6 ms·
You should intercept the API calls it uses!
by skeletonjelly 6y ago
You should intercept the API calls it uses!
- fakedang 6y agoHonest question. How do you intercept and retrieve an API that communicates within an app?
- nickserv 6y agoIf it's on WiFi, any old packet sniffer on the network should do the job. If it's on cellular, you'll need to have access to police equipment.
- ThermalCube 6y agoCellular data? just connect your phone to your own VPN (like a RaspPi) and sniff there
- tpetry 6y agoA packet sniffer on the network will not help with tls encrypted endpoints. The charles proxy with custom ssl certificates may help if the certificate is not pinned in the app.
- rl1987 6y agoAssuming it does not use TLS cert pinning, you can use mitmproxy [0]. [0] https://mitmproxy.org/ https://mitmproxy.org/
- nezgar 6y agoHTTPS MITM + Wireshark If it even uses HTTPS lol
- jeofken 6y agoWireshark is popular for this