From cfcf8c499d2f26d66c7b71c0aedd29101d41084d Mon Sep 17 00:00:00 2001 From: HardWork <67123922+Kechinator@users.noreply.github.com> Date: Sun, 31 Jul 2022 08:38:35 +0200 Subject: [PATCH 1/2] New hook for Appmatus transparency. --- frida-script.js | 94 ++++++++++++++++++++++++++++--------------------- 1 file changed, 53 insertions(+), 41 deletions(-) diff --git a/frida-script.js b/frida-script.js index f511cb5..a254d4b 100644 --- a/frida-script.js +++ b/frida-script.js @@ -18,57 +18,57 @@ setTimeout(function () { // always match built-in types, so here we spot all failures that use the built-in cert // error type (notably this includes OkHttp), and after the first failure, we dynamically // generate & inject a patch to completely disable the method that threw the error. - try { - const UnverifiedCertError = Java.use('javax.net.ssl.SSLPeerUnverifiedException'); - UnverifiedCertError.$init.implementation = function (str) { - console.log(' --> Unexpected SSL verification failure, adding dynamic patch...'); + // try { + // const UnverifiedCertError = Java.use('javax.net.ssl.SSLPeerUnverifiedException'); + // UnverifiedCertError.$init.implementation = function (str) { + // console.log(' --> Unexpected SSL verification failure, adding dynamic patch...'); - try { - const stackTrace = Java.use('java.lang.Thread').currentThread().getStackTrace(); - const exceptionStackIndex = stackTrace.findIndex(stack => - stack.getClassName() === "javax.net.ssl.SSLPeerUnverifiedException" - ); - const callingFunctionStack = stackTrace[exceptionStackIndex + 1]; + // try { + // const stackTrace = Java.use('java.lang.Thread').currentThread().getStackTrace(); + // const exceptionStackIndex = stackTrace.findIndex(stack => + // stack.getClassName() === "javax.net.ssl.SSLPeerUnverifiedException" + // ); + // const callingFunctionStack = stackTrace[exceptionStackIndex + 1]; - const className = callingFunctionStack.getClassName(); - const methodName = callingFunctionStack.getMethodName(); + // const className = callingFunctionStack.getClassName(); + // const methodName = callingFunctionStack.getMethodName(); - console.log(` Thrown by ${className}->${methodName}`); + // console.log(` Thrown by ${className}->${methodName}`); - const callingClass = Java.use(className); - const callingMethod = callingClass[methodName]; + // const callingClass = Java.use(className); + // const callingMethod = callingClass[methodName]; - if (callingMethod.implementation) return; // Already patched by Frida - skip it + // if (callingMethod.implementation) return; // Already patched by Frida - skip it - console.log(' Attempting to patch automatically...'); - const returnTypeName = callingMethod.returnType.type; + // console.log(' Attempting to patch automatically...'); + // const returnTypeName = callingMethod.returnType.type; - callingMethod.implementation = function () { - console.log(` --> Bypassing ${className}->${methodName} (automatic exception patch)`); + // callingMethod.implementation = function () { + // console.log(` --> Bypassing ${className}->${methodName} (automatic exception patch)`); - // This is not a perfect fix! Most unknown cases like this are really just - // checkCert(cert) methods though, so doing nothing is perfect, and if we - // do need an actual return value then this is probably the best we can do, - // and at least we're logging the method name so you can patch it manually: + // // This is not a perfect fix! Most unknown cases like this are really just + // // checkCert(cert) methods though, so doing nothing is perfect, and if we + // // do need an actual return value then this is probably the best we can do, + // // and at least we're logging the method name so you can patch it manually: - if (returnTypeName === 'void') { - return; - } else { - return null; - } - }; + // if (returnTypeName === 'void') { + // return; + // } else { + // return null; + // } + // }; - console.log(` [+] ${className}->${methodName} (automatic exception patch)`); - } catch (e) { - console.log(' [ ] Failed to automatically patch failure'); - } + // console.log(` [+] ${className}->${methodName} (automatic exception patch)`); + // } catch (e) { + // console.log(' [ ] Failed to automatically patch failure'); + // } - return this.$init(str); - }; - console.log('[+] SSLPeerUnverifiedException auto-patcher'); - } catch (err) { - console.log('[ ] SSLPeerUnverifiedException auto-patcher'); - } + // return this.$init(str); + // }; + // console.log('[+] SSLPeerUnverifiedException auto-patcher'); + // } catch (err) { + // console.log('[ ] SSLPeerUnverifiedException auto-patcher'); + // } /// -- Specific targeted hooks: -- /// @@ -503,8 +503,20 @@ setTimeout(function () { console.log('[ ] Boye AbstractVerifier'); } + // Appmattus + try { + const appmatus_Activity = Java.use('com.appmattus.certificatetransparency.internal.verifier.CertificateTransparencyInterceptor'); + appmatus_Activity['intercept'].implementation = function (a) { + console.log(' --> Bypassing Appmattus (Transparency)'); + return a.proceed(a.request()); + }; + console.log('[+] Appmattus (Transparency)'); + } catch (err) { + console.log('[ ] Appmattus (Transparency)'); + } + console.log("Unpinning setup completed"); console.log("---"); }); -}, 0); \ No newline at end of file +}, 0); From f35078db9bbf87bb3964118ec059e19e132fcd76 Mon Sep 17 00:00:00 2001 From: HardWork <67123922+Kechinator@users.noreply.github.com> Date: Sun, 31 Jul 2022 08:39:57 +0200 Subject: [PATCH 2/2] Update frida-script.js --- frida-script.js | 80 ++++++++++++++++++++++++------------------------- 1 file changed, 40 insertions(+), 40 deletions(-) diff --git a/frida-script.js b/frida-script.js index a254d4b..ae1eb24 100644 --- a/frida-script.js +++ b/frida-script.js @@ -18,57 +18,57 @@ setTimeout(function () { // always match built-in types, so here we spot all failures that use the built-in cert // error type (notably this includes OkHttp), and after the first failure, we dynamically // generate & inject a patch to completely disable the method that threw the error. - // try { - // const UnverifiedCertError = Java.use('javax.net.ssl.SSLPeerUnverifiedException'); - // UnverifiedCertError.$init.implementation = function (str) { - // console.log(' --> Unexpected SSL verification failure, adding dynamic patch...'); + try { + const UnverifiedCertError = Java.use('javax.net.ssl.SSLPeerUnverifiedException'); + UnverifiedCertError.$init.implementation = function (str) { + console.log(' --> Unexpected SSL verification failure, adding dynamic patch...'); - // try { - // const stackTrace = Java.use('java.lang.Thread').currentThread().getStackTrace(); - // const exceptionStackIndex = stackTrace.findIndex(stack => - // stack.getClassName() === "javax.net.ssl.SSLPeerUnverifiedException" - // ); - // const callingFunctionStack = stackTrace[exceptionStackIndex + 1]; + try { + const stackTrace = Java.use('java.lang.Thread').currentThread().getStackTrace(); + const exceptionStackIndex = stackTrace.findIndex(stack => + stack.getClassName() === "javax.net.ssl.SSLPeerUnverifiedException" + ); + const callingFunctionStack = stackTrace[exceptionStackIndex + 1]; - // const className = callingFunctionStack.getClassName(); - // const methodName = callingFunctionStack.getMethodName(); + const className = callingFunctionStack.getClassName(); + const methodName = callingFunctionStack.getMethodName(); - // console.log(` Thrown by ${className}->${methodName}`); + console.log(` Thrown by ${className}->${methodName}`); - // const callingClass = Java.use(className); - // const callingMethod = callingClass[methodName]; + const callingClass = Java.use(className); + const callingMethod = callingClass[methodName]; - // if (callingMethod.implementation) return; // Already patched by Frida - skip it + if (callingMethod.implementation) return; // Already patched by Frida - skip it - // console.log(' Attempting to patch automatically...'); - // const returnTypeName = callingMethod.returnType.type; + console.log(' Attempting to patch automatically...'); + const returnTypeName = callingMethod.returnType.type; - // callingMethod.implementation = function () { - // console.log(` --> Bypassing ${className}->${methodName} (automatic exception patch)`); + callingMethod.implementation = function () { + console.log(` --> Bypassing ${className}->${methodName} (automatic exception patch)`); - // // This is not a perfect fix! Most unknown cases like this are really just - // // checkCert(cert) methods though, so doing nothing is perfect, and if we - // // do need an actual return value then this is probably the best we can do, - // // and at least we're logging the method name so you can patch it manually: + // This is not a perfect fix! Most unknown cases like this are really just + // checkCert(cert) methods though, so doing nothing is perfect, and if we + // do need an actual return value then this is probably the best we can do, + // and at least we're logging the method name so you can patch it manually: - // if (returnTypeName === 'void') { - // return; - // } else { - // return null; - // } - // }; + if (returnTypeName === 'void') { + return; + } else { + return null; + } + }; - // console.log(` [+] ${className}->${methodName} (automatic exception patch)`); - // } catch (e) { - // console.log(' [ ] Failed to automatically patch failure'); - // } + console.log(` [+] ${className}->${methodName} (automatic exception patch)`); + } catch (e) { + console.log(' [ ] Failed to automatically patch failure'); + } - // return this.$init(str); - // }; - // console.log('[+] SSLPeerUnverifiedException auto-patcher'); - // } catch (err) { - // console.log('[ ] SSLPeerUnverifiedException auto-patcher'); - // } + return this.$init(str); + }; + console.log('[+] SSLPeerUnverifiedException auto-patcher'); + } catch (err) { + console.log('[ ] SSLPeerUnverifiedException auto-patcher'); + } /// -- Specific targeted hooks: -- ///