Commit Graph
18 Commits
Author SHA1 Message Date
Tim Perry 6ee3d4ebb1 Centralize config parameters and document the use of each script 2023-09-19 20:40:21 +02:00
Tim Perry 653cb60b9e Manually hook libc connect() to capture even more traffic 2023-09-19 19:43:39 +02:00
Tim Perry 6ba4419e1b Add a script to directly inject one always-trusted cert into Conscrypt
This is a notably different approach to the past certificate unpinning
setup. Through this new mechanism, we trust just one additional
certificate (instead of disabling cert verification entirely) and handle
just the standard Android certificate trust (we'll integrate unpinning
into this later).

This uses a hardcoded cert for now just for testing, but that will of
course be configurable in future.
2023-09-19 11:35:14 +02:00
Tim Perry 179d508e0f Set system proxy properties to catch even more cases 2023-09-15 17:10:33 +02:00
Tim Perry 95705e51f5 Update the readme, to migrate towards a new world of multiple scripts in this repo 2023-09-07 15:29:26 +02:00
Tim Perry f649806244 PoC for working Android proxy redirection
Tried a few different routes, this seems most promising - works fairly
quickly (~100ms, measured from the remote client), and should be
reliable for all plausible implementations of ProxySelector, which
should cover both default & proxy-overriding implementations.

Definitely needs a configurable route (most likely we'll go through
Android properties here, I think? There's a few possiblities) and this
notably doesn't handle Flutter, which ignores all Java's proper APIs for
this (but I think I have some plans for that...)
2023-09-06 19:38:28 +02:00
Tim PerryandGitHub 4d477da8c5 Merge pull request #34 from baltpeter/b_appmattus-checkServerTrusted
Add hook for Appmatus CertificateTransparencyTrustManager.checkServerTrusted
v1.0.0
2023-06-26 11:11:29 +01:00
Benjamin Altpeter feddf62e84 Add hook for Appmatus CertificateTransparencyTrustManager.checkServerTrusted 2023-06-23 14:52:20 +02:00
Tim PerryandGitHub f82daadf7d Merge pull request #23 from Kechinator/main
Add new hook for "Appmatus Certificate Transparency"
2022-08-01 12:31:36 +02:00
HardWorkandGitHub f35078db9b Update frida-script.js 2022-07-31 08:39:57 +02:00
HardWorkandGitHub cfcf8c499d New hook for Appmatus transparency. 2022-07-31 08:38:35 +02:00
Tim PerryandGitHub 0973d25a8a Add HTTP Toolkit links to the README 2022-03-03 17:14:32 +01:00
Tim Perry 91422adeda Add a *dynamic* patch for all code that throws SSL verification errors
This is crazy, but it seems to work! The case in point example here is
Vimeo, which is heavily obfuscated (so we can't reliably match method or
class names) but uses OkHttp internally, which uses the standard
exception types. We can spot those, so we do retrospective patching: the
first time a certificate validation fails, we disable the method that
threw the exception.

We'll still get one initial failure, but after that everything works
nicely. Wild.
2021-11-17 16:54:16 +01:00
Tim Perry b5a1340800 Fix 'unpinning completed' log message 2021-11-17 16:53:36 +01:00
Tim Perry 6c4225692d Fix unpinning of OkHTTP v3
In fact, the CertificatePinner.check() methods all throw if the
certificate is invalid, rather than returning a boolean, in v3
and older versions.
2021-09-22 16:27:27 +02:00
Tim Perry a0c61076f3 Link to the blog post in the README 2021-07-06 17:26:27 +02:00
Tim Perry 8a54e6324f Add the script 2021-07-01 17:17:13 +02:00
Tim PerryandGitHub cb08b55f5d Initial commit 2021-07-01 16:50:56 +02:00