reRust
Traffic interception for Rust-based mobile apps — the reFlutter playbook, applied to rustls/reqwest cores.
Mobile apps increasingly move their networking into a statically-linked Rust library.
That kills every classic interception technique at once: TLS terminates inside the .so
with compiled-in Mozilla roots (webpki-roots), the platform CA store is never consulted,
and the Wi-Fi proxy settings are ignored because reqwest only speaks HTTP(S)_PROXY env
vars that Android never sets.
reRust makes those apps transparent again:
rerust inspect app.apk— fingerprint the Rust core (exact crate versions, TLS stack, trust store flavor) straight from a stripped binary.rerust patch app.apk --proxy http://127.0.0.1:9999— repack with an env-proxy shim + fingerprint-gated trust patch (+ optionalconnect()hook for cores without env plumbing); debug-signed output that runs on unrooted devices.rerust frida <apk|lib> --proxy URL— the same interception at runtime, no repack.
# pip / uv
pip install rerust
uv tool install rerust # or from a clone: uv sync && uv run rerust --help
# end-to-end lab recipe (validated on production-image emulators, no root):
rerust patch app.apk --proxy http://127.0.0.1:9999 --out app.rerust.apk
adb reverse tcp:9999 tcp:8080 # tunnel to Burp/mitmproxy — never rely on 10.0.2.2
adb install -r app.rerust.apk
# decrypted HTTP/2 lands in your proxy within seconds of launch
No CA installation is needed for the Rust core — the trust patch makes the client accept the proxy's certificate, which is why patched apps run unrooted. Platform-store consumers (Java/WebView/Dart) are covered separately in docs/lab-setup.md, including the modern-Android apex-store recipe.
The pattern DB is keyed by library build, not app: off-the-shelf cores (rhttp,
Tauri v2's reqwest, …) ship identical .so files across apps, so each entry unlocks
every app on that release — and entries can be farmed proactively against self-built
pinned targets (docs/corpus-farming.md).
Docs: SPEC.md · lab setup · pattern derivation · corpus farming
Lineage: from the maintainer of reFlutter.
License: MIT
Metadata
Release files for rerust 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| rerust-0.1.0.tar.gz | 89.7 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| rerust-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 118.0 kB
Release files / rerust-0.1.0.tar.gz
| Download URL | rerust-0.1.0.tar.gz |
|---|---|
| Size | 89.7 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
61693b41a637743f56735432bbb6f3928522be5115a05cb8983fcfeed33729bd
|
|
BLAKE2b-256 checksum How to use checksums |
d739ed6bd78a68edb3b562304f4fe648e3581f07c4c67d6e97e046974552faa5
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.11.4
|
Release files / rerust-0.1.0-py3-none-any.whl
| Download URL | rerust-0.1.0-py3-none-any.whl |
|---|---|
| Size | 28.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
433398ccfbd47adc80d9b74a6a155fb630254140f4cc57603d6f9f504a11e4c1
|
|
BLAKE2b-256 checksum How to use checksums |
150ee45f1130590f6bb4d70d879613c4240ca364f77354332f0481900527269d
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.11.4
|