9 ms·
Reverse Engineering Native Apps by Intercepting Network Traffic
- coin 10y agoIsn't it possible for apps for ignore the OS's proxy settings and make a direct TCP connection? In that case the proxy man-in-the-middle trick won't work.
- pki 10y agoAt least on Android you can generate a fake VPN-esque connection locally that passes everything through a proxy, so the proxy isn't exposed to the application
- MichaelGG 10y agoSure but then the verification will fail since you won't be able to sign the handshake with the "pin'd" cert. (Assuming they implement TLS or other crypto in their own code.) If you aren't modifying the execution environment then it's possible for an app to be "safe".
- deleted 10y ago[deleted]
- BoringCode 10y agoIn that case I would look into ARP poisoning.
- sjtgraham 10y agoYes. Socket programming. A number of banking apps in the UK use the connect(2) etc, although I can't say if this is the reason. It's most likely to make it a touch more difficult to reverse than hooking NSURLConnection etc.
- deleted 10y ago[deleted]
- bruno222 10y agoThere is also a way, on rooted Androids, to sniff SSL pinned Apps. SSL pinned is not an protection for reverse engineering anymore, you may want to add this info on your post. More info at https://github.com/ac-pm/SSLUnpinning_Xposed https://github.com/ac-pm/SSLUnpinning_Xposed
- bruno2223 10y agoThere is also a way, on rooted Androids, to sniff SSL pinned Apps. SSL pinned is not an protection for reverse engineering anymore, you may want to add this info on your post. More info at https://github.com/ac-pm/SSLUnpinning_Xposed https://github.com/ac-pm/SSLUnpinning_Xposed
- Mizza 10y agoI had to do this recently and found a great tool for Android for sniffing traffic on the device called Packet Capture. It can even sniff SSL without root permissions by installing a self-signed certificate and running an in-app local VPN proxy. It also had a bunch of other nice features like parsing common protocols, showing the good bits of HTTP, etc. Much nicer than the approach described here (this article is from 2013), although it's certainly only for Android folk. I don't think it's FOSS, but hopefully a FOSS alternative will come along and use this approach.
- TeMPOraL 10y agoI've been using Packet Capture to get some data I wanted out of an app recently and in the process I started generally snooping around. What I saw disgusts me. First, just how much waste there is in communication - so many requests with so much JSON traffic for no real reason (except maybe laziness). Second - just how much various apps report on you. I've seen everything I could possibly imagine the phone could know about me and my operator sent to the various "motherships", sans actually transcribing my contact lists and messages. I'm not even going to ask what they do with this data. I recommend the experience highly. Just be warned, you may not like what you see.
- nitrogen 10y agoUsually it's just usage analytics, but the potential for abuse is great because individual data is still sent.
- dirkdk 10y agothis doesn't work anymore on iOS apps that use ATS. ATS is enabled by default and will be required by Apple by the end of 2016
- abalone 10y agoSounds like Charles can work with ATS, just not pinned certs.[1] [1] https://www.charlesproxy.com/documentation/faqs/ssl-proxying-with-ios-9/ https://www.charlesproxy.com/documentation/faqs/ssl-proxying...
- shawkinaw 10y agoWow, this guy has the completely opposite attitude of me. He seems to think it's a bad thing, an attack!, for users to see just what the hell data you're pulling off someone's phone. And, bizarrely, uses an example of an app that essentially stole data from its users. I should be able to see what data an app is sending, and certificate pinning (and ATS according to another comment) kills that. That's not a good thing.
- xuki 10y agoI agree. Cert pinning is fine but there should be an option to disable it (maybe system-wide) for people who want to analyze traffic.
- pilif 10y agodisabling system-wide is pretty much impossible. If OSes added such a toggle, people would start using their own SSL stack and overall security would suffer (because people won't be keeping their SSL stacks up to date)
- sjtgraham 10y agoThis is already a reality. There are at least 5 banking apps I can think of that statically link OpenSSL and use that instead of OS crypto.
- mkagenius 10y agoThat would pretty much beat the purpose, the author of the app doesn't anyone to snoop.
- ec109685 10y agoThis article is from 2013. The ssl vulnerability mentioned is no longer present: https://www.charlesproxy.com/documentation/using-charles/ssl-certificates/ https://www.charlesproxy.com/documentation/using-charles/ssl...
- isuckatcoding 10y agoWhat are some other ways to prevent people from discovering your API endpoints? One terrible idea I just had was creating only one publicly accessible API and then encrypting the actual endpoint in the payload which the server would decrypt and then redirect.
- ju-st 10y ago- encrypt everything using AES and pray that nobody will find the key in the apk - use your own crooked Http implementation that violates the official specs (e.g. missing \r\n's or introducing random whitespace characters...). Simple http parsing tools won't work anymore and the attacker will get grey hairs when he tries to test/use your endpoints
- danielrhodes 10y agoJust a heads up that changing the HTTP protocol can break a load balancer. Experienced this one time while using Amazon's ELB: the response had invalid HTTP and the ELB instances would silently lock up and stop responding, eventually draining the pool. Was not fun to debug.
- sjtgraham 10y agoDon't use a static key. At least use DHE or ECDH to negotiate the key.
- userbinator 10y agoOne terrible idea I just had was creating only one publicly accessible API and then encrypting the actual endpoint in the payload which the server would decrypt and then redirect. You just reinvented the TLS socket connection.
- K0nserv 10y agoDon't rely on obscurity and obfuscation. Instead build your API in such a way that handing someone the complete documentation would have no negative impact. Assume the client is always compromised. My $0.02
- heinrichf 10y agoLet us also mention the great mitmproxy, an open source equivalent to the Charles proxy: https://github.com/mitmproxy/mitmproxy https://github.com/mitmproxy/mitmproxy / https://mitmproxy.org/ https://mitmproxy.org/
- bugmenot3 10y agoMy go-to has always been Fiddler[1] (for windows). I wish it were open-source though. I'll give mitmproxy a try. Thanks! [1] http://www.telerik.com/fiddler http://www.telerik.com/fiddler
- _pmf_ 10y agoFiddler is amazing!
- illicium 10y agoAnother option is Burp Suite (https://portswigger.net/burp/ https://portswigger.net/burp/ ) -- ubiquitous in the security world.
- homero 10y agoSeems ignorant not to have a unique Charles certificate
- brokenmachine 10y agoApparently modern Charles versions have a unique CA generated by each client.
- bytesandbots 10y agoOn android, this only works when the app is using http urlconnection provided by java. If the app uses apache http stack, the request is not routed through the proxy settings. Such traffic will not showup in charles or the great MITM.
- chillydawg 10y agoI wonder how many techies could be silently MITM'd using the Charles root.
- benmanns 10y agoI worried about the same thing. Modern versions of Charles use a per-user root CA that is generated in the client.
- chillydawg 10y agoAha, much more sensible.
- throwaway2016a 10y agoI can confirm Android detects it and sternly warns you (but allows you to keep doing it if you want).
- blin17 10y agoDid someone just post this guys blog from 2013 up?
- msoad 10y agoThat's what I call debug mode enabled in production. RESTful JSON APIs are truly in debug mode in production
- Grimes23 10y agoWhat would you recommend in place of RESTful JSON API's?
- qq66 10y agoIs there any scenario where snooping on the upstream network connection can give you valuable reverse engineering information? Because of latency/reliability issues, most mobile apps have pretty simple and stateless protocols with the server.
- filleokus 10y agoEven on iOS it's possible to bypass certificate pinning by using a jailbroken device and tool. I wouldn't say that's a good meassure against reverse engineering.
- aggregator-ios 10y agoFor those looking for a fully native experience, give https://interceptapp.xyz https://interceptapp.xyz a try. Currently in alpha. Feedback is welcome and appreciated. Disclosure: I'm the developer.
- spangry 10y agoNice, I reckon you're targeting the primary 'benefit' sought by MITM'ers. Most of my Android MiTM'ing is because I want to get at the data behind the app. Trying to comprehend some of the crazy, ultra-nested JSON schemas that some app devs use is a PITA. Just a suggestion: I know you mention it in one of the marketing lines, but it might be worth stating that it's for Mac in the headline (or in the download button). Otherwise people like me, who just breeze past the marketing material to the download link, will waste 6.8MB of your bandwidth (sorry about that...)
- throwaway2016a 10y agoI'm pretty heavy into home automation and I use this technique all the time to learn how to control various walled garden home automation systems. Even worked with my Alarm company's system. However, if the phone app uses certificate pinning and SSL it doesn't work. (yes, that means my alarm company doesn't use certificate pinning).