4 ms·
Can you even do this if the client hasn't installed your cert?
by H4sh3 6y ago
Can you even do this if the client hasn't installed your cert?
- colechristensen 6y agoIt depends on how the client will treat an untrusted cert.
- dewey 6y agoNo, only works if there's a way to install custom certificates on the device you are monitoring. Otherwise that would defeat the whole purpose of https (If there are no bugs in the implementation or other security issues of course). For mitmproxy that would be achieved like this: https://docs.mitmproxy.org/stable/concepts-certificates/ https://docs.mitmproxy.org/stable/concepts-certificates/
- H4sh3 6y agoThought so i played around with this and my phone, self hacking ;) It's also very nice to intercept app traffic. Some use cert pinning, so the custom certificate won't work.
- capableweb 6y agoThink there are a few tools for getting around the certificate pinning, projects like sensepost/objection
- feanaro 6y agoIn most cases you can get away with simply connecting to the application with `objection` (mentioned in a sibling post) and running `android sslpinning disable`. This will fail in some cases when the application is obfuscated or uses a non-standard pinning mechanism. In this case you can decompile the application to determine the methods used to accomplish the pinning and use frida (https://frida.re https://frida.re) directly in order to manually override them.