Null-DRM-Official/apps/proxy/README.md
404errordeveloper 2fa8f2435f Initial commit: Null DRM Official
Capture, decrypt, and restream toolkit with compiled-in app modules
(RTE, TG4, BBC), on-device MITM proxy, streamd control plane, and www.
BBC module.yaml is published (clear streams); other module values stay local.
2026-10-06 00:25:35 +02:00

3.3 KiB
Raw Permalink Blame History

proxy — on-device HTTPS MITM (appproxy)

Host CLI plus the Android binary that MITMs phone HTTPS, so a capture can see license URLs, manifests and auth headers.

apps/proxy/
  proxyctlcmd/      host CLI, hosted by bin/drm as `drm proxy`
  device/           linux/arm64 MITM source (module: appproxy)
  rteproxy-ca.crt   MITM CA (subject hash 6c3578b4)

The process name on the phone is appproxy. Some on-disk names still say rteproxy-*, and those paths are still read, so an already-provisioned phone keeps working.

Build

go -C apps/cli build -o ../../bin/drm .   # host CLI
./bin/drm proxy build                     # cross-compile the device binary

proxy build compiles device/ for linux/arm64 into apps/proxy/proxy-android-arm64 and copies it to bin/proxy-android-arm64.

Use

# trust the MITM CA (needs Magisk; mounts into the system store)
./bin/drm proxy install-ca --reinject
./bin/drm proxy reinject-ca              # mount only, CA already pushed

# structured capture proxy
./bin/drm proxy start --install-ca --reinject
./bin/drm proxy stop

# record everything while you explore an unknown app
./bin/drm proxy discover --install-ca --reinject
./bin/drm proxy discover --force-stop <package>   # so it inherits the CA mount

# pull artifacts without re-running, and release the phone
./bin/drm proxy pull
./bin/drm proxy clear-proxy

Always clear the proxy when done, or the phone keeps pointing at a dead listener.

Transparent mode (UK VPN OK — no Wi‑Fi HTTP proxy)

Root iptables redirects only one app’s TCP/443 into on-device appproxy. The phone can stay on NordVPN UK; nothing sets http_proxy.

# leave UK VPN connected on the phone, then:
./bin/drm proxy transparent --package bbc.iplayer.android --reinject
# open the app / play — Ctrl+C stops iptables and pulls files

Writes on device (adb-readable):

/data/local/tmp/capture/<package>/cap.json
/data/local/tmp/capture/<package>/traffic.jsonl
/data/local/tmp/capture/<package>/appproxy.log

Pull anytime:

adb pull /data/local/tmp/capture/bbc.iplayer.android ./bbc-cap

Force-stop the target app once after CA reinject so it inherits the Magisk CA mount.

The device binary cannot read an app module's values file, so a module's manifest-scoring hosts are passed to it as flags (--match, --score-host, --score-deny). drm capture does this automatically.

Artifacts

File What
appproxy_traffic.jsonl / traffic.jsonl every HTTP(S) request/response (discover / transparent)
appproxy_cap.json / cap.json structured mpd / license / auth / pssh when detected
appproxy.log tagged lines: [MPD] [LIC] [PSSH] [MAN] [TPROXY]

Pulled into outputs/discover/<stamp>/ or outputs/transparent/<stamp>/.

Device paths

Remote Role
/data/local/tmp/appproxy binary
/data/local/tmp/appproxy_cap.json structured capture (proxy mode)
/data/local/tmp/capture/<pkg>/ transparent out-dir (cap + traffic + log)
/data/local/tmp/tproxy_iptables.sh UID REDIRECT helper
/data/local/tmp/6c3578b4.0 system CA hash file
Wi‑Fi http_proxy used only in classic proxy mode — not in transparent mode

Full guide: docs/capture.md — CA troubleshooting and how to mine a discover dump.