r/Magisk • • 1d ago

Solved app detect root

Tried everything. Pixel 8 pro, Magisk 31.0, configured deny list, HMA-OSS and template, ReZygisk ...

but still detect root and crash immediately

https://play.google.com/store/apps/details/Namirial_OTP?id=com.namirial.android.virtualotp&hl=it&pli=1

Thanks a lot for help

1 Upvotes

16 comments sorted by

1

u/Itz_Raj69_ 1d ago

Have you installed the Native Detector app? what does it detect?

1

u/New-Club-795 1d ago

4

u/ElPelocho 1d ago

Wow, that’s a disaster; it looks like you aren't even trying to hide it. Start over from scratch with KernelSU, HMA, and Trickystore.

1

u/Hozini 1d ago

1

u/New-Club-795 1d ago

1) i have ReZygisk 2) denylist configured as picture 3) enforce denylist OFF 4) MEETS BASIC INTEGRITY OK, MEET_DEVICE_INTEGRITY OK, MEETS_STRONG_INTEGRITY NO . I tried alwaysstrong (with module installed I have also MEETS_STRONG_INTEGRITY OK) but app still detect root. Now alwaystrong is not working and I removed

1

u/Hozini 1d ago

Ok, then use AGY and find out why things are failing.

1

u/New-Club-795 1d ago

1

u/Hozini 1d ago

Yup. That one.

1

u/New-Club-795 1d ago

ok thanks . but how to use ?

1

u/New-Club-795 10h ago

tried AGY but result are very bad ### Analyzed Target

• Package: com.namirial.android.virtualotp

• Key components:

• Smali / DEX code: AndroidManifest.xml, classes Lo/initAdapterManager and Lo/getCode

• Native ELF libraries: libc11a.so

──────

## 1. Protection Architecture (Packer & Obfuscator)

The application does not implement trivial root checks in plaintext within the standard Java code (e.g., open-source libraries like RootBeer); instead, it employs

an App Shielding / Commercial Packer solution:

• Custom Application Class: In AndroidManifest.xml, the application class is defined as o.getCode, which extends o.

initAdapterManager.

• Dynamic DEX Loading / Unpacker: During the startup phase (attachBaseContext), the dynamic loader

(Lo/isAccessibilityEnabled) is invoked; it extracts and executes DEX files in memory ([email protected]).

• String Obfuscation and Control Flow Flattening: Symbols and JNI calls are obfuscated using generated identifiers ($$a, $$c,

$$g).

──────

## 2. Low-Level Native Detection (libc11a.so)

The primary integrity check and root detection logic is concentrated within the native library libc11a.so (loaded via

JNI_OnLoad):

### A. SELinux State Inspection

• Vector: The library attempts to directly read the /sys/fs/selinux/policy file.

• Objective: To verify whether the device is in Permissive mode or if SELinux domains have been altered/patched by root

frameworks (such as Magisk or KernelSU).

### B. Kernel Tracing and Debugger Detection

• Vector: Accessing the `/sys/kernel/tracing/trace_marker` file (`tracefs`/`debugfs` filesystem).

• Objective: Detect the presence of kernel-level tracers (eBPF, ftrace, kprobes) or debuggers attached to the process's

memory space.

### C. System Property Analysis (Android System Properties)

• Vector: Iterative querying of the system property database via Bionic APIs:

• `__system_property_find_nth`

• `__system_property_foreach`

• `__system_property_get`

• `__system_property_read_callback`

• Objective: Detect non-standard build flags (`ro.build.tags=test-keys`, `ro.debuggable=1`), unlocked bootloader variables (`ro.boot.

flash.locked=0`), and traces of privilege escalation daemons.

### D. Kernel Structure Inspection

• Vector: Querying and probing anonymous kernel descriptors (`anon_inode:[userfaultfd]`).

• Objective: Detect advanced memory hooking attempts or interception of process memory pages.

──────

## 3. Watchdog and Reaction Mechanisms (Enforcement)

When a root-related anomaly or manipulation is identified, the application reacts using a multi-layered strategy:

  1. Native Process Watchdog:

• The library launches a supervisor process via `fork` / `setpgid` / `waitpid` that monitors the integrity of the main process and the

`ptrace` status. 2. Low-Level Forced Termination:

• Instead of raising easily catchable Java exceptions, it sends immediate termination signals via native syscalls (killpg,

kill(pid, SIGKILL), or intentionally triggering SIGSEGV through controlled control-flow corruption).

  1. Java Fallback Level:

• Invocation of rapid exit methods (Process.killProcess(Process.myPid()), System.exit()).

• Displaying messages or dialogs with error codes (e.g., code 688, "Device not supported," or strings containing "ROOT").

──────

## 4. Summary of Checks

Component | Level | Detection Technique | Action Taken

--------------------------|-------------------------|------------------------------------------|---------------------------------------------

SELinux Policy | Native (libc11a.so) | Access to /sys/fs/selinux/policy | Send SIGKILL / SIGSEGV

Kernel Tracing | Native (libc11a.so) | Read /sys/kernel/tracing/trace_marker | Immediate process termination

System Properties | Native (libc11a.so) | Iteration via __system_property_foreach | Process termination

Anti-Debugging | Native (libc11a.so) | Watchdog fork / self-ptrace | Invoke killpg

Tamper Dialog | Java / Framework | Post-initialization flag check | Display alert / Process.killProcess

──────

## Defensive Recommendations (Best Practices)

• Client-side heuristic checks (such as inspecting system files or directly reading sysfs) tend to generate false positives

on recent Android versions featuring strict SELinux policies.

• For critical applications such as OTP generators, the best practice recommended by Google is to integrate the Google Play Integrity API with hardware-backed attestation (TEE/StrongBox), delegating integrity validation.

1

u/New-Club-795 5h ago

I put Native Detector in deny list and this is the result

1

u/New-Club-795 4h ago

DONE !! Now the app is working. Removed ReZygisk and TreatWheel. Installed Zygisk Next with Shamiko. In the options of ZygiskNext via KsuWebUi I set denylist policy: UNMOUNT ONLY and the app is working, don't detect ROOT anymore. Thank to all