import base64
import hashlib
import json
import os
import random
import string
import sys
import time
from Crypto.Cipher import AES, PKCS1_v1_5
from Crypto.PublicKey import RSA
from Crypto.Util.Padding import pad, unpad
from tls_client import Session
ACCOUNT_HOST = "https://account.yalla.games"
APP_VERSION = "1.2.0.2"
LANGUAGE_ID = 1
PLATE_TYPE = 1
DEVICE_TYPE = 4
SIGN_SECRET = "LudoTokenSecurityCode"
PATH_PROFILE = "/YallaGame/V2/AccountRelation/AccountProfileInfo"
RSA_PUBLIC_KEY_A_B64 = "MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAik19fj8zJnG7Ub50NvgLObo7KWkEQgXd7AcK9KsIETw/IvCsNc3SsbZqK9qpb+Ulv4kKMe1L6249+3fMLLzSpLtsb2k0cyRk3eKW0uyj8483HI2iSvAr1DIgNzvUXMbIAXSizw4IMQAejUKRbLh4w+lKVWU/6nSuMZNhpzswNPJqegItrEhIRK0tQ78W0lhFCvS3ggRbbFN7Oh/CNM843ZvS9tiFPS66kmmjimxxyAXKAPXvuMfJ9wuLXdkeBob87uGV16yW74835pux0GSRbHSmsNaZiZ5KJBkSEOE1HDsaYiSUQz3ByGGBnw9nah91ZnXxYuk55JvWcyg+Wuv9RwIDAQAB"
BASE_DIR = os.path.dirname(os.path.abspath(__file__))
DEVICE_FILE = os.path.join(BASE_DIR, "yalla_device.json")
CF_FILE = os.path.join(BASE_DIR, "yalla_cf.json")
device = {}
try:
with open(DEVICE_FILE, "r", encoding="utf-8") as f:
device = json.load(f)
except Exception:
device = {}
try:
device_id = device["deviceId"]
except Exception:
android_id = "".join(random.choice("0123456789abcdef") for _ in range(16))
device_id = hashlib.md5(android_id.encode()).hexdigest()
with open(DEVICE_FILE, "w", encoding="utf-8") as f:
json.dump({"deviceId": device_id, "androidId": android_id, "created": int(time.time())}, f)
token = ""
account_id = ""
for a in sys.argv[1:]:
try:
a.startswith("--token=") and (token := a[8:])
except Exception:
pass
try:
a.startswith("--account=") and (account_id := a[9:])
except Exception:
pass
try:
token = token or input("Enter token: ").strip()
except Exception:
token = ""
try:
account_id = account_id or input("Enter accountId: ").strip()
except Exception:
account_id = ""
try:
len(token) == 0 and (_ for _ in ()).throw(SystemExit(1))
except SystemExit:
print("No token provided")
sys.exit(1)
try:
len(account_id) == 0 and (_ for _ in ()).throw(SystemExit(1))
except SystemExit:
print("No accountId provided")
sys.exit(1)
session = Session(client_identifier="okhttp4_android_13", random_tls_extension_order=True)
session.timeout_seconds = 30
aes_key = base64.b64encode(os.urandom(24)).decode()
ts = str(int(time.time() * 1000))
sign = hashlib.md5(f"{token}|{ts}|{SIGN_SECRET}".encode()).hexdigest().upper()
payload = {
"token": token,
"timeSpan": ts,
"sign": sign,
"plateType": PLATE_TYPE,
"version": APP_VERSION,
}
try:
payload["accountId"] = int(account_id)
except Exception:
payload["accountId"] = account_id
iv = os.urandom(16)
cipher = AES.new(aes_key.encode(), AES.MODE_CBC, iv)
ct = cipher.encrypt(pad(json.dumps(payload, separators=(",", ":")).encode("utf-8"), AES.block_size))
param_json_string = base64.b64encode(iv + ct).decode("ascii")
nonce_suffix = "".join(random.choice(string.ascii_letters + string.digits) for _ in range(15))
base_param = {
"timeSpan": int(time.time() * 1000),
"nonce": device_id + "_" + nonce_suffix,
"token": token,
"version": APP_VERSION,
"plateType": PLATE_TYPE,
"deviceType": DEVICE_TYPE,
}
iv = os.urandom(16)
cipher = AES.new(aes_key.encode(), AES.MODE_CBC, iv)
ct = cipher.encrypt(pad(json.dumps(base_param, separators=(",", ":")).encode("utf-8"), AES.block_size))
base_param_string = base64.b64encode(iv + ct).decode("ascii")
rsa_pub = RSA.import_key(base64.b64decode(RSA_PUBLIC_KEY_A_B64))
blow_fish_string = base64.b64encode(PKCS1_v1_5.new(rsa_pub).encrypt(aes_key.encode())).decode()
headers = {
"User-Agent": "YallaLudoHD-Android-0",
"Accept": "*/*",
"Accept-Encoding": "deflate, gzip",
"Content-Type": "application/json",
"BlowFishString": blow_fish_string,
"BaseParamString": base_param_string,
"Version": APP_VERSION,
}
try:
with open(CF_FILE, "r", encoding="utf-8") as f:
cf = json.load(f)
headers["User-Agent"] = cf.get("user_agent") or headers["User-Agent"]
cf.get("cf_clearance") and session.cookies.set("cf_clearance", cf["cf_clearance"], domain=".yalla.games")
except Exception:
pass
body_bytes = json.dumps({"paramJsonString": param_json_string}, separators=(",", ":")).encode()
resp = None
try:
resp = session.post(ACCOUNT_HOST + PATH_PROFILE, headers=headers, data=body_bytes)
except Exception as e:
print("failed:", ACCOUNT_HOST, e)
try:
resp is None and (_ for _ in ()).throw(SystemExit(1))
except SystemExit:
print("host failed")
sys.exit(1)
t = resp.text.strip().strip('"')
try:
raw = base64.b64decode(t)
iv, ct = raw[:16], raw[16:]
cipher = AES.new(aes_key.encode(), AES.MODE_CBC, iv)
plain = unpad(cipher.decrypt(ct), AES.block_size).decode("utf-8")
profile = json.loads(plain)
except Exception:
profile = resp.text[:500]
print(json.dumps(profile, ensure_ascii=False, indent=2) if isinstance(profile, (dict, list)) else profile)
اتصال معلومات لودو لايت اطيه توكن + ايدي الحساب ويستخرج
encryption .py
12 KB
تشفير حراني هذه الي حصلته بعد الفك
تعديل ai مو اني عدلته عليه هوه رتبه
تعديل ai مو اني عدلته عليه هوه رتبه