Snapchat Reverse Engineering - Part 1 - Snapchat Account Creator Bot - API based

Status
Not open for further replies.
Hello, I have some questions that have not been asked here in your topic yet :)

Could you tell me more about the legal aspect of your actions? Since you are breaking app code, isn`t it considered as same lvl as e.g. house burglary? If so, how can they prove it and what techniques do you use to be as anonymous as possible?
Also, is there a noncontractual line that it is better not to cross when playing with reverse engineering?
If you sell your code to someone and they will use it in bad purpose, who would be in charge, you or him?
 
Could you tell me more about the legal aspect of your actions? Since you are breaking app code, isn`t it considered as same lvl as e.g. house burglary? If so, how can they prove it and what techniques do you use to be as anonymous as possible?
Also, is there a noncontractual line that it is better not to cross when playing with reverse engineering?
If you sell your code to someone and they will use it in bad purpose, who would be in charge, you or him?

I am not a lawyer, but of course I use consultations by lawyers.

Reverse engineering is no crime, because I don't use it for hacking accounts, phishing accounts or causing financial damage to users.

It's almost the same like SEO, you break the ToS, of course. But you don't commit a crime. 2 years ago somebody posted illegal stuff by using on of my tools (SaaS), I banned him right away.

Every few weeks somebody asks me to "hack" something. I clearly reject such offers, no matter what they would pay.

I don't plan to sell my personal library (containing code to use the internal APIs of many known platforms), so it can't be abused.


* Edit: I didn't write that I also reverse engineered some hardware based solutions and industrial communications in 2022 and also 2023. So I'm not just focussed on social media apps.
 
Last edited:
without a bridge or signer you wouldn't be able to make the x-snapchat-att therefor you wouldn't be able to make the request as it would just 401 you

also you've reversed the following: x-snapchat-att, the sensor data and safetynet or google integrity?

(i've said i've doubted you before but this just raises more questions as the only other person i know who's reversed google integrity & safetynet is charging each person on their "signing api" $40,000 a month so if you had done this you wouldn't be working the 20 hours or whatever it was you work) but hey that's just my opinion

So, you're not going to answer these questions?
No, my goal was to rebuild all requests for accounts.snapchat.com regarding the email verification only. Just this small part.

1 API call and that's it. Why make it sound like something so complicated?
Please use the ignore button if you can't get along with another member. Also, be respectful towards each member, as you can agree to disagree, but don't let it take up the thread.

Tbh this isn't a small topic. He claims to have so much done and yet he refuses to answer anything. Then come his friend and both bumping the threads in any way possible to keep it at top. Again since I'm in this snap scene, I know how fishy they both are operating atm. He claims to not use any signer or anything but without a working signer his API requests are going to be rejected in first place. It's a journey thread, I understand that. But then he is saying "hire me", has telegram in his main post.

He opened a RE thread and a very few people asked him questions that relates to RE and he choose to ignore all those RE questions + he reports them to keep them away from this thread. This is a complete joke tbh.
 
@th3darkknight I'm not going to answer to your offending questions or react to your false accusations. We all saw that you are the only follower of l****** and just appeared after he started to trash my journey thread.

It's your right to think that I'm unable to reverse engineer, unable to use the right API endpoints, and that I don't answer anything. The smart BlackHatWorld user will understand the plan you follow.

PS: Done with this thread and OP.

I suggest you to create your own thread about Snapchat. There you can bully around, offend people (falsely) for bumping, offend people (falsely) for hidden sales activities and let your friend promote his unauthorized sales incl. a website with a sort of crypto miner or other trojan (I have been told).

Please stop trashing my journey thread. And good luck for your sales!

Have a nice time!
 
Last edited:
@th3darkknight I'm not going to answer to your offending questions or react to your false accusations. We all saw that you are the only follower of l****** and just appeared after he started to trash my journey thread.

It's your right to think that I'm unable to reverse engineer, unable to use the right API endpoints, and that I don't answer anything. The smart BlackHatWorld user will understand the plan you follow.
Haha, in business you need to be wise enough to understand that everyone can lie and do anything.

But the trick is to use even wisdom liars and cheaters tell you.

I can learn both from you and those people that write accusations without tangible proofs, just simple "America / New York" speculation.

If we go to some big guy, a billionaire like Bill Gates, everyone calls him a liar and a scammer.

But is this really true? lol

Even if it was all built on lies and stuff, you can still learn all the terminology and find inspiration.

It's not some thievery but engineering. Concepts are concepts - that's all we need. It doesn't matter if everything is made up or not. Just take those concepts and learn from them.

So reading this journey I learned that what could be an interesting branch to learn is "pentesting" and some basics of "ethical hacking". Then some C++, but do it slowly, so you don't get discouraged but actually can make use of it.

It's all about vulnerabilities in large systems.

I like how people think that "few lines of code" cannot be powerful. "Bro, it's just an API call".

Have these people ever seen inlined code? In inlined code you can put 50 operations in 3 lines lol.

This is just sick.

I have broken down a library into pieces to write tests called "puppeteer" and I found there's so many pitfalls created by creators (Google) that you need to write your own, specific implementations of many functions. I don't know if CIA with Google does that on purpose to scary kids away from automation.

If someone is in college and they can't break through all those Selenium and Puppeteer tricks presented to them, they'll probably give up. In a podcast with Lex Fridman I saw a large social media site owner talking about elimination of 80% of bots or something like that. And... and that's how they can eliminate 80% of bots, by eliminating kids that want to make easy money. They just make it hard.

Now those functions aren't anything sophisticated, but to get to that point where you actually understand that you need them is time consuming and it's not just "window manipulation" or "DOM manipulation". It's a long process of journey that some people just dumb down to some simple equation like 1 + 1.

No, it's not 1 + 1. It's a long term deduction that doesn't happen in one day.
 
Last edited:
Question:

Which topic would you like to learn a little more about (at my next thread updates)?


1. How to generate signed tokens (for the HTTP request headers, for the gRPC Protobuf HTTP body) without using connected phones, Android emulators, browser emulators or external signing services?

2. How to avoid HTTP errors like 401 or 403 without using phones, emulators, external services etc.?

3. How to distract Snapchat during the automated mass account creation and following "warm up" workflows?

4. How to boost the Snapchat score automatically (no phones, no emulators, no browsers, no signers etc.)?


Please kindly let me know your desired topic. Or maybe something completely different?


(As mentioned earlier I won't post C++/Assembler/... code snippets or memory addresses how to bypass SSL pinning, how to reverse engineer certain Snapchat functions or similar reverse engineering tasks. Please don't ask about it.)

(If you are a seller of Snapchat services or Snapchat accounts, please don't trash this thread, offend me or question my shown skills/methods/setup to boost your own business. Also the BHW moderation team constantly monitors this thread and removes nonsense replies, regardless of my own activities.)
 
3. How to distract Snapchat during the automated mass account creation and following "warm up" workflows?
This could be generally interesting.
2. How to avoid HTTP errors like 401 or 403 without using phones, emulators, external services etc.?
Then this.
4. How to boost the Snapchat score automatically (no phones, no emulators, no browsers, no signers etc.)?
Well, maybe I could make more quality accounts later.
1. How to generate signed tokens (for the HTTP request headers, for the gRPC Protobuf HTTP body) without using connected phones, Android emulators, browser emulators or external signing services?
That's probably most technical of all those.

I think I'll install some C++ libraries.
Libcurl as first. Then what?
 
I think I'll install some C++ libraries.
Libcurl as first. Then what?

Then you should move the environment to a Linux server, I use Ubuntu 22.04 for this (24.04 will follow in a few weeks).

You can use libcurl for the HTTP requests, also for HTTP/2.0 - but I don't use it.

The next of your C++ modules should encrypt and decrypt gRPC Probuf requests and responses.

Good luck to you!

Congratulations for the efforts you put into this
Good luck

Thank you for your feedback.
 
Snapchat Reverse Engineering - Part 1 - Snapchat Account Creator Bot - API based


Update 5 - part 1 (June 23rd, 2024)


Progress:

OOOOOOOOOOOOOOOOOOOOOOOOOOOOOO
- around 90 %
0 - - - - - - - - - - - - - - - 50 - - - - - - - - - - - - - - 100

Backend - Linux servers: 100 % complete
Frontend - GUI, API: ~ 30 % complete
Upscaled hardware (proxy servers, Linux servers, routers): 20 % complete


Account stability/ban rate:

Since June 8th, 2024: 0,00 % (0 of 30,000+ accounts locked/permanently locked, banned)


Update splitting:

This is part 1 of today's update. I have to split it, because a) BlackHatWorld doesn't allow very large posts (as here) b) more exciting news will follow in the evening.


New goal - 30,000 to 40,000 2000 freshly created Snapchat accounts per day:

19 days ago when I started this journey thread I couldn't even think how to reach a high throughput of 2000 accounts per day.

Many people talked to me, told me more about their business model, their current setup and their dreams of upscaling everything.

A few days ago somebody at Telegram asked me if it would be theoretically possible to create 20,000 Snapchat accounts per day. I thought he was joking and asked about his BHW username (he doesn't have an account at BHW yet) to have a look at his profile and posting history. But later he showed me some proofs and explained all details.

I called a female business partner of mine, asked her about another upscaling (pro/con) and we discussed the methods that would be required.

So, as of today (June 23rd, 2024) it's similar to a dream goal to register 30,000 to 40,000 accounts per day, because I would have to buy a lot more customized dedicated servers for this (more details at the FAQ below).

But it's not impossible to reach this goal, since I am independent from "signing" services (people offering a mini API to sign variables for HTTP request headers or gRPC Profobuf requests), all of them unfortunately realized with "bridges" (so either connected Android phones or Android emulators).

Please remember: No matter how hard you try to reject/manipulate Snapchats system requests, Snapchat will sooner or later detect your devices/emulators, the patterns you use, the footprints you leave and start a huge ban wave for all matching accounts. So don't use connected Android phones or Android emulators!

I'll keep you updated...


How many accounts per IP address?

As mentioned above I talk a lot to other Snapchat professionals and their setup, also their individual proxy server usage.

At the moment every created Snapchat account uses a totally separate IPv4 address, based on a /8 network. [1] So, 1 IP address per account. (You can read more about my proxy setup and the meaning of /8 here.)

If Snapchat would support IPv6 completely, this would open a whole new world... ;-)


FAQ - part 2 (part 1 here):

Q: You don't use a signer (look above) or bridge (look above), why don't you get the HTTP errors 401 or 403 or rejections of your request?

A: In my original post I explained that I won't use any connected Android phone, Android emulator or other tricks to create this Android based account creator. This also means I don't use signers or bridges, neither internally (build by myself) not externally (provided by others). I explained the main reason to not use these services above already.

Instead I use reverse engineered parts of the Snapchat app for Android, especially the native libraries, to create my own signatures (encoded variables to be used in HTTP headers and gRPC protobuf requests) in real time.


Q: Why don't you share the reverse engineered code or explain in detail how you did it?

A: BlackHatWorld is a public forum, even unregistered guests/lurkers can read this thread and all updates. I also know that reverse engineering is considered as a sort of crime in some countries far away.

This journey thread has been created to explain you the basics how to rebuild Snapchat requests, avoid a fast detection by Snapchat and show you ways to upscale everything (more to come).

Snap Inc. constantly monitors other platforms, reports Snapchat bot related content and sends orders to take this down. I don't want that this may happen to BHW also.


Q: What do you use to generate the signing instead?

A:
- Pure C++ code of my own library.
- Linux (Ubuntu) servers at my Intranet and data centers.
- A special 5G proxy setup.
- A customized server setup with several graphics cards (GPU usage).
- Price of each customized server: US$ 11,000+


New - Quick links:

- Topic poll (Which topic would you like to learn more about?) (June 22nd, 2024): jump
- Little update (June 20th, 2024): jump
- Update 4 (June 16th, 2024): jump
- Extension to update 3 (June 15th, 2024): jump
- Update 3 (June 15th, 2024): jump
- Update announcement (June 7th, 2024): jump
- Update 2 (June 4th, 2024): jump
- Update 1 (June 4th, 2024): jump
- Original post (June 4th, 2024): jump


(As mentioned earlier I won't post C++/Assembler/... code snippets or memory addresses how to bypass SSL pinning, how to reverse engineer certain Snapchat functions or similar reverse engineering tasks. Please don't ask about it.)

(If you are a seller of Snapchat services or Snapchat accounts, please don't trash this thread, offend me or question my shown skills/methods/setup to boost your own business. Also the BHW moderation team constantly monitors this thread and removes nonsense replies, regardless of my own activities.)


Some easy terms have been used to make it easier for non-professionals to read and understand the concept. For example: I wrote "access tokens", "hard coded" or "encoded" although there is much more behind.


(I am not native English/American, so please excuse any spelling or grammar mistakes.)


Side notes (linked from above):

[1] - CIDR, /8 network https://en.wikipedia.org/wiki/Classless_Inter-Domain_Routing


Short updates (random daily work) will be posted at my BHW profile: https://www.blackhatworld.com/members/reverseengineering.1413206/

So maybe you should follow me here at BHW to keep you up-to-date? https://www.blackhatworld.com/members/reverseengineering.1413206/follow
 
Last edited:
(**0** of 30,000+ accounts locked/permanently locked, banned)

Already $150k value of the green Benjamin made!
Engineering > crypto shills. ;)

19 days ago when I started this journey thread I couldn't even think how to reach a high throughput of 2000 accounts per day.

These are to be achieved with browser automation, but not on Snapchat of course. :D
I believe Snapchat account value is 20x more of what we get on other sites.
So it's like 20k accounts value on other sites.

Please remember: No matter how hard you try to reject/manipulate Snapchats system requests, Snapchat will sooner or later detect your devices/emulators, the patterns you use, the footprints you leave and start **a huge ban wave** for all matching accounts. **So don't use connected Android phones or Android emulators!**

Classic trap made by CIA and NSA.

I mean, Google and Snapchat and Meta, they all have cyber security experts hired and pentesters.

It's actually the same people who work for NSA and CIA.

At the moment every created Snapchat account uses a totally separate IPv4 address, based on a /8 network.
What I think matters at least for me, is that it's better to use proxies from multiple countries / locations.

But from what I understand you got a number of addresses equal to 2²̲⁴ at a.0.0.0/8.

Nobody gives a... about it, but maybe that's a nice benefit to find such a network.

- Price of each customized server: US$ 11,000+
:eek:
It sounds like some quantum computing and breaking cryptography.
These would be even bigger claims.

(As mentioned earlier I won't post C++/Assembler/... code snippets or memory addresses how to bypass SSL pinning, how to reverse engineer certain Snapchat functions or similar reverse engineering tasks. Please don't ask about it.)
People wouldn't understand anything anyways.

I'm the one who actually started it but there are few people actually genuinely who want to know more. :D
I don't know, people just go to telegram and discord, and speak there lol.

Some easy terms have been used to make it easier for non-professionals to read and understand the concept. For example: I wrote "access tokens", "hard coded" or "encoded" although there is much more behind.
So many bits cracked behind the scenes.
 
You mentioned that you are using 5G proxies via raspberry pi. Which HAT/usb dongle do you use and how many for your setup? Can you give more technicalities about the management side like how do you rotate the IP? Did you develop some custom API you can call from server to rotate the IP and how do you call your raspberry pi if you are behind a NAT or dynamic IP?
 
You mentioned that you are using 5G proxies via raspberry pi. Which HAT/usb dongle do you use and how many for your setup? Can you give more technicalities about the management side like how do you rotate the IP? Did you develop some custom API you can call from server to rotate the IP and how do you call your raspberry pi if you are behind a NAT or dynamic IP?

I don't use classic USB dongles, because at my research I found out that most of them don't support 5G (at least at the time I looked into the specifications).

I use external "SIM card slots" with a little electronics attached I bought in 2022 for something completely different (reverse engineering of an industrial solution).

The Raspberry Pi servers contain a classic Ubuntu 22.04 server environment. The API to control the connections, start new connections (retrieve a new IP address), statistics etc. is a custom solution coded in C++ by myself. The recent IP address will be saved at a large database, to be checked by the Raspberry Pi servers, to not use the same IP address twice.

Currently the Raspberry Pi servers are located at a different place, because most data centers don't have a stable 5G signal due to its structures.


Is it possible to do reverse engineering using node.js or PHP or C#?
What would be the main limitation?
What is the benefit of C++?

For the classic reverse engineering you will need tools like IDA Pro, Ghidra and others and at least knowledge of the Assembler language. This has nothing to do with scripting languages like Node.JS or PHP.

You compile your C++ source code, link it (with some libraries) and receive a so called "native code". This native code can't be decompiled like Java, C#, .Net. So if somebody really tries to inspect your software, it's only possible to disassemble it (debugger) or again use tools like IDA Pro, Ghidra & Co.

Scripting languages like PHP, Python etc. can be compiled and/or obfuscated. But similar to C#, Java, .Net and others it's just so called "p-code". So the real "translation" into machine code will be done after you started the compiled executable. Totally different from "native code".

(Some easy terms have been used to make it easier for non-professionals to read and understand the concept.)
 
I don't use classic USB dongles, because at my research I found out that most of them don't support 5G (at least at the time I looked into the specifications).

I use external "SIM card slots" with a little electronics attached I bought in 2022 for something completely different (reverse engineering of an industrial solution).

The Raspberry Pi servers contain a classic Ubuntu 22.04 server environment. The API to control the connections, start new connections (retrieve a new IP address), statistics etc. is a custom solution coded in C++ by myself. The recent IP address will be saved at a large database, to be checked by the Raspberry Pi servers, to not use the same IP address twice.

Currently the Raspberry Pi servers are located at a different place, because most data centers don't have a stable 5G signal due to its structures.

Alright. So can you give me at least the brand name of that "SIM card slot" you are using? How many SIM cards are you using to run your proxy service or do you use eSIM?

And the most important: How do you connect to your proxy API which is behind NAT?
 
Alright. So can you give me at least the brand name of that "SIM card slot" you are using? How many SIM cards are you using to run your proxy service or do you use eSIM?

And the most important: How do you connect to your proxy API which is behind NAT?

The brand is SIEMENS, it's a module created for remote controls of industrial components (telemetric data, firmware updates etc.). It's originally used together with SIEMENS LOGO! and other products.

Currently I use 5 SIM cards per Raspberry PI server, because 2 of the Raspberry mini servers also do another job sometimes. I don't use eSIMs at the moment.

I remember that @lucky.sparks wrote more details about his own proxy setup in one journey thread: https://www.blackhatworld.com/members/lucky-sparks.1444975/#about Maybe this could help you also.

For the connection of the data center servers to the local Raspberry Pi servers I use a custom solution, a mix between a VPN tunnel and a completely modified proxy software. Maybe not the best solution regarding the required development, but for me it works pretty stable.

If I will reach the 10,000-accounts-milestone (per day) I have to decide about a different solution.

What's your plan, why do you ask?
 
Last edited:
The brand is SIEMENS, it's a module created for remote controls of industrial components (telemetric data, firmware updates etc.). It's originally used together with SIEMENS LOGO! and other products.

Currently I use 5 SIM cards per Raspberry PI server, because 2 of the Raspberry mini servers also do another job sometimes. I don't use eSIMs at the moment.

I remember that @lucky.sparks wrote more details about his own proxy setup in one journey thread: https://www.blackhatworld.com/members/lucky-sparks.1444975/#about Maybe this could help you also.

For the connection of the data servers to the local Raspberry Pi servers I use a custom solution, a mix between a VPN tunnel and a completely modified proxy software. Maybe not the best solution regarding the required development, but for me it works pretty stable.

If I will reach the 10,000-accounts-milestone (per day) I have to decide about a different solution.

What's your plan, why do you ask?

Sorry but something just doesn't add up. You wanna say you use industrial grade Siemens 5G routers for snapchat account creation proof-of-concept which is not yet in production environment and has no monetization plan?

For example Siemens SCALANCE MUM856-1 5G router costs in EU around 1900€ (excl. VAT) and has one SIM slot. In your case you would need at least 5 of them but then again you are speaking about multiple servers with 5 SIM cards EACH so let's say there's at least 10 SIM cards. That would cost you around 19 000€ plus VAT just to set up your 5G proxy service with Siemens 5G devices. Industrial grade 3G/4G/5G devices are expensive as f*ck.

Your reasoning for setting up your own 5G proxy service was cost effectiveness. Your own quote:

Unfortunately 5G IPv4 proxy services are either hard to find or extremely expensive, since most mobile proxies are based on hardware dongles (USB sticks) from Asia with 4G support only (e. g. Huawei).

You also use intentionally vague language when it comes to communication between data center servers and your local raspberry pi's over the public network. You could have just mentioned you use ZeroTier to put your devices in the same network and a few lines of python code to create a REST API with cherrypy like any sane person. Boom, done. Instead you say everything is "custom C++". Who on Earth manages TCP/IP stack with C++ in 2024?

One more thing which is a red flag for any professional developer is your fixation to "Ubuntu 22.04" and the fact that this is basically the only exact technical info about your tech stack. Who cares about the OS when your setup should be dockerized anyway if you want to scale to your intended level. Doesn't matter if your host is running fedora, ubuntu, RHEL, centos or whatever.

To anyone desperate for snapchat automations: Be careful taking discussion off the forum to OP's telegram. This journey stinks.
 
For example Siemens SCALANCE MUM856-1 5G router costs in EU around 1900€ (excl. VAT) and has one SIM slot.

1. I don't use "SCALANCE MUM... whatever" you mentioned above.

2. I also wrote above:

I use external "SIM card slots" with a little electronics attached I bought in 2022 for something completely different (reverse engineering of an industrial solution).

I didn't write anything about brand new hardware or the SIEMENS module you mentioned.

Instead you say everything is "custom C++". Who on Earth manages TCP/IP stack with C++ in 2024?

The C++ library I created is from 2016. Why shouldn't I re-use already existing code for this? Please remember what I wrote about the industrial reverse engineering above...

One more thing which is a red flag for any professional developer is your fixation to "Ubuntu 22.04" and the fact that this is basically the only exact technical info about your tech stack.

A part of my software strictly requires Ubuntu 22.04 Linux, 24.04 will be supported soon I guess.

Regarding the other "tech stack" please check my first post again: https://www.blackhatworld.com/seo/s...apchat-account-creator-bot-api-based.1604235/

This journey stinks.

If you have worries about this thread, please use the "Report" button or talk to a BHW moderator of your choice. ;-)

I didn't sell anything so far, no source code, no binary code, no single account, nothing else.
 
Last edited:
So if you decided that you will not sell anything what is the purpose of this project ?

Welcome to BHW, @TokenBooster (registered today)!

As of now I don't sell anything, that's true.

But maybe I could decide to create a BHW marketplace thread later this year, who knows? I'm not sure yet.

About my plans (already answered above many times):

- Recently: https://www.blackhatworld.com/seo/s...t-creator-bot-api-based.1604235/post-17809620

- Older: https://www.blackhatworld.com/seo/s...t-creator-bot-api-based.1604235/post-17805606


The reason why I created this journey thread is to show a proof of concept, that it really works to create higher numbers of Snapchat accounts without using connected phones, emulators, signers/bridges, browser emulations or other BS.

And also to document my steps to reach the old goal (2000 accounts per day) and maybe also the new goal.
 
1. I don't use "SCALANCE MUM... whatever" you mentioned above.

2. I also wrote above:



I didn't write anything about brand new hardware or the SIEMENS module you mentioned.

If you know your stuff as you claim then why not just give the exact model name for the 5G router you are using? Why do I have to milk some very basic info like this?

You already told that:
a) you built 5G proxy service
b) the 5G device brand is Siemens

The C++ library I created is from 2016. Why shouldn't I re-use already existing code for this?

Because codebase gets old and libraries need constant maintenance and refactoring. I wouldn't trust a single proprietary API open to public internet written in 2016 especially when using a readymade, open source, well-maintained REST API library in any language is so trivial nowadays.
 
Status
Not open for further replies.
Back
Top