Generate and obtain a avlid authentication beaerer token from google play to be used in curl call to fetch data about top 600 grossing games, has to be for the games ranked 201-600 since top 200 is already available in chrome.
Budget: $250 – $750 USD
Generate and obtain a avlid authentication beaerer token from google play to be used in curl call to fetch data about top 600 grossing games, has to be for the games ranked 201-600 since top 200 is already available in chrome.
The task contains the following:
1. Generate and obtain a valid authentication beaerer token from google play to be used in curl call to fetch data about top 600 grossing games.
2. Generate a valid curl (or httpie) query to google play top grossing charts to fetch top600 grossing games, has to be in for games ranked from 201-600 since top 200 is already available in chrome.
3. Explain the query parameter "entp".
4. Decode the google protobuf response and define the protobuf rules used.
Suggested tool to use is for example "fiddler" and use the attached sniffed traffic towards google play top 600 grossing games.
Alternatively, sniff your own google play traffic from top 600 grossing.
Top 200 grossing is available at google play from a browser:
https://play.google.com/store/apps/collection/cluster?clp=0g4YChYKEHRvcGdyb3NzaW5nX0dBTUUQBxgD:S:ANO1ljLhYwQ&gsr=ChvSDhgKFgoQdG9wZ3Jvc3NpbmdfR0FNRRAHGAM%3D:S:ANO1ljIKta8&hl=en_US&gl=US
However, for this task we want all the games after top 200, i.e. games ranked 200-600.
Sniffed traffic between an android emulator (nox), fiddler and google play will be provided and also screenshots with some more details.
As a complement to the provided sniffed traffic you can set up your own sniffing environment using nox android emulator (or memu, genymotion) and fiddler (or mitmproxy, charles proxy or other).
Postman might also be good to use to complete this project.
Delivery:
Provide a how with text and screenshots how to reproduce the above 4 steps, and also a screenrecording where the above is show how it is done.
The task contains the following:
1. Generate and obtain a valid authentication beaerer token from google play to be used in curl call to fetch data about top 600 grossing games.
2. Generate a valid curl (or httpie) query to google play top grossing charts to fetch top600 grossing games, has to be in for games ranked from 201-600 since top 200 is already available in chrome.
3. Explain the query parameter "entp".
4. Decode the google protobuf response and define the protobuf rules used.
Suggested tool to use is for example "fiddler" and use the attached sniffed traffic towards google play top 600 grossing games.
Alternatively, sniff your own google play traffic from top 600 grossing.
Top 200 grossing is available at google play from a browser:
https://play.google.com/store/apps/collection/cluster?clp=0g4YChYKEHRvcGdyb3NzaW5nX0dBTUUQBxgD:S:ANO1ljLhYwQ&gsr=ChvSDhgKFgoQdG9wZ3Jvc3NpbmdfR0FNRRAHGAM%3D:S:ANO1ljIKta8&hl=en_US&gl=US
However, for this task we want all the games after top 200, i.e. games ranked 200-600.
Sniffed traffic between an android emulator (nox), fiddler and google play will be provided and also screenshots with some more details.
As a complement to the provided sniffed traffic you can set up your own sniffing environment using nox android emulator (or memu, genymotion) and fiddler (or mitmproxy, charles proxy or other).
Postman might also be good to use to complete this project.
Delivery:
Provide a how with text and screenshots how to reproduce the above 4 steps, and also a screenrecording where the above is show how it is done.
Related categories:
Web Security
Internet Security
cURL
Certified Ethical Hacking
Reverse Engineering