mirror of
https://github.com/httptoolkit/frida-interception-and-unpinning.git
synced 2026-10-09 01:12:26 +02:00
Remove overly lax hook on TrustManagerImpl
This isn't required, because our system certificate injection prepopulates the index used by all trust managers anyway, so they trust our cert regardless. As configured, the previous hook just trusted _all_ certificates, exposing 3rd party MitM risk - better to keep it strict for just our certificate where we can.
This commit is contained in:
@@ -66,19 +66,6 @@ const PINNING_FIXES = {
|
||||
}
|
||||
],
|
||||
|
||||
// --- Native TrustManagerImpl
|
||||
|
||||
'com.android.org.conscrypt.TrustManagerImpl': [
|
||||
{
|
||||
methodName: 'checkTrustedRecursive',
|
||||
replacement: () => () => Java.use('java.util.ArrayList').$new()
|
||||
},
|
||||
{
|
||||
methodName: 'verifyChain',
|
||||
replacement: () => (untrustedChain) => untrustedChain
|
||||
}
|
||||
],
|
||||
|
||||
// --- Native Conscrypt OpenSSLSocketImpl
|
||||
|
||||
'com.android.org.conscrypt.OpenSSLSocketImpl': [
|
||||
|
||||
Reference in New Issue
Block a user