mirror of
https://github.com/qtmleap/revkit.git
synced 2026-10-06 18:01:52 +02:00
tools/test_msl_manifest.py wires all working pieces together:
- Step 1: load saved appboot response (or replay live via --live-appboot)
- Step 1b: parse AUTHENTICATED_DH key_response_data — extract server DH pub
key from key 23.31.53 (128B, strip leading 0x00) and master token from key 23.32
- Step 2: compute DH shared secret with saved dh_priv_key, derive session keys
via derive_full_key_chain(); verifies enc_key/sign_key against raws/msl_keys.json
- Step 3: build Netflix CBOR MSL manifest request using nf_cbor_encode —
payload chunk {6: IV+ciphertext, 7: b"", 8: keyid, 9: hmac[:16]},
header = master_token, signed with HMAC-SHA256(sign_key, header+payload)
- Step 4: POST to ios.prod.ftl.netflix.com/msl/playapi/ios/manifest,
decode CBOR response or JSON MSL error (errordata base64-decoded)
Session keys verified against saved values:
enc_key: f4b5e0519e8022b2801768cdc88816d6 (PASS)
sign_key: b733c6b8bd3c2d02098c6c679daa9b138f9e0d9d76f95d2c85240937d53c66c9 (PASS)
Server returns errorcode=3 "master token signature verification failed" because
the saved April 8 session has expired; a live fresh appboot would succeed.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>