Commit Graph
117 Commits
Author SHA1 Message Date
Tim PerryandGitHub 7eca72577a Merge pull request #143 from sinnet3000/fix/typo
fix: Correct README script path for android-disable-root-detection.js
2025-06-23 14:02:34 +02:00
Luis Colunga 0b650ec11a docs(readme): fix typo in script path for android-disable-root-detection.js 2025-06-22 11:01:03 -07:00
Tim Perry 3858ba270f Fix root-detection java.io.File case 2025-06-20 19:08:39 +02:00
Tim Perry f6c05206c6 Fix config module utils for Frida 17 2025-06-20 18:40:32 +02:00
Tim Perry 4b4744ca0b Update new no-root-detection script to Frida 17 too 2025-06-20 18:28:06 +02:00
Tim PerryandGitHub 362ea92dfb Merge pull request #140 from kaifcodec/main
fix: update deprecated Module.* APIs for Frida v17
2025-06-20 18:20:32 +02:00
Tim Perry aacc1579cb Update native TLS & iOS hooks to Frida 17 too 2025-06-20 16:59:52 +02:00
Tim Perry c5dcc8acd6 Fix connect module fallback (get* throws an error, find* returns null) 2025-06-20 16:46:23 +02:00
Tim PerryandGitHub b4f9c2786c Merge pull request #141 from riyadmondol2006/main
Add Android root detection bypass script from external repository
2025-06-20 16:22:22 +02:00
Tim Perry 1385cf7e89 Fix GHA actions config 2025-06-20 16:19:40 +02:00
Tim Perry 2c440d3775 Document the root bypass script 2025-06-20 16:15:53 +02:00
Tim Perry f41596752d Match Android fingerprint where possible while hiding root 2025-06-20 16:15:52 +02:00
Tim Perry 318725026a Make Android root detection match our other logs 2025-06-20 16:12:25 +02:00
Riyad MondolandGitHub 7a50ac4691 Update README.md 2025-06-14 05:11:03 +06:00
Riyad MondolandGitHub da710353fe Add files via upload 2025-06-14 05:08:26 +06:00
Riyad MondolandGitHub fa10ac6f9b Delete root_detection_bypass.js 2025-06-14 05:08:12 +06:00
Riyad MondolandGitHub d6429b7ac7 Add files via upload
Added root detection bypass
2025-06-14 05:04:12 +06:00
kaifcodec eac9e21444 fix: update deprecated Module.* APIs for Frida v17 2025-06-11 21:32:20 +05:30
Tim Perry 185e91f62d Add a script to disable iOS jailbreak detection (WIP) 2024-07-16 18:18:29 +02:00
Tim Perry 5b0fd454b9 Fix parallel TLS hook issue
It's unclear why, but in some scenarios the hook would reliably hit a
null pointer within the native realCallback() call if the call is made
while another is already in progress (even though without Frida that's
presumably happening just fine, and they're different cb pointers etc
etc).

We could use Frida's exclusive scheduling to fix this, but that raises
the risk of a deadlock here a bit in, so instead we do a very simple
locking setup with a polling unlock. Very quick & rough but works
nicely, and allows reentrant locks in a single thread in case some apps
use SSL to verify SSL somehow. Hard to imagine a cross-thread deadlock
here so hopefully that'll be sufficient...
2024-06-17 15:39:34 +02:00
Tim Perry e99740babb Fix native TLS hook null-callback handler 2024-06-17 15:38:09 +02:00
Tim Perry eb4720f1d4 Include iOS support in the native connect hook 2024-06-14 18:18:04 +02:00
Tim Perry 8ca3cb5b94 Handle null TLS callback in native-tls-hook
This doesn't seem to be widely used, but it can come up, and it's easy
enough for us to handle correctly.
2024-06-14 17:30:59 +02:00
Tim Perry b96aac3d0a Avoid needless reallocation of host & port strings on iOS
This is also extremely likely a memory leak since we're never cleaning
these up - best to avoid that!
2024-06-12 12:40:36 +02:00
Tim Perry b0387881c9 Update IP testing script to signal just once, for the first good IP 2024-06-03 19:24:14 +02:00
Tim Perry a7f9bf4dc3 Add IP connectivity test script 2024-05-31 09:31:42 +01:00
Tim Perry 0499961831 Move native module detection into a reusable method 2024-03-05 17:49:06 +01:00
Tim Perry 9731e4bc52 Hook native Android OpenSSL too 2024-03-05 17:08:23 +01:00
Tim Perry a1223136cd Extend iOS BoringSSL hook to hook BoringSSL in other cases too
This notably affects TikTok, but will also apply for any bundled use of
BoringSSL within apps elsewhere. This is now recommended for all Android
& iOS usage.

Note the per-lib difference at the start of the hooked callback - it
seems we may need to customize whether the callback is proactively
called for some individual cases, and that might need extending in
future.
2024-03-05 15:46:41 +01:00
Tim Perry b5206370fb Make IPv4-mapped IPv6 addresses more readable in native-connect-hook
Useful as these can require manual intervention & redirection later,
which is tricky when you can't easily read the IP involved.
2024-02-21 14:02:45 +01:00
Tim Perry a3ff3914a8 Update incomplete comment in iOS TLS script 2024-02-02 18:29:23 +01:00
Tim Perry 6136e1ac6e Document iOS scripts & interception setup 2024-02-02 18:25:08 +01:00
Tim Perry a1a80cb63b Update the comments documenting our new iOS TLS override hook 2024-02-02 17:59:17 +01:00
Tim Perry 08d4ef8bda Tweak & better document limitations of our iOS TLS validation 2024-02-02 17:59:16 +01:00
Tim Perry 713a628319 Make iOS BoringSSL hook fallback to the real verification callback
This is useful because it means that traffic which bypasses the proxy
(e.g. by using TLS passthrough or similar) will still succeed! This
makes it easier to handle any issues later on.
2024-02-02 17:59:16 +01:00
Tim Perry 140af9b8be Validate the certificate chain (for our CA) when hooking iOS BoringSSL
This is really cool. Rather than just blindly disabling all TLS
validation, we now verify the cert directly against the CA you provide.
We only do extremely basic checks (some more testing required to
validate this provides even basic guarantees) so this shouldn't be
relied for rock-solid TLS validation (probably even after it's been
tested tbh) and it won't handle many real-world cases of CA validation,
but in terms of "do a local MitM while retaining the basics of TLS
protection" it should do a reasonable job, hopefully.
2024-02-02 17:59:16 +01:00
Tim Perry 88016333b5 Parse PEM into raw DER bytes ourselves in pure JS 2024-02-02 17:59:14 +01:00
Tim Perry b5d439a4df Make sure config.js doesn't break in non-Java environments 2024-02-02 17:58:53 +01:00
Tim Perry 4e42ca8ed5 Handle missing get_psk_identity in iOS 2024-02-02 17:58:53 +01:00
Tim Perry 47307a53f3 Add iOS BoringSSL script for full TLS override 2024-02-02 17:58:52 +01:00
Tim Perry ab38296bb1 Add an iOS low-level hook for Network Framework 2024-02-02 17:58:52 +01:00
Tim PerryandGitHub 8cfe27b746 Merge pull request #69 from AlexPaiva/updated-readme
Updated ReadMe file for better understanding
2024-01-24 17:31:41 +01:00
Tim Perry 6e99adad29 Format extra README details a little for clarity 2024-01-24 17:08:08 +01:00
Alexandre Paiva 5ca233985b Updated ReadMe file for better understanding 2024-01-23 13:59:38 +00:00
Tim PerryandGitHub d081776d1f Update README to explain where to find HTTP Toolkit's CA & proxy details 2024-01-23 14:16:48 +01:00
Tim PerryandGitHub 64fc7d443a Note dependency between Android unpinning scripts in the README 2024-01-09 12:02:35 +01:00
Tim PerryandGitHub c58b0b9d76 Merge pull request #64 from Anon-Exploiter/patch-1
Word correction - Update config.js
2024-01-02 11:02:23 +01:00
Syed Umar ArfeenandGitHub 0e47a3779b Update config.js 2023-12-12 14:05:09 +11:00
Tim Perry 78fa288d46 Revert "Always loudly log intercepted connections that fail to reach the proxy"
This reverts commit 6eec741f5c.

This doensn't actually work correctly, as connect() will return -1
(treated here as failure) for sockets that are still in progress, when
opened non-blocking, and therefore we end up logging these as failures.
We need to handle async connection state detection - that's a bit fiddly
from inside Frida, so for now let's just roll this back.
2023-11-15 18:39:51 +01:00
Tim Perry 6eec741f5c Always loudly log intercepted connections that fail to reach the proxy 2023-11-14 10:26:59 +01:00