Snapchat Reverse Engineering - Part 1 - Snapchat Account Creator Bot - API based
Update 5 - part 1 (June 23rd, 2024)
Progress:
OOOOOOOOOOOOOOOOOOOOOOOOOOOOOO - around
90 %
0 - - - - - - - - - - - - - - - 50 - - - - - - - - - - - - - - 100
Backend - Linux servers: 100 % complete
Frontend - GUI, API: ~ 30 % complete
Upscaled hardware (proxy servers, Linux servers, routers): 20 % complete
Account stability/ban rate:
Since June 8th, 2024:
0,00 % (
0 of 30,000+ accounts locked/permanently locked, banned)
Update splitting:
This is part 1 of today's update. I have to split it, because a) BlackHatWorld doesn't allow very large posts (as
here) b) more exciting news will follow in the evening.
New goal - 30,000 to 40,000 2000 freshly created Snapchat accounts per day:
19 days ago when I started this journey thread I couldn't even think how to reach a high throughput of 2000 accounts per day.
Many people talked to me, told me more about their business model, their current setup and their dreams of upscaling everything.
A few days ago somebody at Telegram asked me if it would be theoretically possible to create 20,000 Snapchat accounts per day. I thought he was joking and asked about his BHW username (he doesn't have an account at BHW yet) to have a look at his profile and posting history. But later he showed me some proofs and explained all details.
I called a female business partner of mine, asked her about another upscaling (pro/con) and we discussed the methods that would be required.
So, as of today (June 23rd, 2024) it's similar to a dream goal to register 30,000 to 40,000 accounts per day, because I would have to buy a lot more customized dedicated servers for this (more details at the FAQ below).
But it's not impossible to reach this goal, since I am
independent from "signing" services (people offering a mini API to sign variables for HTTP request headers or gRPC Profobuf requests), all of them unfortunately realized with "bridges" (so either connected Android phones or Android emulators).
Please remember: No matter how hard you try to reject/manipulate Snapchats system requests, Snapchat will sooner or later detect your devices/emulators, the patterns you use, the footprints you leave and start
a huge ban wave for all matching accounts.
So don't use connected Android phones or Android emulators!
I'll keep you updated...
How many accounts per IP address?
As mentioned above I talk a lot to other Snapchat professionals and their setup, also their individual proxy server usage.
At the moment every created Snapchat account uses a totally separate IPv4 address, based on a /8 network.
[1] So, 1 IP address per account. (You can read more about my proxy setup and the meaning of /8
here.)
If Snapchat would support IPv6 completely, this would open a whole new world... ;-)
FAQ - part 2 (part 1 here):
Q: You don't use a signer
(look above) or bridge
(look above), why don't you get the HTTP errors 401 or 403 or rejections of your request?
A: In my original post I explained that I won't use any connected Android phone, Android emulator or other tricks to create this Android based account creator. This also means I don't use signers or bridges, neither internally (build by myself) not externally (provided by others). I explained the main reason to not use these services above already.
Instead I use reverse engineered parts of the Snapchat app for Android, especially the native libraries, to create my own signatures (encoded variables to be used in HTTP headers and gRPC protobuf requests) in real time.
Q: Why don't you share the reverse engineered code or explain in detail how you did it?
A: BlackHatWorld is a public forum, even unregistered guests/lurkers can read this thread and all updates. I also know that reverse engineering is considered as a sort of crime in some countries far away.
This journey thread has been created to explain you the basics how to rebuild Snapchat requests, avoid a fast detection by Snapchat and show you ways to upscale everything (more to come).
Snap Inc. constantly monitors other platforms, reports Snapchat bot related content and sends orders to take this down. I don't want that this may happen to BHW also.
Q: What do you use to generate the signing instead?
A:
- Pure C++ code of my own library.
- Linux (Ubuntu) servers at my Intranet and data centers.
- A special 5G proxy setup.
- A customized server setup with several graphics cards (GPU usage).
- Price of each customized server: US$ 11,000+
New - Quick links:
- Topic poll (Which topic would you like to learn more about?) (June 22nd, 2024):
jump
- Little update (June 20th, 2024):
jump
- Update 4 (June 16th, 2024):
jump
- Extension to update 3 (June 15th, 2024):
jump
- Update 3 (June 15th, 2024):
jump
- Update announcement (June 7th, 2024):
jump
- Update 2 (June 4th, 2024):
jump
- Update 1 (June 4th, 2024):
jump
- Original post (June 4th, 2024):
jump
(As mentioned earlier I won't post C++/Assembler/... code snippets or memory addresses how to bypass SSL pinning, how to reverse engineer certain Snapchat functions or similar reverse engineering tasks. Please don't ask about it.)
(If you are a seller of Snapchat services or Snapchat accounts, please don't trash this thread, offend me or question my shown skills/methods/setup to boost your own business. Also the BHW moderation team constantly monitors this thread and removes nonsense replies, regardless of my own activities.)
Some easy terms have been used to make it easier for non-professionals to read and understand the concept. For example: I wrote "access tokens", "hard coded" or "encoded" although there is much more behind.
(I am not native English/American, so please excuse any spelling or grammar mistakes.)
Side notes (linked from above):
[1] - CIDR, /8 network
https://en.wikipedia.org/wiki/Classless_Inter-Domain_Routing
Short updates (random daily work) will be posted at my BHW profile: https://www.blackhatworld.com/members/reverseengineering.1413206/
So maybe you should follow me here at BHW to keep you up-to-date? https://www.blackhatworld.com/members/reverseengineering.1413206/follow