Snapchat Reverse Engineering - Part 1 - Snapchat Account Creator Bot - API based

Status
Not open for further replies.
Looking forward to hearing about the lifetime you can achieve with these accounts. Are you going to simulate using the accounts for marketing to see how long they last against reports etc

At the moment the lifetime of the accounts from the second last test case is at least 1 week. Almost all accounts are up and running. The ones I can't do logins with are my own fault since I played too much with useless nonsense settings. ;-)

For the moment I don't have a current usage scenario for the accounts.

I didn't plan increasing the account strength yet (against incoming reports etc.). But that's a nice idea.

I think my confusion is because I'm growing accounts and you're just aging them.

That's a little difference.

Do you have Telegram to destroy your confusion? ;-)

. . .

Small update:

Yesterday and today I played a little with the server side device parameters (I don't use an emulator, so the emulation is just done with my own software and its settings).

I remembered the old Android DeviceID method I already used last year and modified the method on server side.


Sometimes you have the best ideas after you got distracted with a different project and totally different problem. So thank you, "Mr. Discord accounts". ;-)


At my BHW profile you will find today's "code snippet" - no the API endpoint HTTP/2.0 GRPC request only - to keep it a little hidden from Snap Inc.
 
Last edited:
no offense but you sound 100% like the scammer from cpaelites. You type exactly the same way lol. He used to sell some snapchat tool called letsnapit and was banned from bhw
 
no offense but you sound 100% like the scammer from cpaelites. You type exactly the same way lol. He used to sell some snapchat tool called letsnapit and was banned from bhw

Could you please send me a link to check your story? Would you be so kind?
 
Letsnapit, moneyisinthebot,.... he has multiple personalities

Somebody warned me about the haters who write at BHW (user @xbycx with his first post, freshly registered).

If you really think I am a scammer, please create a dispute thread here: https://www.blackhatworld.com/forums/dispute-resolution.31/ Please attach the invoice, a payment proof, the software you ordered, a valid conversation etc.

I scammed nobody, I have nothing to offer for sale, I don't even plan a sale at the moment.


Please stop accusing me for criminal activities and offending me:

no offense but you sound 100% like the scammer from cpaelites. You type exactly the same way lol. He used to sell some snapchat tool called letsnapit and was banned from bhw

Or show a public proof for everything (invoices, payment proofs, software you ordered, conversations etc.) here: https://www.blackhatworld.com/forums/dispute-resolution.31/


I will talk to a BHW moderator very soon about you @xbycx (first post) and @whitecupg (first post since September 2023).


P. S.: The next "journey" thread with the disclosure of important app details will be posted at the closed Jr. VIP section. So anonymous haters with 1-day-accounts can't view the content.
 
Last edited:
no offense but you sound 100% like the scammer from cpaelites. You type exactly the same way lol. He used to sell some snapchat tool called letsnapit and was banned from bhw
Yeah OP is Charlie Harper and it’s his account (one of many others he ran to promote his LetsSnapIt scam):

https://www.blackhatworld.com/members/germanbotmafia.1236241/

Get some help, Charlie. Pretty sure mods should review this as all this shit leads to Telegram where OP sells his imaginary Snapchat bots again. @BassTrackerBoats
 
(removed by myself, content above has been deleted)

BTW: I didn't sell anything at Telegram.
 
Snapchat Reverse Engineering - Part 1 - Snapchat Account Creator Bot - API based


Update announcement (June 7th, 2024)


Progress:

OOOOOOOOOOOOOOOOOOOOOOOOOOOOOO
- around 75 %
0 - - - - - - - - - - - - - - - 50 - - - - - - - - - - - - - - 100


Update announcement:

During the last 2 days I found interesting stuff by analyzing the "native libraries" (see updates above) - aka .so files - again.

2 people asked me about the "root" detection of the Snapchat Android app, another guy asked the same about "Frida" (see updates above). So I will be able to answer this soon with many details.

Unfortunately it takes a lot of time to inspect all Assembler code (even the pseudo code), because Snapchat jumps around trough different functions/modules to not do a single check at the same place. And to let the inspector lose the overview. ;-)

Anyways, it's day 7, and the success rate of the previously mass created accounts from the last weekend is very high. Most of them are still alive, working and didn't receive any lock or ban.

To keep a long story short: The completion level has been increased to 75 % above, and my next update will follow as soon as I invested a few more hours into the Assembler code. Therefore today's "update announcement" only.


Thank you to everybody contacting me at Telegram, but sometimes I am very busy and need a few hours to reply (please remember my timezone UTC+2 West Europe). Nevertheless I really enjoy to talk to each of you guys. You can find the link at my BHW profile.



Some easy terms have been used to make it easier for non-professionals to read and understand the concept. For example: I wrote "access tokens", "hard coded" or "encoded" although there is much more behind.


(I am not native English/American, so please excuse any spelling or grammar mistakes.)


Short updates (random daily work) will be posted at my BHW profile: https://www.blackhatworld.com/members/reverseengineering.1413206/

So maybe you should follow me here at BHW to keep you up-to-date? https://www.blackhatworld.com/members/reverseengineering.1413206/follow
Stop taking people off the forum and onto the scammer's paradise, Telegram.
 
Somebody warned me about the haters who write at BHW (user @xbycx with his first post, freshly registered).

If you really think I am a scammer, please create a dispute thread here: https://www.blackhatworld.com/forums/dispute-resolution.31/ Please attach the invoice, a payment proof, the software you ordered, a valid conversation etc.

I scammed nobody, I have nothing to offer for sale, I don't even plan a sale at the moment.


Please stop accusing me for criminal activities and offending me:



Or show a public proof for everything (invoices, payment proofs, software you ordered, conversations etc.) here: https://www.blackhatworld.com/forums/dispute-resolution.31/


I will talk to a BHW moderator very soon about you @xbycx (first post) and @whitecupg (first post since September 2023).


P. S.: The next "journey" thread with the disclosure of important app details will be posted at the closed Jr. VIP section. So anonymous haters with 1-day-accounts can't view the content.
That would suck for non jr vips. Ignore them.
 
The next person that takes this thread and derails it will have ended their own journey on BHW (nice way to say I'll ban you).

Stay on topic!
 
Good Luck on this.
I have to say I only really understood the title! LOL
 
Snapchat Reverse Engineering - Part 1 - Snapchat Account Creator Bot - API based


Update 3 (June 15th, 2024)


Progress:

OOOOOOOOOOOOOOOOOOOOOOOOOOOOOO
- around 85 %
0 - - - - - - - - - - - - - - - 50 - - - - - - - - - - - - - - 100

Backend - Linux servers: 100 % complete
Frontend - GUI, API: 20 % complete


Account stability/ban rate:

Since June 8th, 2024: 0,00 % (0 accounts locked/permanently locked, banned)


Previous journey thread delays:

I would like to apologize for the missing journey thread updates during the last week. I didn't abandon this thread, as explained here: profile post

I managed to reach a huge milestone in the account creation process last weekend. I also detected at least 4 more Snapchat leaks (missing security flows at the Snapchat API).

The negative side: I had to work on this 20 hours per day, so there was no time left for any update here.

So the next journey thread updates will be shorter but will happen more frequently. There are around 12 more topics on my journey thread update TODO.

So, let's start. Shall we?


Snapchat loves to track your activities:

Similar to TikTok and other social media apps also Snapchat tracks your activities.

One example is the input field for your username:

For every character you type online Snapchat does at least 1 HTTP/2.0 gRPC Protobuf request, sometimes even 2.

Snapchat is able to measure your input speed. So if you really try to use an ADB connection to your Android device (or, worst case, Android emulator), please don't to a quick insert. Implement some delays instead.

Anything automated will risk your account lifetime.


Randomize your user agent:

User agent? The what? [1]

Rich (BB code):
POST https://aws.api.snapchat.com/snapchat.janus.api.RegistrationService/RegisterWithUsernamePassword HTTP/2.0

Request header:

accept-encoding:                 br
accept-language:                 en
x-request-id:                    (removed)
x-snap-janus-request-created-at: (removed)
te:                              trailers
content-type:                    application/grpc
user-agent:                      Snapchat/12.x.x.x (xxx; Android xx.0#xxx; gzip) V/MUSHROOM grpc-c++/x.x.x grpc-c/x.x.x (android; cronet_http)
grpc-accept-encoding:            identity,deflate,gzip
grpc-timeout:                    30S

(...)

(Typical HTTP/2.0 gRPC Protobuf request header for the registration of accounts under Android.)


1. Don't use the same user agent for every request.

2. Randomize the Snapchat version your software emulates (e. g. Snapchat 12.90.0.46), but please make sure that this version matches your DeviceID request:

Rich (BB code):
POST https://app.snapchat.com/loq/device_id HTTP/1.1

Request header:

(...)
user-agent:                      Snapchat/12.x.x.x (xxx; Android xx.0#xxx; gzip) V/MUSHROOM)
(...)

Request body:

req_token=xxx@timestamp=xxx

(Typical HTTP/1.1 POST request to use (register) your Android device, without Protobuf content.)

As a result you will receive 2 important variables: dtoken1i and dtoken1v Both are required at several places.


3. The same for the Android version and Android device description your software emulates (e. g. Android 14.0, SAMSUNG SM-S918B).


(Edit: Further content had to be posted below because BHW displayed an error.)



Some easy terms have been used to make it easier for non-professionals to read and understand the concept. For example: I wrote "access tokens", "hard coded" or "encoded" although there is much more behind.


(I am not native English/American, so please excuse any spelling or grammar mistakes.)


Side notes (linked from above):

[1] - User agent: https://en.wikipedia.org/wiki/User-Agent_header


Short updates (random daily work) will be posted at my BHW profile: https://www.blackhatworld.com/members/reverseengineering.1413206/

So maybe you should follow me here at BHW to keep you up-to-date? https://www.blackhatworld.com/members/reverseengineering.1413206/follow
 
Last edited:
Unfortunately BHW didn't let me post all prepared content (screenshot with the error message follows). The edit with additional text also didn't work.

So I was forced to separate it into 2 parts.




Be careful with your Snapchat account verification by email:


Email is the best method to verify your freshly created Snapchat accounts, since every permanently available mobile number (SMS) costs a lot of money if you let the bot create 1000 or 2000 Snapchat accounts per day.

Of course this will work only with permanently available, so non-disposable email addresses. Gmail addresses are the way to go.

But please be careful if you verify your emails with browsers like Google Chrome or use the same IP address for every verification:

1. Google Chrome contains code to track your activities. They also used to have an UUID (Universally Unique Identifier), for each installation of Google Chrome a different code. Officially Google claims to have removed this UUID years ago. But who knows, Chrome is not open source. Snapchat uses the Google cloud for a few server activities, so who knows if Google also shares such data with Snapchat?

2. Snapchat sends HTML emails containing remote images with also unique identification strings. So if you happen to verify more than 1 Snapchat account with the same browser, same IP address, same cookie set you can forget your accounts on the long run.

3. Of course you should also keep an eye on WebRTC (reveals your real IP address) and OS specific settings like "Do not track".



That's all for today.

Do you have questions, suggestions, own experiences? Then please reply to this thread.

I would be very happy to answer to your replies. But please remember to not trash this thread again.


Screenshot of the BHW error message:

1718455409122.png
 
Last edited:
2. Randomize the Snapchat version your software emulates (e. g. Snapchat 12.90.0.46), but please make sure that this version matches your DeviceID request:
As a result of near duplicates scanning on social media I found out how to create music, so I don't have 2 same songs ever. https://supercollider.github.io/

Well, I also learned how to create hundreds of videos that make sense...

It's a lot you learn when you build something serious.

Some fool tried to convince me once that they don't scan inputs and they don't check times, typing speed etc.

well, if you automate realistically everything, it's impossible for them to see a difference

There are people who think Google deep learning algorithms are simple LOL!
 
Snapchat Reverse Engineering - Part 1 - Snapchat Account Creator Bot - API based


Update 3 (June 15th, 2024)


Progress:

OOOOOOOOOOOOOOOOOOOOOOOOOOOOOO
- around 85 %
0 - - - - - - - - - - - - - - - 50 - - - - - - - - - - - - - - 100

Backend - Linux servers: 100 % complete
Frontend - GUI, API: 20 % complete


Account stability/ban rate:

Since June 8th, 2024: 0,00 % (0 accounts locked/permanently locked, banned)


Previous journey thread delays:

I would like to apologize for the missing journey thread updates during the last week. I didn't abandon this thread, as explained here: profile post

I managed to reach a huge milestone in the account creation process last weekend. I also detected at least 4 more Snapchat leaks (missing security flows at the Snapchat API).

The negative side: I had to work on this 20 hours per day, so there was no time left for any update here.

So the next journey thread updates will be shorter bot happen more frequently. There are around 12 more topics on my journey thread update TODO.

So, let's start. Shall we?


Snapchat loves to track your activities:

Similar to TikTok and other social media apps also Snapchat tracks your activities.

One example is the input field for your username:

For every character you type online Snapchat does at least 1 HTTP/2.0 gRPC Protobuf request, sometimes even 2.

Snapchat is able to measure your input speed. So if you really try to use an ADB connection to your Android device (or, worst case, Android emulator), please don't to a quick insert. Implement some delays instead.

Anything automated will risk your account lifetime.


Randomize your user agent:

User agent? The what? [1]

Rich (BB code):
POST https://aws.api.snapchat.com/snapchat.janus.api.RegistrationService/RegisterWithUsernamePassword HTTP/2.0

Request header:

accept-encoding:                 br
accept-language:                 en
x-request-id:                    (removed)
x-snap-janus-request-created-at: (removed)
te:                              trailers
content-type:                    application/grpc
user-agent:                      Snapchat/12.x.x.x (xxx; Android xx.0#xxx; gzip) V/MUSHROOM grpc-c++/x.x.x grpc-c/x.x.x (android; cronet_http)
grpc-accept-encoding:            identity,deflate,gzip
grpc-timeout:                    30S

(...)

(Typical HTTP/2.0 gRPC Protobuf request header for the registration of accounts under Android.)


1. Don't use the same user agent for every request.

2. Randomize the Snapchat version your software emulates (e. g. Snapchat 12.90.0.46), but please make sure that this version matches your DeviceID request:

Rich (BB code):
POST https://app.snapchat.com/loq/device_id HTTP/1.1

Request header:

(...)
user-agent:                      Snapchat/12.x.x.x (xxx; Android xx.0#xxx; gzip) V/MUSHROOM)
(...)

Request body:

req_token=xxx@timestamp=xxx

(Typical HTTP/1.1 POST request to use (register) your Android device, without Protobuf content.)

As a result you will receive 2 important variables: dtoken1i and dtoken1v Both are required at several places.


3. The same for the Android version and Android device description your software emulates (e. g. Android 14.0, SAMSUNG SM-S918B).






Some easy terms have been used to make it easier for non-professionals to read and understand the concept. For example: I wrote "access tokens", "hard coded" or "encoded" although there is much more behind.


(I am not native English/American, so please excuse any spelling or grammar mistakes.)


Side notes (linked from above):

[1] - User agent: https://en.wikipedia.org/wiki/User-Agent_header


Short updates (random daily work) will be posted at my BHW profile: https://www.blackhatworld.com/members/reverseengineering.1413206/

So maybe you should follow me here at BHW to keep you up-to-date? https://www.blackhatworld.com/members/reverseengineering.1413206/follow
To put the ban rate into perspective, how many accounts were created during that time?
 
To put the ban rate into perspective, how many accounts were created during that time?

Tens of thousands, so far.

2 weeks ago (June 1st/2nd) I experimented a lot with the settings, had no real device randomization by the software etc. So I lost a few accounts because I played too much around.

But since June 8th everything is fine. :)

Interesting Journey. I'll be following.

Thank you. :)
 
Status
Not open for further replies.
Back
Top