4 ms·
In the second part of the blog post series, I show that they AMap SDK they use encrypts data data first using AES and then further encrypting the AES key(s) wit
by x1sec 3y ago
In the second part of the blog post series, I show that they AMap SDK they use encrypts data data first using AES and then further encrypting the AES key(s) with a public RSA key embedded in the application. Not trivial.
If certificate pinning was used, it can be bypassed by modifying the APK or dynamically hooking into the running application using Frida. Often you have to try a few things before getting it working, often starting with a universal TLS bypass Frida script [1][2]
[1] https://codeshare.frida.re/@pcipolloni/universal-android-ssl-pinning-bypass-with-frida/ https://codeshare.frida.re/@pcipolloni/universal-android-ssl...
[2] https://codeshare.frida.re/@akabe1/frida-multiple-unpinning/ https://codeshare.frida.re/@akabe1/frida-multiple-unpinning/