_traffic.jsonl / traffic.jsonl |
every HTTP(S) request/response (discover / transparent) |
appproxy_cap.json / cap.json |
structured mpd / license / auth / pssh when detected |
appproxy.log |
tagged lines: [MPD] [LIC] [PSSH] [MAN] [TPROXY] |
Pulled into outputs/discover/<stamp>/ or outputs/transparent/<stamp>/.
Device paths
| Remote | Role |
|---|---|
/data/local/tmp/appproxy |
binary |
/data/local/tmp/appproxy_cap.json |
structured capture (proxy mode) |
/data/local/tmp/capture/<pkg>/ |
transparent out-dir (cap + traffic + log) |
/data/local/tmp/tproxy_iptables.sh |
UID REDIRECT helper |
/data/local/tmp/6c3578b4.0 |
system CA hash file |
Wi‑Fi http_proxy |
used only in classic proxy mode — not in transparent mode |
Full guide: docs/capture.md — CA troubleshooting and how to mine a discover dump.