让 iChat 音视频会议功能重获新生
Resurrecting iChat Audio and Video Conferencing

原始链接: https://blog.pipetogrep.org/2026/09/11/resurrecting-ichat-audio-and-video-conferencing/

本文介绍了如何在 Mac OS X Leopard 或 Snow Leopard 上恢复 iChat AV 的音视频通话功能。iChat 最初依赖 Apple 已停用的 SNATMAP 服务来发现用户的公网 IP 地址和 UDP 端口,以建立点对点 RTP 通话。如今,其 HTTP 配置请求会重定向到 HTTPS,而操作系统过时的 TLS 协议栈无法处理这种重定向,导致通话双方只能交换无法使用的局域网私有地址。 作者通过数据包捕获和借助大语言模型进行的逆向工程,重新实现了 SNATMAP 协议,并将其构建为一个简单的 Python UDP 服务器。16 字节的请求包含类型、随机数、本地 IP 和本地端口;响应则返回随机数,以及服务器观察到的公网 IP 和端口。 作者在实验室中使用两台虚拟 OpenWrt 路由器和两台 Mac 进行测试,随后将该服务部署到公网,并通过 `/etc/hosts` 将 `configuration.apple.com` 映射到该服务的 IP 地址。完成用户配置并启用 NAT 源端口保留后,旧版 iChat 再次可以通过互联网正常通话,并且也能使用现代的 Logitech C920 网络摄像头。

``` 黑客新闻 最新 | 往期 | 评论 | 提问 | 展示 | 工作 | 提交 登录 重现 iChat 音视频会议功能 ( pipetogrep.org ) 4 分 由 thepipetogrep 发布 55 分钟前 | 隐藏 | 往期 | 收藏 | 1 条评论 帮助 jadar 46 分钟前 [–] 太棒了!我记得小时候曾试图弄清楚这是如何工作的,但始终没有理清。今天,我的梦想实现了。;) 回复 考虑申请 YC 2027 年冬季批次! 申请 截至 11 月 2 日开放。 指南 | 常见问题 | 列表 | API | 安全 | 法律 | 申请加入 YC | 联系我们 搜索: ```
相关文章

原文

Published on: by Chris Jones

Updated on: • 7 min read

Add this to your /etc/hosts file on your old Mac running Leopard or Show Leopard (has not been tested on Tiger or Panther), and iChat should be able to make audio and video calls again. This assumes your router does port-preserving NAT (most do).

157.230.2.213 configuration.apple.com

Do note that if you are on a BSD based router like pfSense or OPNsense, you will need to enable source port preservation in your outbound NAT settings.

I used to be the most annoying kind of Apple zealot. In the early 2000s, I thought everything Apple had was better than anything else out there whether it was true or not. There was one place that it was true, however, and that was in the realm of video and audio conferencing in the early 2000s.

The big players for consumer level video conferencing at the time were Microsoft with MSN Messenger, Yahoo! with Yahoo! Messenger, and AOL with AOL Instant Messenger (AIM). Then at Apple's World Wide Developer Conference (WWDC) in June of 2003, along with the G5 processor and OS X 10.3 panther, Apple announced "iChat AV".

iChat AV Marketing Screenshot

They also announced this gorgeous over-engineered webcam to go along with it called the "iSight".

Original iSight Webcam

I actually had a G4 laptop and an iSight. It felt like living in the future and I loved it. This post is about how I got iChat's video conferencing on early OS X working over the Internet again to relive some of that fun.

In early 2023, my friend (will be referred to as "Methodius") and I decided to just try it and see what would happen. We tried to test a simple iChat audio call on OS X Leopard. That version of iChat works with XMPP (Jabber) servers, so we each set it up with an account on jabb.im, and pressed the green call button. It rang for the other party, it said it was trying to connect, and then...failed to connect.

It's never that easy.

Time to do some traffic inspection with tcpdump. Thankfully, that comes pre-installed on OS X from back then so I didn't have to install anything extra. Along with the packet inspection, I also ran iChat in debug mode by launching it in the terminal like this:

/Applications/iChat.app/contents/MacOS/iChat -errorLogLevel 7

iChat's debug mode was very helpful and barely documented anywhere, so now it lives here if I ever need to look it up again.

  1. iChat makes an http request to http://configuration.apple.com/configurations/macosx/ichat/1/snatmap.txt to get the address of an SNATMAP server.
  2. iChat makes a UDP request to that SNATMAP server to get its own public IP address.
  3. iChat on both ends then exchanges their public IPs and ports via their text communication channel (XMPP in our case).
  4. iChat on both ends then attempts to set up a peer-to-peer RTP connection by blasting packets to each over over the public IPs and ports previously discovered via the SNATMAP server. Since NAT connections are stateful, and outbound NAT connections open an inbound connection to the machine making the request, iChat behind NAT routers are able to connect with each other without the need to set up NAT port forwarding ahead of time.
  1. iChat attempted to make an http request to http://configuration.apple.com/configurations/macosx/ichat/1/snatmap.txt but got redirected to https which it could not connect to because OS X's TLS suite is too old.
  2. iChat failed to complete that request, so instead of exchanging our public IPs, they exchanged private LAN IPs instead, which obviously failed to connect over NAT.

The https URL is still up at the time of writing this, however, and actually contains something!

snatmap://snatmap.apple.com:5678

OK, NP. I set up my own simple web server, hosted that file myself, update OS X's /etc/hosts file to point configuration.apple.com to an IP of my choosing. Ran it and...still nothing.

Apple's SNATMAP server doesn't respond anymore. At this point, we were at a dead end because we had no idea how this SNATMAP server worked or how iChat expects to communicate with it. We learned a lot but ended in failure.

Methodius and I decide to try again in summer 2026, but this time with a little LLM assistance. With our prior network captures, we were able to use an LLM to reverse engineer iChat's video conferencing framework and figure out what the request to the SNATMAP server looks like and what iChat expects as a response. From that, we were able to generate a specification file of the SNATMAP protocol.

Even though I didn't have the know how to decompile iChat, read the assembly code, and them make sense of it, I can at least learn how to write a simple UDP server from the spec file the LLM generated.

I'm a systems engineer and admin by trade. I install and configure servers, but I've never written a server of my own before. Turns out, this SNATMAP server made for a great first server to practice with.

The protocol:

  1. Communicates over UDP on port 5678
  2. The request packet contains four fields in 16 bytes.
    1. Type ("1" for request)
    2. Nonce (random number used to match a request with a response)
    3. client local IP (unused)
    4. client local port (unused)
  3. The response packet contains four fields in 16 bytes
    1. Type ("2" for response)
    2. Nonce (the same random number from the request)
    3. External IP from the UDP request
    4. The external port from the UDP request

Links for the spec file and source code to the SNATMAP server are at the end of this post

Since Methodius has kids and, as a result, has much less free time than I do, I needed a way to test how iChat works across the Internet by myself. Since I don't have two separate ISP connections to play with, I decided to build an "Internet" in a lab. This was achieved by running two NAT routers (OpenWrt) as virtual machines running on a KVM host (Proxmox) that traversed a flat network space acting as the "Internet". Then I physically hooked two Macs up to the physical KVM host (via USB NICs) where the VM routers assigned them IP addresses in their own private LAN behind a NAT. Then on the "Internet" network, I had the Jabber (ejabberd), web (lighttpd), and SNATMAP servers running in a Debian Linux VM.

Here it is diagrammed with pictures of the physical setup with the Proxmox Server (the Thinkpad laptop) and the two Macs hooked up to it. iChat Diagram iChat Lab 1 iChat Lab 2 iChat Lab 3 iChat Lab 4

With this, I was able to test and iterate quickly.

The spec file can be used to create your own version of the server if you so desire. The source code was hand written in Python from the spec file and is ready to run on just about any OS that can run Python 3.

If you wish to self host, be sure you have a web server configured to answer requests to configuration.apple.com and have it serve snatmap.txt from the path

/configurations/macosx/ichat/1/snatmap.txt

In snatmap.txt make it contain

snatmap://YOUR_SERVER_IP:5678

replacing YOUR_SERVER_IP with the public IP address of the server the SNATMAP server is running on.

Or you can just use my server! I keeping it running for the 1-5 people left in the world that want to video chat using the ancient software. :D

On your old mac running OS X Leopard or Snow Leopard (might work on older but not tested), just enter this into your /etc/hosts file.

157.230.2.213 configuration.apple.com

Then have the friend you want to call do the same. After that, mash that green call button!

It's true! You can even use a fairly modern Logitech webcam. I tested on OS X Leopard with a Logitech C920.

Here is a screenshot of Methodius and I chatting over the real Internet with iChat AV. iChat AV Screenshot Real

Enjoy and happy chatting!

联系我们 contact @ memedata.com