Skip to main content

reRust

Traffic interception for Rust-based mobile apps — the reFlutter playbook, applied to rustls/reqwest cores.

Mobile apps increasingly move their networking into a statically-linked Rust library. That kills every classic interception technique at once: TLS terminates inside the .so with compiled-in Mozilla roots (webpki-roots), the platform CA store is never consulted, and the Wi-Fi proxy settings are ignored because reqwest only speaks HTTP(S)_PROXY env vars that Android never sets.

reRust makes those apps transparent again:

  • rerust inspect app.apk — fingerprint the Rust core (exact crate versions, TLS stack, trust store flavor) straight from a stripped binary. .ipa and bare Mach-O images work too.
  • rerust patch app.apk|.ipa --proxy http://127.0.0.1:9999 — repack with an env-proxy shim + fingerprint-gated trust patch (+ optional connect() hook for cores without env plumbing); debug-signed APK output that runs on unrooted devices, ad-hoc re-signed ipa output for the iOS pipeline (simulator-validated; see the iOS section of docs/lab-setup.md).
  • rerust frida <apk|lib> --proxy URL — the same interception at runtime, no repack.
# pip / uv
pip install rerust
uv tool install rerust        # or from a clone: uv sync && uv run rerust --help

# end-to-end lab recipe (validated on production-image emulators, no root):
rerust patch app.apk --proxy http://127.0.0.1:9999 --out app.rerust.apk
adb reverse tcp:9999 tcp:8080   # tunnel to Burp/mitmproxy — never rely on 10.0.2.2
adb install -r app.rerust.apk
# decrypted HTTP/2 lands in your proxy within seconds of launch

No CA installation is needed for the Rust core — the trust patch makes the client accept the proxy's certificate, which is why patched apps run unrooted. Platform-store consumers (Java/WebView/Dart) are covered separately in docs/lab-setup.md, including the modern-Android apex-store recipe.

The pattern DB is keyed by library build, not app: off-the-shelf cores (rhttp, Tauri v2's reqwest, …) ship identical .so files across apps, so each entry unlocks every app on that release — and entries can be farmed proactively against self-built pinned targets (docs/corpus-farming.md).

Docs: SPEC.md · lab setup · pattern derivation · corpus farming · iOS Mach-O walkthrough

Lineage: from the maintainer of reFlutter.

License: MIT

Metadata

Release files for rerust 0.2.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for rerust 0.2.0
File Size Uploaded
rerust-0.2.0.tar.gz 129.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for rerust 0.2.0
File Interpreter ABI Platform
rerust-0.2.0-py3-none-any.whl Python 3 none any Details

Total release size: 231.0 kB

Release files / rerust-0.2.0.tar.gz

Download URL rerust-0.2.0.tar.gz
Size 129.1 kB
Tags Source
SHA-256 checksum
How to use checksums
67da9531e219bc4aa064754616dbb036ad63c8fbef51b60ceafd13d014f8c657
BLAKE2b-256 checksum
How to use checksums
0b1c553bf3617860dd357df32634662b329a02b46825a5d1e1e8bfe67d5fc922
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.11.4

Release files / rerust-0.2.0-py3-none-any.whl

Download URL rerust-0.2.0-py3-none-any.whl
Size 102.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
9c7fc4b89f899ac85739c608fca2bc43862e70fac445a759173e74ce26b08c34
BLAKE2b-256 checksum
How to use checksums
6fa81e38642a36442a318eb9f2c006bccf1398c266b9d216edbb3e3e8a2cadf5
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.11.4

Release history Release notifications | RSS feed

This release

0.2.0 This release

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page