← 资料库索引 ← 开源项目 原始链接 ↗ 🔍
开源项目

PDD-Algorithm:拼多多 Android 客户端加密算法纯 Python 还原(GitHub 仓库) 原文标题:GitHub - mankezhou/Pdd-anti-token: pdd-anti-token 还原

发表时间:2026-04-26采集时间:2026-10-09 14:49:05来源:github.com原文语言:zh状态:完整

内容概要总结

GitHub 开源项目 mankezhou/Pdd-anti-token 的仓库页。项目用纯 Python 还原了拼多多 Android 客户端位于 libpdd_secure.so 的核心加密逻辑,可脱离 App 直接调用拼多多 API。已还原 3 种签名算法:anti-token 短签名(info4,2ag 前缀,用于普通 API 请求如瀑布流)、anti-token 长签名(info2,2af 前缀,用于搜图/埋点等高安全接口)、埋点加密(ng,RSA 信封加密)。README 给出短签名明文结构(版本标志 2B + android_id 8B + padding 2B + timestamp 6B + uuid 8B + checksum 4B + etag 8B,再经 AES-128-CBC、key=pdd_aes_180121_1、iv=0、PKCS7 加密)、长签名结构(AES-128-CBC 包裹 GZIP 压缩的 TLV 共 33 个设备字段)及请求链路(t.gif 前置埋点 → 业务 API → te.gif 后置埋点)。项目通过 ADB 采集真机设备指纹,提供瀑布流与拍照识图示例,License 为 MIT,声明仅用于安全研究。

原文内容(原文即中文)

⚠ 说明:GitHub 仓库页,content_zh 为 README 全文翻译(原文为中文)。

You signed in with another tab or window. Reload to refresh your session.
You signed out in another tab or window. Reload to refresh your session.
You switched accounts on another tab or window. Reload to refresh your session.
Dismiss alert

Latest commit

History

Folders and files

NameName

Repository files navigation

PDD-Algorithm

拼多多 Android 客户端加密算法的纯 Python 实现,可脱离 APP 直接调用拼多多 API。

已还原的加密算法

核心加密逻辑位于 libpdd_secure.so,本项目完整还原了以下 3 种签名算法:

算法标识用途
anti-token 短签名 (info4)2ag 前缀普通 API 请求 (如瀑布流)
anti-token 长签名 (info2)2af 前缀搜图/埋点等高安全接口
埋点加密 (ng)RSA 信封加密埋点请求 body

短签名 (info4)

"2ag" + Base64(AES-128-CBC(key="pdd_aes_180121_1", iv=0, PKCS7(38字节明文)))
明文 = 版本标志(2B) + android_id(8B) + padding(2B) + timestamp(6B) + uuid(8B) + checksum(4B) + etag(8B)

长签名 (info2)

"2af" + Base64(AES-128-CBC(key="pdd_aes_180121_1", iv=0, PKCS7(GZIP(TLV(33个设备字段)))))

埋点加密 (ng)

random_key = os.urandom(32)
{"key": Base64(RSA-1024(public_key, random_key)), "data": Base64(AES-256-CBC(random_key, iv=0, json))}

请求链路

POST t.gif (前置埋点, info2 + ng body)
 -> GET/POST api (业务请求, info4/info2)
 -> POST te.gif (后置埋点, info4 + ng body)

目录结构

.
├── [algo](https://github.com/mankezhou/Pdd-anti-token/tree/main/algo)/ # 加密算法
│ ├── anti_token.py # 签名生成 (info4 + info2 + ng)
│ ├── device_loader.py # 设备信息加载
│ ├── pdd_guest.py # 游客态瀑布流
│ ├── pdd_search_img.py # 拍照识图 (登录态)
│ ├── pdd_login.py # 手机号登录完整流程
│ ├── pdd_goods_detail.py # 商品详情接口
│ └── device_info.example.json # 设备信息模板
├── [tools](https://github.com/mankezhou/Pdd-anti-token/tree/main/tools)/
│ └── collect_device_info.py # ADB 一键采集真机设备信息
├── [examples](https://github.com/mankezhou/Pdd-anti-token/tree/main/examples)/
│ ├── demo_waterfall.py # 瀑布流 Demo (游客, 无需登录)
│ └── demo_search_img.py # 拍照识图 Demo (需登录)
└── [docs](https://github.com/mankezhou/Pdd-anti-token/tree/main/docs)/
 └── 拼多多加密算法分析.md # 算法逆向完整分析

快速开始

1. 安装依赖

pip install -r [requirements.txt](https://github.com/mankezhou/Pdd-anti-token/blob/main/requirements.txt)

2. 采集设备信息

通过 ADB 从真机采集设备指纹,保存到 algo/device_info.json:

python tools/collect_device_info.py

也可手动复制 algo/device_info.example.json 为 algo/device_info.json 并填入真实设备信息。

3. 瀑布流 (游客态, 无需登录)

python examples/demo_waterfall.py
PDD Waterfall Demo (Guest Mode)
Device: b17104fc6f8baeda
HTTP 200
Items: 20
 1. [437028372588] Y29.90 - 纯棉短袖t恤男夏季新款潮流...
 2. [421893710456] Y15.80 - 一次性洗脸巾女纯棉加厚...

4. 拍照识图 (需登录)

需要先在 algo/device_info.json 中配置 pdd_access_token:

python examples/demo_search_img.py product.jpg

免责声明

本项目仅用于安全研究和学习目的。使用者应遵守相关法律法规,不得将本项目用于非法用途。作者不对使用本项目造成的任何后果承担责任。

交流群

img.png
img.png

License

About

Resources

Stars

Watchers

Forks

Releases

Packages

Contributors

Languages

You can’t perform that action at this time.

放大预览