13 ms·
Cracking Meta's Messenger Certificate Pinning on macOS
- notso411 3y agoOkay why just use the web interface and intercept that
- saagarjha 3y agoOften the web interface will be using a different API or be missing characteristics that are being investigated.
- ridafkih 3y ago> With Meta’s Messenger application for macOS being so close to the Texts.com model—that being a standalone desktop application—Batuhan İçöz who is leading the Meta platform project at Texts.com thought we could gain some valuable insight by analyzing it.
- pizzalife 3y ago[flagged]
- sneak 3y agoCracking (abbreviated “[k]”) is the term of art for making small modifications to a compiled binary to toggle functionality (usually disabling license/serial checks, but in this case cert pinning). This usage is completely consistent with the typical and is well in-bounds.
- natpalmer1776 3y agoCracking is also used to refer to converting some obfuscated secret to plaintext, most commonly in reference to passwords. So I can understand the confusion
- deleted 3y ago[deleted]
- dvt 3y agoVery clever way of doing this (though I have a feeling you could probably enforce pinning even in sandboxed mode). I remember trying to MitM Snapchat back in college and couldn't figure it out as they were also using cert pinning.
- 4death4 3y agoFundamentally, it’s hard to enforce certificate pinning if the user can modify the binary. Even if sandbox mode used certificate pinning, there would likely be some other way of removing the pinned cert checks.
- detourdog 3y agoThis is a large part of Apple's control/Secure Enclave decisions. These decisions can seem arbitrary and anti-completive from the outside.
- saagarjha 3y agoThis seems unrelated?
- detourdog 3y agoI saw is as related by an entities ability to control certificates on platforms with zero trust.
- saagarjha 3y agoApple designs the platform, though. Seems like a different model to me?
- detourdog 3y agoExactly I was pointing out why some may choose certain models. I would say that building a platform takes many considerations and the choices made led to this outcome. Apple made different choices and is often vilified for trying to maintain these protections. Apple has been slowly making progress of opening up their platform. The next 3 years will introduce a new landscape for apps. People will still be complaining.
- bevekspldnw 3y agoHa, I found myself going down a similar route and threw in the towel once I was trying to decompile/edit/recompile. This is dedication, would love to know the hours involved. I set myself a cutoff and stuck to it.
- ridafkih 3y agoThis was initially an internal post at Texts.com that we decided to share, and I scrapped mention of the fact I had tried the exact same approach a few weeks prior and reached my time-box as well. I initially spent two hours trying to modify different instructions, and then gave up. I saw another blog post written by a reverse engineer by the name of "Hassan Mostafa" (aka cyclon3) that previously succeeded in the same approach (taking Hopper Disassembler to Instagram on iOS) and I was inspired to try again that night, but I had no luck. I even found and attempted to modify the same instructions. I decided to call it quits, and then a few weeks later with a bit of a grudge, I spontaneously tried again and I had it done in about 30 minutes after finding the sandbox function.
- bevekspldnw 3y agoOk, that makes sense! Sometimes when you read a blog post that is well written and cogent it makes it feel like the author did it in 20 min! If I end up in the same arena I think I’ll look for debugging code next. I love certificate pinning as a user, but as a forensic analyst I fucking loath it.
- vengefulduck 3y agoEven as a user I don’t there’s a good reason to love cert pinning. If you’re going up against adversaries that can compromise web pki they also probably have some other exploits up their sleeve to pwn you. Cert pinning pretty much serves to protect companies from people reversing their protocols and little else imo.
- ridafkih 3y agoIt prevents attack vectors that involve attacker-owned certificate authorities as well as compromised certificate authorities from exposing user-data. https://sslmate.com/resources/certificate_authority_failures https://sslmate.com/resources/certificate_authority_failures
- sneak 3y agoI remember the first time I ever cracked an app, I was so convinced I would fail, but it turns out that finding these sorts of easy-to-modify JNE/JEZ spots is easier than it seems. Even if you pick wrong you can just revert to the original file and try a different spot. I imagine this would be something that AI will be able to do easily in an automated fashion, you can literally just try flipping the JEZ/JNZ in a bunch of candidate spots and launching the app and seeing if the nag screen comes up.
- XorNot 3y agoNot really an AI problem though: that's just fuzzing. If the fail case is well defined then really all you need to do is prune the candidates down. Now if AI could crack something like Denuvo in a 0-shot way...
- ridafkih 3y agoI will say that ChatGPT did a decent job of explaining non-documented instructions in prior attempts of binary patching. Now if I could feed an AI a binary and have it tell me where what is happening in a very broad scope, that'd be a game changer, and I'd say that's quite attainable with a high-context window LLM as they seemingly understand hex-formatted byte-code quite well.
- fddrdplktrew 3y ago> Not really an AI problem though: that's just fuzzing everything is AI these days apparently... even LLMs
- userbinator 3y agoHad tools like that already in the 90s, no AI, just brute force.
- protoman3000 3y agoHow come applications from such big players are not completely obfuscated and have all kinds of other protections in them to e.g. deny modified binaries from running?
- ridafkih 3y agoIt's probably a matter of priorities, as well as cost v. benefit. Obfuscation would've had very little effect on the outcome of this experiment, but might've changed the approach to involve dynamic instrumentation a little more. The most effective obfuscation I've seen is VM obfuscation, but that presents a significant performance impact. Obfuscation would also make legitimate debugging harder. Preventing modified binaries is done at the system level, and could feasibly be implemented at the application level and is common, but this functionality itself could be both bypassed, or modifications could simply be implemented after security checks have completed (once again, through dynamic instrumentation libraries like Frida). Engaging in a cat-and-mouse game with reverse engineers probably isn't in Meta's best interest.
- toast0 3y agoObfuscation has costs, and certificate pinning is more to make it more difficult for user-adversarial MITM than to prevent reverse engineering. Although the impact on reverse engineering is more than a happy accident. At the end of the day, your code runs on user machines, and they can observe what the code does, so it's always possible to deobfuscate, and if one person does it and shares their results, it becomes very easy to replicate. That doesn't mean obfuscation is useless, but you shouldn't put too much time into it.
- wkat4242 3y agoSome app builders turn it into an art though. Like TikTok. They're infamous for it.
- rokkitmensch 3y agoI wonder if this is a cultural line of defense against server security...
- simonw 3y agoI'm really glad this is possible, because it's important for dispelling conspiracy theories. Plenty of people are convinced that Facebook's apps spy on them through their microphone and use that to show them targeted ads. The easiest way to disprove this is to monitor the traffic between the apps and Facebook's servers... but certificate pinning prevents this! (Not that anyone who believes this can ever be talked out of it, see https://simonwillison.net/2023/Dec/14/ai-trust-crisis/#facebook-dont-spy-microphone https://simonwillison.net/2023/Dec/14/ai-trust-crisis/#faceb... - but it's nice to know that we can keep tabs on this kind of thing anyway)
- saagarjha 3y agoUnfortunately while this thing helps it doesn't actually conclusively stop any speculation. If I wanted to spy on you via app, I would encrypt the data inside the HTTPS stream and only decrypt it on my server.
- ncann 3y agoPretty sure anything you encrypt client side can be decrypted client side, as long as you have control over the binary and OS/hardware. It's just a matter of effort.
- poyu 3y agoThey only need the server's public key to encrypt it client side. But if all you want is to see if they're spying on you, you could go one step above and see if they're calling system APIs to your mic/camera/keyboard, instead of observing the network activities.
- ridafkih 3y agoNot the case with asymmetric encryption, you could encrypt with a public key and only the server's private key would be able to decrypt it. Not even the client could.
- ghotli 3y ago
- deleted 3y ago[deleted]
- eugenekolo 3y agoThere's no point in implementing cert pinning if you don't also have integrity checking... Being able to alter bytes in the physical file and running it should not be possible (without another bypass).
- bevekspldnw 3y agoEh, clearly it raises the barrier to entry significantly. You’re never safe from a truly determined adversary, but you can keep out the riff raff.
- eugenekolo 3y agoPerhaps I'm a bit harsh... but my suggestion to fortune 500 tech company remains. Implement integrity validation as well, otherwise all it takes is editing 2 bytes to bypass your ssl pinning.
- saagarjha 3y agoRight, but the threat model of SSL pinning is an attacker that has compromised the CA certificate store. The user editing a binary on disk is not a security problem.
- meindnoch 3y agoCool idea! Now it takes 2 bytes to bypass integrity validation, and 2 bytes to bypass cert pinning. (4 bytes in total)
- deleted 3y ago[deleted]
- kevincox 3y agoCert pinning protects against compromised certificate authorities. There are hundreds of trusted root certificates in most operating system stores so one of them gets breached every once and a while. Integrity checking is user-hostile, but certificate pinning can be good for users.
- wkat4242 3y agoGood reminder that no app is truly ever "closed source" after all there is still the compiled machine code. People used to hand code in this language. Though I'm personally glad we no longer have to :) it's still way more difficult and compilers can really obfuscate the code (if it isn't already by design)
- NSHkr_hn 3y agoWould a runtime binary checksum have helped to complicate such modification? This isn’t sop for mobile apps? Do iOS or Android SDK’s provide such facilities? Presumably associated with the official release process and enforced on their respective non-jailbroken platforms? Basic questions, admittedly. Just noticed that the final solution was to simply modify a few bytes of the binary, which seemed preventable.
- thewakalix 3y agomacOS (desktop), not iOS (mobile).
- NSHkr_hn 3y agoThanks for the correction. Same inquiry for macOS for signed apps.
- _kbh_ 3y agoYou have to resign the binary when you modify anyway which achieves the same thing. On non-jailbroken platforms you generally do this with a developer certificate.
- oefrha 3y agoSeems Meta’s (or at least Messenger’s) RE defense is quite lenient here. Should be trivial for them to drop IsUsingSandbox() from prod builds entirely, that’s before we get into advanced obfuscation techniques.
- sophiebits 3y agoAt least when I worked there, protecting against reverse engineering was never a goal. Cert pinning is to make it harder for an adversary to tamper, not to make it harder for the user to.
- grishka 3y agoMeta's apps come with entire debug menus in production builds. The string that author found is likely part of such a menu.
- ridafkih 3y agoTheir Android application in particular allows the participation in a developer program which allows access to one of these menus. Not available on macOS and iOS unfortunately!
- grishka 3y agoYears ago I did manage to get into the impressively huge debug menu in the iOS Messenger app on a jailbroken device. So they do exist there, or at least did back then.
- hansonpeter 3y ago[dead]
- spullara 3y agoI can see an argument that software's communication over the network must be inspectable by the owner of the hardware.
- deleted 3y ago[deleted]
- mdaniel 3y agoI don't know why but your comment reminded me of learning about $SSLKEYLOGFILE and the ability to retroactively decrypt traffic captured in Wireshark: https://everything.curl.dev/usingcurl/tls/sslkeylogfile https://everything.curl.dev/usingcurl/tls/sslkeylogfile (I was expecting there to be an entry on MDN since my first contact with that env-var was from Mozilla's TLS library but no luck) I guess it's the fact that in my mental model any supporting library doesn't have to be modified to allow viewing the traffic, and no cert-pining-breaks required
- tru3_power 3y agoWhat proxy tool are you using in that write up? Does it route all application traffic through it when running? Sorry if these are dumb questions.
- ridafkih 3y agoGood question, Proxyman is the one I'm using in the writeup. It does route all application through it on macOS, and you can proxy iOS devices as well by installing a self-signed certificate on the device and connecting it through the proxy.
- tru3_power 3y agoVery cool. I got so used to using burp all these years I never bothered to look into anything else. I’ll try this out.
- fireattack 3y ago[flagged]
- KennyBlanken 3y agoThey're being hostile to security researchers - app developers don't like people snooping around their private APIs and whatnot. Nor does google, for that matter. Every move Apple and Google are making on their platforms is about turning the devices we pay for into devices for the companies whose apps we install.
- deleted 3y ago[deleted]
- charcircuit 3y ago>I don't get why it has to be this hostile toward developers and why no option is offered to disable it. If you can convince someone to install a certificate to violate their privacy you can just block the network, forcing the user to flip the setting. This allow apps to be able to protect their user's privacy from nosy enterprise network administrators.
- fireattack 3y agoI get it, but that's ultimately the user's choice.
- charcircuit 3y agoThat line of thinking leads you to the path where users are free to install malware and give it all the capabilities it needs because the user chose to do so.
- fireattack 3y agoYes, if the user want to disable all the protections and choose to install malware it's their choice. You can already do so on *nix, Windows, and macOS (albeit more complicated). Not sure why a phone OS would be different. Your line of thinking is basically "think of the children".
- rs_rs_rs_rs_rs 3y agoYou don't really need to do that if you want to intercept Meta apps traffic. https://www.facebook.com/whitehat/bugbounty-education/261571715763453/?helpref=topq https://www.facebook.com/whitehat/bugbounty-education/261571...
- ridafkih 3y agoThis only works on Android, we had no interest in intercepting the Android application.
- danpalmer 3y agoOut of interest, why not? I've needed to reverse engineer APIs in the past and using Android apps was always much easier so we always did that when the APIs were available.
- ridafkih 3y agoSince the Messenger Application on desktop is much closer to the usage model of the Texts.com client. We want to replicate the desktop client as closely as possible. It can be assumed there’s going to be properties that are unique to the desktop client and vice versa.
- rollulus 3y agoThis made me think back of the days of +Orc [1]. I believe a lot of knowledge common back then, like how to find and nop out an undesired branch, has been lost. Which is fair, there’s way more other tech to learn nowadays. [1]: https://en.m.wikipedia.org/wiki/Old_Red_Cracker https://en.m.wikipedia.org/wiki/Old_Red_Cracker
- stevekemp 3y agoI always feel nostalgic when I see references to +Orc, or Fravia (RIP). But I think there's still a lot of people doing the NOP-patching thing, albeit with more complexity. There continue to be people breaking DRM, and investigating random [mobile] apps with hex-editors & etc. It's harder to get started these days as programs are more complex, but at the same time the knowledge required is more accessible.
- Razengan 3y agoDoes anyone know WHERE the HELL Facebook stores tracking data on iOS? It shows my previous account even after I delete the app, clear the cache and Keychain, disable iCloud Drive, AND sign out of iCloud?? Why can't I see where this data is stored? Same for TikTok. WHY does Apple, parading around as a pompous paragon of privacy, even allow this shit?
- actualwitch 3y agoDevelopers can store items in keychain on your device/icloud account that are only visible to the apps made by that developer (and not you). It is a feature that it works this way, and this whole concept is fucking insane to me.
- Razengan 3y agoSo how can the user delete it without going through the app or wiping the entire phone? What else is being stored that we aren’t even aware of?
- gene91 3y agoOn iPhones, three ways to get rid of the keychain data of an app 1. wipe the phone AND you must not restore backups 2. jailbreak the phone 3. the app can wipes its own keychain (but apps don’t expose this feature generally)
- justin101 3y agoI am curious about the legality of this. I guess I assumed that doing this type of thing would technically a DCMA type breech? So this makes me wonder if my assumption wrong? How does this work legally?
- scoot 3y agoWhat does copyright have to do with this?
- Rebelgecko 3y agoI'm not an expert, but I think in the Blizzard v Glider case the courts decided that if you've violated a program's EULA it becomes illegal copyright infringement to duplicate the bits from your disk into RAM
- blincoln 3y agoI think the implication is that bypassing cert pinning could be considered a violation of the anti-circumvention provisions in the DMCA and WIPO Copyright Treaty, because it results in decryption of copyrighted content without the permission of the copyright owner. IANAL, but in the US, at least, I think the exemptions for good-faith security research[1] would apply. Maybe even the reverse-engineering for interoperability language in the DMCA itself[2]. [1] https://www.federalregister.gov/documents/2015/10/28/2015-27212/exemption-to-prohibition-on-circumvention-of-copyright-protection-systems-for-access-control https://www.federalregister.gov/documents/2015/10/28/2015-27... [2] https://www.govinfo.gov/content/pkg/PLAW-105publ304/pdf/PLAW-105publ304.pdf https://www.govinfo.gov/content/pkg/PLAW-105publ304/pdf/PLAW...
- danpalmer 3y agoIt's typically against terms of service to decompile or reverse engineer applications you download in this way, but it's also typically against terms of service to use their services from unofficial clients, so I think they're already way past T&Cs.
- djhn 3y agoRE for interoperability is allowed in many jurisdictions (afaik, ianal)
- kuter 3y agoI did something similar for Instagram on android few years ago. The usual methods for bypassing certificate didn't work on Instagram, they were statically linking openssl into a shared library called libcoldstart.so. I Spent some time reading openssl documentation and ended up installing a hook to the function that configured the certificate verification. In case you are curious. I used Frida for installing hooks to native functions.
- deleted 3y ago[deleted]
- farnulfo 3y agoIt seems that with ebpf you can read data before TLS encryption : Debugging with eBPF Part 3: Tracing SSL/TLS connections https://blog.px.dev/ebpf-openssl-tracing/ https://blog.px.dev/ebpf-openssl-tracing/
- tempaccount420 3y agoSide note: this wouldn't work with Rust programs that statically link to `rustls`, the most popular Rust TLS library.
- blincoln 3y agoThat's handy, and you can almost certainly hook the TLS send/receive functions in other ways, like with Frida, but being able to bypass pinning instead means that the researcher can route the traffic through existing tools like Burp Suite or mitmproxy. Routing real app traffic through an intercepting proxy can be a real time-saver depending on what the researcher is trying to do. E.g. if they want to automatically tamper with a parameter in a request that doesn't happen until after some kind of authentication/session setup, it's much faster to let the app do all of that and configure the proxy to just make the one change, versus having to write a whole client that does all of the initial steps and then makes the modified request, or writing an eBPF filter that makes the changes the researcher is interested in.