Commit Graph
127 Commits
Author SHA1 Message Date
Tim PerryandGitHub a07671fbe9 Merge pull request #146 from acomerlatto/main
feat(native-connect-hook): enhance support for system connection hooks
2025-07-03 15:27:41 +02:00
Alisson Comerlatto 09cd59b728 feat(native-connect-hook): enhance support for system connection hooks
- Declare system module as a constant.
- Add `conn` variable for cleaner `Interceptor.attach` initialization.
- Improve error handling.
2025-07-03 10:14:24 -03:00
Tim PerryandGitHub 426bd4e2ab Merge pull request #145 from acomerlatto/main
fix(native-connect-hook): adjust scope of `systemModule` declaration
2025-07-03 14:01:23 +02:00
Alisson Comerlatto ad465d0044 fix(native-connect-hook): adjust scope of systemModule declaration
- Move `systemModule` declaration outside `try` block for proper scope management.
2025-07-02 17:30:59 -03:00
Tim Perry ae338c5bcd Add SOCKS support to native-connect hook 2025-06-27 18:00:17 +02:00
Tim Perry bcbe288aa2 Add functionality to block HTTP/3 by default 2025-06-24 17:43:09 +02:00
Tim Perry 33c9febf1b Add a fallback hook for meta proxygen unpinning 2025-06-24 16:31:15 +02:00
Tim Perry 4c2019597e Expand scripts included in standard build output 2025-06-24 12:40:32 +00:00
Tim Perry 6922444bf2 Make anti-root detection resilient to odd packages 2025-06-24 14:34:43 +02:00
Tim Perry 34c74c1505 Tighten up 'su' file IO detection on Android anti-root detection
Previously this blocked all reads of any paths containing 'su', which
has a lot of false positives (e.g. .../support-file) that will very
plausibly cause problems.
2025-06-24 14:34:43 +02:00
Tim PerryandGitHub 7eca72577a Merge pull request #143 from sinnet3000/fix/typo
fix: Correct README script path for android-disable-root-detection.js
2025-06-23 14:02:34 +02:00
Luis Colunga 0b650ec11a docs(readme): fix typo in script path for android-disable-root-detection.js 2025-06-22 11:01:03 -07:00
Tim Perry 3858ba270f Fix root-detection java.io.File case 2025-06-20 19:08:39 +02:00
Tim Perry f6c05206c6 Fix config module utils for Frida 17 2025-06-20 18:40:32 +02:00
Tim Perry 4b4744ca0b Update new no-root-detection script to Frida 17 too 2025-06-20 18:28:06 +02:00
Tim PerryandGitHub 362ea92dfb Merge pull request #140 from kaifcodec/main
fix: update deprecated Module.* APIs for Frida v17
2025-06-20 18:20:32 +02:00
Tim Perry aacc1579cb Update native TLS & iOS hooks to Frida 17 too 2025-06-20 16:59:52 +02:00
Tim Perry c5dcc8acd6 Fix connect module fallback (get* throws an error, find* returns null) 2025-06-20 16:46:23 +02:00
Tim PerryandGitHub b4f9c2786c Merge pull request #141 from riyadmondol2006/main
Add Android root detection bypass script from external repository
2025-06-20 16:22:22 +02:00
Tim Perry 1385cf7e89 Fix GHA actions config 2025-06-20 16:19:40 +02:00
Tim Perry 2c440d3775 Document the root bypass script 2025-06-20 16:15:53 +02:00
Tim Perry f41596752d Match Android fingerprint where possible while hiding root 2025-06-20 16:15:52 +02:00
Tim Perry 318725026a Make Android root detection match our other logs 2025-06-20 16:12:25 +02:00
Riyad MondolandGitHub 7a50ac4691 Update README.md 2025-06-14 05:11:03 +06:00
Riyad MondolandGitHub da710353fe Add files via upload 2025-06-14 05:08:26 +06:00
Riyad MondolandGitHub fa10ac6f9b Delete root_detection_bypass.js 2025-06-14 05:08:12 +06:00
Riyad MondolandGitHub d6429b7ac7 Add files via upload
Added root detection bypass
2025-06-14 05:04:12 +06:00
kaifcodec eac9e21444 fix: update deprecated Module.* APIs for Frida v17 2025-06-11 21:32:20 +05:30
Tim Perry 185e91f62d Add a script to disable iOS jailbreak detection (WIP) 2024-07-16 18:18:29 +02:00
Tim Perry 5b0fd454b9 Fix parallel TLS hook issue
It's unclear why, but in some scenarios the hook would reliably hit a
null pointer within the native realCallback() call if the call is made
while another is already in progress (even though without Frida that's
presumably happening just fine, and they're different cb pointers etc
etc).

We could use Frida's exclusive scheduling to fix this, but that raises
the risk of a deadlock here a bit in, so instead we do a very simple
locking setup with a polling unlock. Very quick & rough but works
nicely, and allows reentrant locks in a single thread in case some apps
use SSL to verify SSL somehow. Hard to imagine a cross-thread deadlock
here so hopefully that'll be sufficient...
2024-06-17 15:39:34 +02:00
Tim Perry e99740babb Fix native TLS hook null-callback handler 2024-06-17 15:38:09 +02:00
Tim Perry eb4720f1d4 Include iOS support in the native connect hook 2024-06-14 18:18:04 +02:00
Tim Perry 8ca3cb5b94 Handle null TLS callback in native-tls-hook
This doesn't seem to be widely used, but it can come up, and it's easy
enough for us to handle correctly.
2024-06-14 17:30:59 +02:00
Tim Perry b96aac3d0a Avoid needless reallocation of host & port strings on iOS
This is also extremely likely a memory leak since we're never cleaning
these up - best to avoid that!
2024-06-12 12:40:36 +02:00
Tim Perry b0387881c9 Update IP testing script to signal just once, for the first good IP 2024-06-03 19:24:14 +02:00
Tim Perry a7f9bf4dc3 Add IP connectivity test script 2024-05-31 09:31:42 +01:00
Tim Perry 0499961831 Move native module detection into a reusable method 2024-03-05 17:49:06 +01:00
Tim Perry 9731e4bc52 Hook native Android OpenSSL too 2024-03-05 17:08:23 +01:00
Tim Perry a1223136cd Extend iOS BoringSSL hook to hook BoringSSL in other cases too
This notably affects TikTok, but will also apply for any bundled use of
BoringSSL within apps elsewhere. This is now recommended for all Android
& iOS usage.

Note the per-lib difference at the start of the hooked callback - it
seems we may need to customize whether the callback is proactively
called for some individual cases, and that might need extending in
future.
2024-03-05 15:46:41 +01:00
Tim Perry b5206370fb Make IPv4-mapped IPv6 addresses more readable in native-connect-hook
Useful as these can require manual intervention & redirection later,
which is tricky when you can't easily read the IP involved.
2024-02-21 14:02:45 +01:00
Tim Perry a3ff3914a8 Update incomplete comment in iOS TLS script 2024-02-02 18:29:23 +01:00
Tim Perry 6136e1ac6e Document iOS scripts & interception setup 2024-02-02 18:25:08 +01:00
Tim Perry a1a80cb63b Update the comments documenting our new iOS TLS override hook 2024-02-02 17:59:17 +01:00
Tim Perry 08d4ef8bda Tweak & better document limitations of our iOS TLS validation 2024-02-02 17:59:16 +01:00
Tim Perry 713a628319 Make iOS BoringSSL hook fallback to the real verification callback
This is useful because it means that traffic which bypasses the proxy
(e.g. by using TLS passthrough or similar) will still succeed! This
makes it easier to handle any issues later on.
2024-02-02 17:59:16 +01:00
Tim Perry 140af9b8be Validate the certificate chain (for our CA) when hooking iOS BoringSSL
This is really cool. Rather than just blindly disabling all TLS
validation, we now verify the cert directly against the CA you provide.
We only do extremely basic checks (some more testing required to
validate this provides even basic guarantees) so this shouldn't be
relied for rock-solid TLS validation (probably even after it's been
tested tbh) and it won't handle many real-world cases of CA validation,
but in terms of "do a local MitM while retaining the basics of TLS
protection" it should do a reasonable job, hopefully.
2024-02-02 17:59:16 +01:00
Tim Perry 88016333b5 Parse PEM into raw DER bytes ourselves in pure JS 2024-02-02 17:59:14 +01:00
Tim Perry b5d439a4df Make sure config.js doesn't break in non-Java environments 2024-02-02 17:58:53 +01:00
Tim Perry 4e42ca8ed5 Handle missing get_psk_identity in iOS 2024-02-02 17:58:53 +01:00
Tim Perry 47307a53f3 Add iOS BoringSSL script for full TLS override 2024-02-02 17:58:52 +01:00