AdguardTeam / AdguardFilters

AdGuard Content Blocking Filters
https://adguard.com/
GNU General Public License v3.0
3.26k stars 635 forks source link

Chinese Xunlei (PikPak) tracker #98913

Closed c2xusnpq6 closed 3 years ago

c2xusnpq6 commented 3 years ago

https://play.google.com/store/apps/details?id=com.pikcloud.pikpak

https://apkpure.com/pikpak-private-cloud-video-saver/com.pikcloud.pikpak

Xunlei (Thunder) official SDK doc: https://open.thunderurl.com/

PikPak is most likely the official overseas version of Xunlei.

Some domains even share an IP address while other apps that use Xunlei SDK do not...

Related Reports:

Tracker:

||res.res.res.res^$app=com.pikcloud.pikpak (1)

/api/stat/rt^

||api-drive.mypikpak.com/drive/v1/events^
or
||api-drive.*/drive/v1/events^$app=com.pikcloud.pikpak (3)

Please download the apk file and try it yourself. 😅

Domains related to this: (3)

xunlei.com
n0808.com
n0909.com
sandai.net
mypikpak.com

Ref:

Classic Xunlei tracking domains: (3):

Just watched a good show in the group of the app, also the reason I post this.

(2): I will post pictures later.

c2xusnpq6 commented 3 years ago

Please don't close this issue easily.😃🤝

c2xusnpq6 commented 3 years ago

https://www.mypikpak.com/

https://indonesia-rcv5.n0909.com/v2/xla.min.js

/api/stat/rt^
/v2/xla.min.js

As I said before, they have multiple domains pointing to the same backend server.

And Xunlei is a notoriously nasty company, just like other early Chinese network companies. This is probably with no competition from other foreign companies in China caused by it ...

So we have to take these companies seriously...

c2xusnpq6 commented 3 years ago

Screenshot

xbase.cloud is owned by Xunlei

c2xusnpq6 commented 3 years ago

Screenshot

Look at the value of the ip it points to.

www.virustotal.com

c2xusnpq6 commented 3 years ago

Screenshot

Another common "fallback method" (or "escape method") for Chinese apps/sdk

Directly connect to the backend server with ip

www.virustotal.com

c2xusnpq6 commented 3 years ago

They will use a lot of ip to connect to the back-end server, probably because the early Chinese Internet instability, dns problems, etc., and there are a variety of restrictions, so the idea of using this method, but later became a network tracker to escape the method.

So I hope you can address this and develop new features to fill the gap.

What if I want to block all direct IP traffic to an app?

c2xusnpq6 commented 3 years ago

They claim to be a purely Singaporean company called FUNI. PTE. LTD., and it supports backup telegram data...

c2xusnpq6 commented 3 years ago

The above is a little messy, I will check it out later if I have time.

c2xusnpq6 commented 3 years ago

Screenshot

Screenshot

Alex-302 commented 3 years ago

Don't know what we can block.