4 ms·
This is the best article on Android app reverse engineering I have read. Thanks. Some more details on this step would be nice: > I currently have an iPhone so
by eixiepia 5y ago
This is the best article on Android app reverse engineering I have read. Thanks.
Some more details on this step would be nice:
> I currently have an iPhone so I installed the Android Emulator on my Linux machine and install the app on that. Then I launched mitmproxy and started intercepting the traffic from the emulator.
Is this also the emulator from Android Studio? It would be very nice to intercept app traffic, without the need for a real device, but I have never been able to get it working.
- l-albertovich 5y agoNot OP but thought I could help : Usually you have to use (or create) an unpinner frida script. In my experience it's been easier to just write down custom dumpers to avoid having to deal with that and also modifying the request (at least some time ago mitmproxy downgraded http/2 to http) which would result in the endpoint being able to detect the tampering. As for the emulator, I haven't ever used the official one to work, I know some people who used Anbox in Linux but I don't have much to say because I use a real device most of the times (although I pleayer with ldplayer, bluestacks and genymotion all of which behaved nicely to some extent).
- mhils 5y agoFWIW mitmproxy shouldn't downgrade HTTP/2, at least if you have a version that was released in 2016 or later. If that's not the case please feel free to file a bug and I'll look into it. :)