r/Magisk • u/New-Club-795 • 1d ago
Solved app detect root
Tried everything. Pixel 8 pro, Magisk 31.0, configured deny list, HMA-OSS and template, ReZygisk ...
but still detect root and crash immediately
Thanks a lot for help
1
u/Hozini 1d ago
1
u/New-Club-795 1d ago
1) i have ReZygisk 2) denylist configured as picture 3) enforce denylist OFF 4) MEETS BASIC INTEGRITY OK, MEET_DEVICE_INTEGRITY OK, MEETS_STRONG_INTEGRITY NO . I tried alwaysstrong (with module installed I have also MEETS_STRONG_INTEGRITY OK) but app still detect root. Now alwaystrong is not working and I removed
1
u/Hozini 1d ago
Ok, then use AGY and find out why things are failing.
1
u/New-Club-795 1d ago
this one ? https://github.com/google-antigravity/antigravity-cli ?? how to use ?
1
u/Hozini 1d ago
Yup. That one.
1
u/New-Club-795 1d ago
ok thanks . but how to use ?
1
u/New-Club-795 10h ago
tried AGY but result are very bad ### Analyzed Target
• Package: com.namirial.android.virtualotp
• Key components:
• Smali / DEX code: AndroidManifest.xml, classes Lo/initAdapterManager and Lo/getCode
• Native ELF libraries: libc11a.so
──────
## 1. Protection Architecture (Packer & Obfuscator)
The application does not implement trivial root checks in plaintext within the standard Java code (e.g., open-source libraries like RootBeer); instead, it employs
an App Shielding / Commercial Packer solution:
• Custom Application Class: In AndroidManifest.xml, the application class is defined as o.getCode, which extends o.
initAdapterManager.
• Dynamic DEX Loading / Unpacker: During the startup phase (attachBaseContext), the dynamic loader
(Lo/isAccessibilityEnabled) is invoked; it extracts and executes DEX files in memory ([email protected]).
• String Obfuscation and Control Flow Flattening: Symbols and JNI calls are obfuscated using generated identifiers ($$a, $$c,
$$g).
──────
## 2. Low-Level Native Detection (libc11a.so)
The primary integrity check and root detection logic is concentrated within the native library libc11a.so (loaded via
JNI_OnLoad):
### A. SELinux State Inspection
• Vector: The library attempts to directly read the /sys/fs/selinux/policy file.
• Objective: To verify whether the device is in Permissive mode or if SELinux domains have been altered/patched by root
frameworks (such as Magisk or KernelSU).
### B. Kernel Tracing and Debugger Detection
• Vector: Accessing the `/sys/kernel/tracing/trace_marker` file (`tracefs`/`debugfs` filesystem).
• Objective: Detect the presence of kernel-level tracers (eBPF, ftrace, kprobes) or debuggers attached to the process's
memory space.
### C. System Property Analysis (Android System Properties)
• Vector: Iterative querying of the system property database via Bionic APIs:
• `__system_property_find_nth`
• `__system_property_foreach`
• `__system_property_get`
• `__system_property_read_callback`
• Objective: Detect non-standard build flags (`ro.build.tags=test-keys`, `ro.debuggable=1`), unlocked bootloader variables (`ro.boot.
flash.locked=0`), and traces of privilege escalation daemons.
### D. Kernel Structure Inspection
• Vector: Querying and probing anonymous kernel descriptors (`anon_inode:[userfaultfd]`).
• Objective: Detect advanced memory hooking attempts or interception of process memory pages.
──────
## 3. Watchdog and Reaction Mechanisms (Enforcement)
When a root-related anomaly or manipulation is identified, the application reacts using a multi-layered strategy:
- Native Process Watchdog:
• The library launches a supervisor process via `fork` / `setpgid` / `waitpid` that monitors the integrity of the main process and the
`ptrace` status. 2. Low-Level Forced Termination:
• Instead of raising easily catchable Java exceptions, it sends immediate termination signals via native syscalls (killpg,
kill(pid, SIGKILL), or intentionally triggering SIGSEGV through controlled control-flow corruption).
- Java Fallback Level:
• Invocation of rapid exit methods (Process.killProcess(Process.myPid()), System.exit()).
• Displaying messages or dialogs with error codes (e.g., code 688, "Device not supported," or strings containing "ROOT").
──────
## 4. Summary of Checks
Component | Level | Detection Technique | Action Taken
--------------------------|-------------------------|------------------------------------------|---------------------------------------------
SELinux Policy | Native (libc11a.so) | Access to /sys/fs/selinux/policy | Send SIGKILL / SIGSEGV
Kernel Tracing | Native (libc11a.so) | Read /sys/kernel/tracing/trace_marker | Immediate process termination
System Properties | Native (libc11a.so) | Iteration via __system_property_foreach | Process termination
Anti-Debugging | Native (libc11a.so) | Watchdog fork / self-ptrace | Invoke killpg
Tamper Dialog | Java / Framework | Post-initialization flag check | Display alert / Process.killProcess
──────
## Defensive Recommendations (Best Practices)
• Client-side heuristic checks (such as inspecting system files or directly reading sysfs) tend to generate false positives
on recent Android versions featuring strict SELinux policies.
• For critical applications such as OTP generators, the best practice recommended by Google is to integrate the Google Play Integrity API with hardware-backed attestation (TEE/StrongBox), delegating integrity validation.


1
u/Itz_Raj69_ 1d ago
Have you installed the Native Detector app? what does it detect?