Skip to main content

reRust

Traffic interception for Rust-based mobile apps — the reFlutter playbook, applied to rustls/reqwest cores.

Mobile apps increasingly move their networking into a statically-linked Rust library. That kills every classic interception technique at once: TLS terminates inside the .so with compiled-in Mozilla roots (webpki-roots), the platform CA store is never consulted, and the Wi-Fi proxy settings are ignored because reqwest only speaks HTTP(S)_PROXY env vars that Android never sets.

reRust makes those apps transparent again:

  • rerust inspect app.apk — fingerprint the Rust core (exact crate versions, TLS stack, trust store flavor) straight from a stripped binary.
  • rerust patch app.apk --proxy http://127.0.0.1:9999 — repack with an env-proxy shim + fingerprint-gated trust patch (+ optional connect() hook for cores without env plumbing); debug-signed output that runs on unrooted devices.
  • rerust frida <apk|lib> --proxy URL — the same interception at runtime, no repack.
# pip / uv
pip install rerust
uv tool install rerust        # or from a clone: uv sync && uv run rerust --help

# end-to-end lab recipe (validated on production-image emulators, no root):
rerust patch app.apk --proxy http://127.0.0.1:9999 --out app.rerust.apk
adb reverse tcp:9999 tcp:8080   # tunnel to Burp/mitmproxy — never rely on 10.0.2.2
adb install -r app.rerust.apk
# decrypted HTTP/2 lands in your proxy within seconds of launch

No CA installation is needed for the Rust core — the trust patch makes the client accept the proxy's certificate, which is why patched apps run unrooted. Platform-store consumers (Java/WebView/Dart) are covered separately in docs/lab-setup.md, including the modern-Android apex-store recipe.

The pattern DB is keyed by library build, not app: off-the-shelf cores (rhttp, Tauri v2's reqwest, …) ship identical .so files across apps, so each entry unlocks every app on that release — and entries can be farmed proactively against self-built pinned targets (docs/corpus-farming.md).

Docs: SPEC.md · lab setup · pattern derivation · corpus farming

Lineage: from the maintainer of reFlutter.

License: MIT

Metadata

Release files for rerust 0.1.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for rerust 0.1.1
File Size Uploaded
rerust-0.1.1.tar.gz 107.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for rerust 0.1.1
File Interpreter ABI Platform
rerust-0.1.1-py3-none-any.whl Python 3 none any Details

Total release size: 193.5 kB

Release files / rerust-0.1.1.tar.gz

Download URL rerust-0.1.1.tar.gz
Size 107.7 kB
Tags Source
SHA-256 checksum
How to use checksums
3ad9ab7735c98a502a1eb646f9e66986ddfb74bbcf88675f19f5f14d414a642a
BLAKE2b-256 checksum
How to use checksums
2708cdeeb6da89257720151c343b5bba312cc90e0f53e79f39dcfc7f37166a73
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.11.4

Release files / rerust-0.1.1-py3-none-any.whl

Download URL rerust-0.1.1-py3-none-any.whl
Size 85.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
6ab698cd42e3df292f4f16f32bb54f0c691ea2bf28eb80957dfa2fc81aab6636
BLAKE2b-256 checksum
How to use checksums
4f0c937e8690841f14ffc952b973d6b86e920f16b1cee72b713e726743d313e5
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.11.4

Release history Release notifications | RSS feed

0.2.0

2 release files

This release

0.1.1 This release

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page