Skip to main content

reRust

Traffic interception for Rust-based mobile apps — the reFlutter playbook, applied to rustls/reqwest cores.

Mobile apps increasingly move their networking into a statically-linked Rust library. That kills every classic interception technique at once: TLS terminates inside the .so with compiled-in Mozilla roots (webpki-roots), the platform CA store is never consulted, and the Wi-Fi proxy settings are ignored because reqwest only speaks HTTP(S)_PROXY env vars that Android never sets.

reRust makes those apps transparent again:

  • rerust inspect app.apk — fingerprint the Rust core (exact crate versions, TLS stack, trust store flavor) straight from a stripped binary.
  • rerust patch app.apk --proxy http://127.0.0.1:9999 — repack with an env-proxy shim + fingerprint-gated trust patch (+ optional connect() hook for cores without env plumbing); debug-signed output that runs on unrooted devices.
  • rerust frida <apk|lib> --proxy URL — the same interception at runtime, no repack.
# pip / uv
pip install rerust
uv tool install rerust        # or from a clone: uv sync && uv run rerust --help

# end-to-end lab recipe (validated on production-image emulators, no root):
rerust patch app.apk --proxy http://127.0.0.1:9999 --out app.rerust.apk
adb reverse tcp:9999 tcp:8080   # tunnel to Burp/mitmproxy — never rely on 10.0.2.2
adb install -r app.rerust.apk
# decrypted HTTP/2 lands in your proxy within seconds of launch

No CA installation is needed for the Rust core — the trust patch makes the client accept the proxy's certificate, which is why patched apps run unrooted. Platform-store consumers (Java/WebView/Dart) are covered separately in docs/lab-setup.md, including the modern-Android apex-store recipe.

The pattern DB is keyed by library build, not app: off-the-shelf cores (rhttp, Tauri v2's reqwest, …) ship identical .so files across apps, so each entry unlocks every app on that release — and entries can be farmed proactively against self-built pinned targets (docs/corpus-farming.md).

Docs: SPEC.md · lab setup · pattern derivation · corpus farming

Lineage: from the maintainer of reFlutter.

License: MIT

Metadata

Release files for rerust 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for rerust 0.1.0
File Size Uploaded
rerust-0.1.0.tar.gz 89.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for rerust 0.1.0
File Interpreter ABI Platform
rerust-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 118.0 kB

Release files / rerust-0.1.0.tar.gz

Download URL rerust-0.1.0.tar.gz
Size 89.7 kB
Tags Source
SHA-256 checksum
How to use checksums
61693b41a637743f56735432bbb6f3928522be5115a05cb8983fcfeed33729bd
BLAKE2b-256 checksum
How to use checksums
d739ed6bd78a68edb3b562304f4fe648e3581f07c4c67d6e97e046974552faa5
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.11.4

Release files / rerust-0.1.0-py3-none-any.whl

Download URL rerust-0.1.0-py3-none-any.whl
Size 28.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
433398ccfbd47adc80d9b74a6a155fb630254140f4cc57603d6f9f504a11e4c1
BLAKE2b-256 checksum
How to use checksums
150ee45f1130590f6bb4d70d879613c4240ca364f77354332f0481900527269d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.11.4

Release history Release notifications | RSS feed

0.2.0

2 release files

0.1.1

2 release files

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page