Null-DRM-Official/apps/proxy/README.md
404errordeveloper 2fa8f2435f Initial commit: Null DRM Official
Capture, decrypt, and restream toolkit with compiled-in app modules
(RTE, TG4, BBC), on-device MITM proxy, streamd control plane, and www.
BBC module.yaml is published (clear streams); other module values stay local.
2026-10-06 00:25:35 +02:00

102 lines
3.3 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# proxy — on-device HTTPS MITM (appproxy)
Host CLI plus the Android binary that MITMs phone HTTPS, so a capture can see
license URLs, manifests and auth headers.
```text
apps/proxy/
proxyctlcmd/ host CLI, hosted by bin/drm as `drm proxy`
device/ linux/arm64 MITM source (module: appproxy)
rteproxy-ca.crt MITM CA (subject hash 6c3578b4)
```
The process name on the phone is **`appproxy`**. Some on-disk names still say
`rteproxy-*`, and those paths are still read, so an already-provisioned phone keeps
working.
## Build
```bash
go -C apps/cli build -o ../../bin/drm . # host CLI
./bin/drm proxy build # cross-compile the device binary
```
`proxy build` compiles `device/` for linux/arm64 into
`apps/proxy/proxy-android-arm64` and copies it to `bin/proxy-android-arm64`.
## Use
```bash
# trust the MITM CA (needs Magisk; mounts into the system store)
./bin/drm proxy install-ca --reinject
./bin/drm proxy reinject-ca # mount only, CA already pushed
# structured capture proxy
./bin/drm proxy start --install-ca --reinject
./bin/drm proxy stop
# record everything while you explore an unknown app
./bin/drm proxy discover --install-ca --reinject
./bin/drm proxy discover --force-stop <package> # so it inherits the CA mount
# pull artifacts without re-running, and release the phone
./bin/drm proxy pull
./bin/drm proxy clear-proxy
```
Always clear the proxy when done, or the phone keeps pointing at a dead listener.
### Transparent mode (UK VPN OK — no Wi‑Fi HTTP proxy)
Root `iptables` redirects only one app’s TCP/443 into on-device `appproxy`. The
phone can stay on NordVPN UK; nothing sets `http_proxy`.
```bash
# leave UK VPN connected on the phone, then:
./bin/drm proxy transparent --package bbc.iplayer.android --reinject
# open the app / play — Ctrl+C stops iptables and pulls files
```
Writes on device (adb-readable):
```text
/data/local/tmp/capture/<package>/cap.json
/data/local/tmp/capture/<package>/traffic.jsonl
/data/local/tmp/capture/<package>/appproxy.log
```
Pull anytime:
```bash
adb pull /data/local/tmp/capture/bbc.iplayer.android ./bbc-cap
```
Force-stop the target app once after CA reinject so it inherits the Magisk CA mount.
The device binary cannot read an app module's values file, so a module's
manifest-scoring hosts are passed to it as flags (`--match`, `--score-host`,
`--score-deny`). `drm capture` does this automatically.
## Artifacts
| File | What |
|---|---|
| `appproxy_traffic.jsonl` / `traffic.jsonl` | every HTTP(S) request/response (discover / transparent) |
| `appproxy_cap.json` / `cap.json` | structured mpd / license / auth / pssh when detected |
| `appproxy.log` | tagged lines: `[MPD]` `[LIC]` `[PSSH]` `[MAN]` `[TPROXY]` |
Pulled into `outputs/discover/<stamp>/` or `outputs/transparent/<stamp>/`.
## Device paths
| Remote | Role |
|---|---|
| `/data/local/tmp/appproxy` | binary |
| `/data/local/tmp/appproxy_cap.json` | structured capture (proxy mode) |
| `/data/local/tmp/capture/<pkg>/` | transparent out-dir (cap + traffic + log) |
| `/data/local/tmp/tproxy_iptables.sh` | UID REDIRECT helper |
| `/data/local/tmp/6c3578b4.0` | system CA hash file |
| Wi‑Fi `http_proxy` | used only in classic proxy mode — **not** in transparent mode |
**Full guide: [docs/capture.md](../../docs/capture.md)** — CA troubleshooting and how
to mine a discover dump.