A project to repurpose the Ninebot app, turning the Ninebot into a companion for extended functionality without any scooter protocol reverse engineering.
Use of this project may affect your device or app in ways not intended by the original manufacturer. It is your responsibility to ensure that any modifications or usage comply with local laws and regulations. Always verify for yourself that your actions are legal in your country or region.
Compatible 6.9.1
Download here
- Ensure Docker is installed on your system.
- Open the project folder in Visual Studio Code
- Ensure the Dev Containers Extension is installed
- Run
Dev Containers: Rebuild and Reopen in Containerfrom the command palette - Copy the following files from your .xapk into the
assets/apksfolder:- com.ninebot.segway.apk
- config.arm64_v8a.apk
- config.en.apk
- config.xxhdpi.apk
- Copy libnbdrift.so into the assets folder.
- Run the patch script:
./patch.sh
- Ensure you have Command-line tools installed.
- Linux/MacOS users can simply execute the installation script.
./install.sh. - On your device, activate
Permissions > Allow management of all files
Notice, that these steps must be executed on the host system, not inside the dev container.
In your internal shared storage (commonly /storage/emulated/0), make a new folder named nbdrift. This is were it tries to find custom configuration files.
Update checks are always spoofed and cannot be disabled.
It is recommended to unbind the device in the original app. Then connect with permission spoofing and a fw update response spoof. Server the fw using a fake server.
This allow scooter connection without device binding. Control it using a flag in prm-spoof.txt: 0 Disabled, 1 Enabled.
- Using logcat:
adb logcat -s "nbdrift" - With cleaning:
clear && adb logcat -c && adb logcat -s "nbdrift"
Write a custom server payload into fw-iot.json. This is useful for injecting custom firmware into the Ninebot app or disabling forced updates.
Example response for no available udpate:
{"code":1,"data":{"parts_version":[],"show_kart_tip":false,"special_version_status":false,"forced_status":false,"forced_content":"","sub_wnumber":"","source":1},"desc":"Successfully"}
Write a custom serial number into sn-spoof.txt. This is useful when the scooter has been patched to ignore limits imposed by its serial number. However, without this patch, it might still not show you the newly available options.
- Injection lib: https://github.com/trueToastedCode/nbdrift
- Fake server: https://github.com/trueToastedCode/nbdrift-osrc/tree/fake-server
- Payload generator: https://github.com/trueToastedCode/nbdrift-osrc/tree/make-payload