{"repo":"Impact-I/reFlutter","free":true,"listed":false,"github":"https://github.com/Impact-I/reFlutter","clone":"git clone https://github.com/Impact-I/reFlutter.git","description":"Flutter Reverse Engineering Framework","language":"Python","stars":2732,"topics":["bugbounty","mobile-security","reverse-engineering","ssl-pinning"],"license":"GPL-3.0","category":"security-tools","readme_excerpt":"Read more on the blog: This framework helps with Flutter apps reverse engineering using the patched version of the Flutter library which is already compiled and ready for app repacking. This library has snapshot deserialization process modified to allow you perform dynamic analysis in a convenient way. Key features: - socket.cc is patched for traffic monitoring and interception; - dart.cc is modified to print classes, functions and some fields; - display absolute code offset for functions; - contains minor changes for successful compilation; - if you would like to implement your own patches, manual Flutter code changes are supported using a specially crafted Dockerfile . Supported engines - Android: arm64, arm32; - iOS: arm64; - Release: Stable, Beta Install Usage Traffic interception You need to specify the IP of your Burp Suite Proxy Server located in the same network where the device with the Flutter application is. Then configure the Proxy in BurpSuite - Listener Proxy - Options tab : - Add port: 8083 - Bind to address: All interfaces - Request handling: Support invisible proxying = True No certificate installation or root access is required for Android. reFlutter also allows bypassing some of the Flutter certificate pinning implementations. ⚠️ Note: Starting from Flutter version 3.24.0 (snapshot hash: 80a49c7111088100a233b2ae788e1f48 ), the hardcoded proxy IP and port have been removed. You now need to configure your proxy directly on the device. On Android Use ADB to co","default_branch":null,"files":null,"tree":[],"storefront":"/r/Impact-I","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/Impact-I/reFlutter/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}