4 ms·
Thought so i played around with this and my phone, self hacking ;) It's also very nice to intercept app traffic. Some use cert pinning, so the custom certifica
by H4sh3 6y ago
Thought so i played around with this and my phone, self hacking ;)
It's also very nice to intercept app traffic.
Some use cert pinning, so the custom certificate won't work.
- capableweb 6y agoThink there are a few tools for getting around the certificate pinning, projects like sensepost/objection
- feanaro 6y agoIn most cases you can get away with simply connecting to the application with `objection` (mentioned in a sibling post) and running `android sslpinning disable`. This will fail in some cases when the application is obfuscated or uses a non-standard pinning mechanism. In this case you can decompile the application to determine the methods used to accomplish the pinning and use frida (https://frida.re https://frida.re) directly in order to manually override them.