reRust
Traffic interception for Rust-based mobile apps — the reFlutter playbook, applied to rustls/reqwest cores.
Mobile apps increasingly move their networking into a statically-linked Rust library.
That kills every classic interception technique at once: TLS terminates inside the .so
with compiled-in Mozilla roots (webpki-roots), the platform CA store is never consulted,
and the Wi-Fi proxy settings are ignored because reqwest only speaks HTTP(S)_PROXY env
vars that Android never sets.
reRust makes those apps transparent again:
rerust inspect app.apk— fingerprint the Rust core (exact crate versions, TLS stack, trust store flavor) straight from a stripped binary..ipaand bare Mach-O images work too.rerust patch app.apk|.ipa --proxy http://127.0.0.1:9999— repack with an env-proxy shim + fingerprint-gated trust patch (+ optionalconnect()hook for cores without env plumbing); debug-signed APK output that runs on unrooted devices, ad-hoc re-signed ipa output for the iOS pipeline (simulator-validated; see the iOS section of docs/lab-setup.md).rerust frida <apk|lib> --proxy URL— the same interception at runtime, no repack.
# pip / uv
pip install rerust
uv tool install rerust # or from a clone: uv sync && uv run rerust --help
# end-to-end lab recipe (validated on production-image emulators, no root):
rerust patch app.apk --proxy http://127.0.0.1:9999 --out app.rerust.apk
adb reverse tcp:9999 tcp:8080 # tunnel to Burp/mitmproxy — never rely on 10.0.2.2
adb install -r app.rerust.apk
# decrypted HTTP/2 lands in your proxy within seconds of launch
No CA installation is needed for the Rust core — the trust patch makes the client accept the proxy's certificate, which is why patched apps run unrooted. Platform-store consumers (Java/WebView/Dart) are covered separately in docs/lab-setup.md, including the modern-Android apex-store recipe.
The pattern DB is keyed by library build, not app: off-the-shelf cores (rhttp,
Tauri v2's reqwest, …) ship identical .so files across apps, so each entry unlocks
every app on that release — and entries can be farmed proactively against self-built
pinned targets (docs/corpus-farming.md).
Docs: SPEC.md · lab setup · pattern derivation · corpus farming · iOS Mach-O walkthrough
Lineage: from the maintainer of reFlutter.
License: MIT
Metadata
Release files for rerust 0.2.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| rerust-0.2.0.tar.gz | 129.1 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| rerust-0.2.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 231.0 kB
Release files / rerust-0.2.0.tar.gz
| Download URL | rerust-0.2.0.tar.gz |
|---|---|
| Size | 129.1 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
67da9531e219bc4aa064754616dbb036ad63c8fbef51b60ceafd13d014f8c657
|
|
BLAKE2b-256 checksum How to use checksums |
0b1c553bf3617860dd357df32634662b329a02b46825a5d1e1e8bfe67d5fc922
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.11.4
|
Release files / rerust-0.2.0-py3-none-any.whl
| Download URL | rerust-0.2.0-py3-none-any.whl |
|---|---|
| Size | 102.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
9c7fc4b89f899ac85739c608fca2bc43862e70fac445a759173e74ce26b08c34
|
|
BLAKE2b-256 checksum How to use checksums |
6fa81e38642a36442a318eb9f2c006bccf1398c266b9d216edbb3e3e8a2cadf5
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.11.4
|