
Closed
Posted
Paid on delivery
Requirements Document: WeChat Mini Program Protocol-Level Auto-Purchasing (Sniping) Tool Development 1. Project Overview The objective of this project is to develop an automated purchasing tool based on the protocol layer (implemented in Python or Go). This tool must bypass the mini program's front-end UI by reverse-engineering its core business logic and API interfaces. It will directly construct underlying network requests (HTTP/HTTPS) to achieve millisecond-level automated purchasing and order placement. 2. Core Technical Requirements Platform Environment: WeChat Mini Program (iOS/Android or PC WeChat client). Development Language: Python 3.10+ or Go 1.20+. Reverse Engineering Capabilities: Must possess the ability to decompile mini program packages (.wxapkg), analyze obfuscated JavaScript logic, and extract encryption algorithms (e.g., MD5/AES/RSA). Packet Capture & Decryption: Must be able to bypass HTTPS restrictions, handle SSL Pinning mechanisms, and capture plaintext requests/responses between the mini program and the server. Protocol Simulation: Fully simulate the acquisition of the WeChat login state, Token maintenance, and various Header parameters required during order placement (e.g., User-Agent, Referer, X-Sign). 3. Functional Requirements List A. Interface Reverse Engineering & Analysis Login Module: Simulate the WeChat [login to view URL] process to exchange the code for the business-side token or session_id. Parameter Decryption: Reverse-engineer dynamically changing encrypted parameters within the order request (e.g., timestamp salts, signature validation sign, and encrypted data payloads). Path Restoration: Identify the core purchasing endpoints (Check-in, Add-to-cart, Submit-order). B. Auto-Purchasing Logic Implementation Precise Timing: Support NTP network time synchronization to trigger requests at the millisecond (ms) level. Concurrency Control: Support multi-threading or Coroutines (Goroutines) for high-frequency requests to respond to inventory refreshes. Inventory Monitoring: Monitor product status in real-time and trigger order placement the exact moment it changes to "Available for sale." C. Bypassing & Anti-Risk Control Certificate Injection: Provide a solution to bypass certificate validation in specific environments (such as Rooted/Jailbroken devices or emulators). Risk Control Bypass: Provide reserved interfaces or integrate third-party captcha-solving platforms to handle risk control measures triggered during order placement, such as image captchas or sliders. 4. Deliverables Requirements Complete Source Code: Must include the core reverse engineering logic and the recreated encryption algorithm code. Environment Setup Guide: Instructions on how to configure the packet capture environment (e.g., using Charles/Fiddler + HttpCanary/Frida). Configuration Files: Allow users to customize settings such as the purchase execution time, product ID, Token information, concurrency limits, etc. Technical Documentation: A brief explanation of the API encryption logic and the method used to maintain the login state. 5. Developer Capability Evaluation Metrics (Suggested Interview Questions) "How do you handle header signature encryption for Request APIs within a WeChat Mini Program?" "For mini programs that have SSL Pinning enabled, what are your standard unpacking and packet capture solutions?" "If the target mini program utilizes WeChat native plugins or highly obfuscated JS code, how do you locate the exact order placement logic?"
Project ID: 40393156
53 proposals
Remote project
Active 25 days ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs