3 ms·
How do you intercept traffic from apps that use cert pinning? Is the only way to patch the app binary and reinstall the patched binary using a dev certificate?
by zuck9 9y ago
How do you intercept traffic from apps that use cert pinning? Is the only way to patch the app binary and reinstall the patched binary using a dev certificate?
How exactly does one go about patching the binary – is there a tutorial somewhere?
- ktta 9y ago>Is the only way to patch the app binary and reinstall the patched binary using a dev certificate? Yes >How exactly does one go about patching the binary – is there a tutorial somewhere? https://www.guardsquare.com/en/blog/iOS-SSL-certificate-pinning-bypassing https://www.guardsquare.com/en/blog/iOS-SSL-certificate-pinn...
- t1o5 9y agoWon't an app worth its salt use certificate pinning to prevent this mitm ? In other words - Can I use Charles to sniff FB or watsapp traffic ? I do not use both services, but interested in analyzing their traffic.
- deleted 9y ago[deleted]
- robterrell 9y agoYou'll see the attempted request (the fact that there was a request to a named server) but none of the request details, except the encrypted stream. There are guides you can google for cracking apps and replacing the certs they compare against. IIRC they all require a jailbroken device.