YourVPNDead — Android VPN Detection & SOCKS5 Vulnerability Scanner
Skill by ara.so — Daily 2026 Skills collection.
Android app (Kotlin + Jetpack Compose) demonstrating that any app — without root or special permissions — can detect VPN usage, identify the VPN client, and retrieve the VPN server's exit IP through unauthenticated SOCKS5 proxies exposed on localhost by popular VPN clients (v2rayNG, NekoBox, Hiddify, etc.).
Build & Install
Or download the pre-built APK from Releases.
Required permissions (AndroidManifest.xml):
Architecture
Stack: Kotlin, Jetpack Compose, Material 3, Coroutines, MVVM (ViewModel + StateFlow)
Key Detection Modules
1. Direct VPN Signs — DirectSignsChecker.kt
Detects VPN via standard (and hidden) Android APIs:
2. VPN Interface Detection
3. /proc/net/tcp Scanner — ProcNetScanner.kt
Reads listening ports without root:
4. Port Scanner — PortScanner.kt
TCP connect scan on 127.0.0.1 and ::1:
5. SOCKS5 Probe — Socks5Probe.kt
Identify proxy type and check for authentication:
6. Exit IP Resolution via SOCKS5 — ExitIPResolver.kt
Get VPN server's real IP through unauthenticated SOCKS5:
7. Clash REST API Probe — ClashAPIProbe.kt
sing-box/mihomo expose Clash API on localhost without auth by default:
8. VPN App Detection — DirectSignsChecker.kt
Enumerate installed VPN apps (requires QUERY_ALL_PACKAGES on Android 11+):
9. Routing Table Check
MVVM Pattern — ViewModel + StateFlow
Composable UI Pattern
Vulnerable Client Reference
Known Port Constants
Troubleshooting
/proc/net/tcp returns empty or permission denied
- Restricted on Android 10+ for non-root apps on some ROMs (Samsung Knox, MIUI)
- Fallback: use TCP connect scan via
PortScannerinstead
Port scan misses ports
- Increase
timeoutfrom 300ms to 500ms for slower devices - Reduce
parallelismto 16 if getting connection reset errors
QUERY_ALL_PACKAGES denied
- Required for VPN app enumeration on Android 11+
- Must be declared in manifest; some app stores may restrict it
- Fallback: check only packages via
Intentresolution
SOCKS5 probe connects but returns unexpected bytes
- Some clients send HTTP 400 response instead of SOCKS5 rejection
- Add HTTP CONNECT fallback probe after SOCKS5 attempt
Exit IP resolution returns null despite open SOCKS5
- Target
api.ipify.orgmay be blocked by the VPN itself - Try alternative:
ifconfig.me,checkip.amazonaws.com - Some clients block loopback-originated connections to external hosts
Clash API returns 401
- Client has set
secretin config — not the default behavior but possible - Check port 19090 (sing-box uses different default than mihomo's 9090)


