Bypassing OkHttp Certificate Pinning

栏目: IT技术 · 发布时间: 6年前

内容简介:Yesterday, I was analyzing an Android application which uses OkHttp for certificate pinning. It took me hours to analyze the app, and have tried different methods to circumvent the app’s certificate pinning implementation. If I had only been monitoring the

Yesterday, I was analyzing an Android application which uses OkHttp for certificate pinning. It took me hours to analyze the app, and have tried different methods to circumvent the app’s certificate pinning implementation. If I had only been monitoring the system log while running the app, I could have done it in just a matter of minutes. I might have wasted a lot of time and effort, but at least I’ve learned.

Here’s my write up on how I bypassed OkHttp’s Certificate Pinning implementation.

Attempt #1: Using Xposed Modules

Since I had Xposed running on my test device, I first used the modules SSLUnpinning and TrustMeAlready . I know these modules are outdated, but it might still work. Unfortunately, it didn’t work on the app that I’m testing.

Attempt #2: Using Frida Scripts

My second attempt involved the use of Frida. After setting it up on my test device, I immediately tried the “most popular” Frida script on CodeShare which is the Universal Android SSL Pinning Bypass script. But what I got was just an error. Bypassing OkHttp Certificate Pinning

I tried another script but no luck as well. It did not even successfully detect the certificate pinning implementation used by the app. Bypassing OkHttp Certificate Pinning

I ended up trying all Frida scripts from CodeShare related to certificate pinning bypass but none of them worked.

Attempt #3: Via Manual Modification

I decided to look at the system log to see what’s happening in the background when the app is running. From the app’s log, I found the following certificate fingerprints (highlighted in green) . Bypassing OkHttp Certificate Pinning

Basically, the app checks for these fingerprints. If the fingerprint from the certificate chain matches one of the pinned fingerprints, then the peer’s identity has been verified and SSL pinning can be bypassed.

Before I could inject Burp’s certificate fingerprint, I first decompiled the app and look for the file where these pinned certificates were located. From the output below, the pinned fingerprints were located in /res/values/arrays.xml . Bypassing OkHttp Certificate Pinning

I then injected Burp’s certificate fingerprint to the list inside /res/values/arrays.xml . Bypassing OkHttp Certificate Pinning

Lastly, I recompiled the app and installed it. Bypassing OkHttp Certificate Pinning

Bypassing OkHttp Certificate Pinning

That’s it! I was able to bypass the app’s certificate pinning mechanism. Bypassing OkHttp Certificate Pinning

Lesson Learned:Always keep an eye on the system log while running the target application.


以上就是本文的全部内容,希望对大家的学习有所帮助,也希望大家多多支持 码农网

查看所有标签

本站部分资源来源于网络,本站转载出于传递更多信息之目的,版权归原作者或者来源机构所有,如转载稿涉及版权问题,请联系我们

机器学习及其应用2007

机器学习及其应用2007

周志华 编 / 清华大学 / 2007-10 / 37.00元

机器学习是人工智能的一个核心研究领域,也是近年来计算机科学中最活跃的研究分支之一。目前,机器学习技术不仅在计算机科学的众多领域中大显身手,还成为一些交叉学科的重要支撑技术。本书邀请相关领域的专家撰文,以综述的形式介绍机器学习中一些领域的研究进展。全书共分13章,内容涉及高维数据降维、特征选择、支持向量机、聚类、强化学习、半监督学习、复杂网络、异构数据、商空间、距离度量以及机器学习在自然语言处理中的......一起来看看 《机器学习及其应用2007》 这本书的介绍吧!

HTML 编码/解码
HTML 编码/解码

HTML 编码/解码

XML、JSON 在线转换
XML、JSON 在线转换

在线XML、JSON转换工具