5 ms·
This is very true. I make an effort to point out that MITM proxy now supports Wireguard [1] to tunnel traffic out from the handset. It literally should take no
by x1sec 3y ago
This is very true.
I make an effort to point out that MITM proxy now supports Wireguard [1] to tunnel traffic out from the handset. It literally should take no more then 5 minutes from download to packet inspection. Of course if TLS is used by the mobile app then on iOS it's a few more minutes of setup time. Unfortunately with Android, installing your own certificate in the trust store is no longer trivial.
As you point out though, the application doesn't even use TLS for sending the GPS data.
In part two [2] of the blog post series, the Alibaba's AMap SDK uses both TLS and custom encryption and this took me quite a few days to figure out the Wifi and cell data collection - so it's not always so trivial. Either way, I recommend to everyone to at least do a basic 'desk check' on the apps they install. You never know what you will find.
[1] https://mitmproxy.org/posts/wireguard-mode/ https://mitmproxy.org/posts/wireguard-mode/
[2] https://doubleagent.net/2023/05/22/a-car-battery-monitor-tracking-your-location-part2 https://doubleagent.net/2023/05/22/a-car-battery-monitor-tra...
- varenc 3y agoSadly certificate pinning is becoming pretty common in my experience. Most of the "big apps" do it. That means that even if you trust your own CA you still can't MITM the traffic. On iOS you need to jailbreak a device to override cert pinning. Funny how mechanisms that increase security also remove some of the freedom and visibility we have into our own deviecs.
- x1sec 3y agoMost defiantly. iOS is a different kettle of fish. Same challenges are present with performing forensics on an iPhone! The top commercial forensic toolkits will try to jailbreak the handset if possible to pull off artifacts. Good luck on newer hardware with the latest iOS versions. [1] On the topic of iOS forensics, you can still get quite many useful artifacts from iOS backups with Mobile Verification Toolkit [2] being quite exceptional. I have had less success with iOS backups and the popular iLEAPP forensics software [3]. [1] https://blog.elcomsoft.com/2022/09/ios-forensic-toolkit-8-0-now-official-bootloader-level-extraction-for-76-devices/ https://blog.elcomsoft.com/2022/09/ios-forensic-toolkit-8-0-... [2] https://docs.mvt.re/en/latest/ https://docs.mvt.re/en/latest/ [3] https://github.com/abrignoni/iLEAPP https://github.com/abrignoni/iLEAPP
- chrisweekly 3y agodefiantly -> definitely, right?
- varenc 3y agoThanks for those great tools recs. Had never seen mvt before and I'm running a check of my local iTunes backup with it now! (Funnily, this seems one of the easier ways to backup my text message history into an easily searchable form)
- x1sec 3y agoIf you haven't used it before, Timesketch [1] is excellent indexing and searching timeline data for forensics analysis. MVT takes a (MACB) timeline of your phone backup file changes and other events - including your text message history. Here is a simple script that I wrote converts it into a format compatible with Timesketch [2] so it's trivial to explore events from the phone, indexed and searchable by time, kind of what you would see in Kibana. [1] https://timesketch.org/ https://timesketch.org/ [2] https://github.com/x1sec/mvt2timesketch https://github.com/x1sec/mvt2timesketch
- fomine3 3y agoThank you for your every post, very informative!
- wkat4242 3y agoAre you sure it's really pinning? On Android it's almost impossible to add certs to the system store, and the user store is ignored by most apps.
- varenc 3y agoMy experience is mostly limited to iOS where adding a trusted root CA is relatively easy. It's uncommon for the average app, but most of the big ones do it. iOS itself cert pins most things as well. But on Android, since adding a new CA is much harder, I'd guess fewer apps do it there.