Commit Graph
94 Commits
Author SHA1 Message Date
Tim Perry b96aac3d0a Avoid needless reallocation of host & port strings on iOS
This is also extremely likely a memory leak since we're never cleaning
these up - best to avoid that!
2024-06-12 12:40:36 +02:00
Tim Perry b0387881c9 Update IP testing script to signal just once, for the first good IP 2024-06-03 19:24:14 +02:00
Tim Perry a7f9bf4dc3 Add IP connectivity test script 2024-05-31 09:31:42 +01:00
Tim Perry 0499961831 Move native module detection into a reusable method 2024-03-05 17:49:06 +01:00
Tim Perry 9731e4bc52 Hook native Android OpenSSL too 2024-03-05 17:08:23 +01:00
Tim Perry a1223136cd Extend iOS BoringSSL hook to hook BoringSSL in other cases too
This notably affects TikTok, but will also apply for any bundled use of
BoringSSL within apps elsewhere. This is now recommended for all Android
& iOS usage.

Note the per-lib difference at the start of the hooked callback - it
seems we may need to customize whether the callback is proactively
called for some individual cases, and that might need extending in
future.
2024-03-05 15:46:41 +01:00
Tim Perry b5206370fb Make IPv4-mapped IPv6 addresses more readable in native-connect-hook
Useful as these can require manual intervention & redirection later,
which is tricky when you can't easily read the IP involved.
2024-02-21 14:02:45 +01:00
Tim Perry a3ff3914a8 Update incomplete comment in iOS TLS script 2024-02-02 18:29:23 +01:00
Tim Perry 6136e1ac6e Document iOS scripts & interception setup 2024-02-02 18:25:08 +01:00
Tim Perry a1a80cb63b Update the comments documenting our new iOS TLS override hook 2024-02-02 17:59:17 +01:00
Tim Perry 08d4ef8bda Tweak & better document limitations of our iOS TLS validation 2024-02-02 17:59:16 +01:00
Tim Perry 713a628319 Make iOS BoringSSL hook fallback to the real verification callback
This is useful because it means that traffic which bypasses the proxy
(e.g. by using TLS passthrough or similar) will still succeed! This
makes it easier to handle any issues later on.
2024-02-02 17:59:16 +01:00
Tim Perry 140af9b8be Validate the certificate chain (for our CA) when hooking iOS BoringSSL
This is really cool. Rather than just blindly disabling all TLS
validation, we now verify the cert directly against the CA you provide.
We only do extremely basic checks (some more testing required to
validate this provides even basic guarantees) so this shouldn't be
relied for rock-solid TLS validation (probably even after it's been
tested tbh) and it won't handle many real-world cases of CA validation,
but in terms of "do a local MitM while retaining the basics of TLS
protection" it should do a reasonable job, hopefully.
2024-02-02 17:59:16 +01:00
Tim Perry 88016333b5 Parse PEM into raw DER bytes ourselves in pure JS 2024-02-02 17:59:14 +01:00
Tim Perry b5d439a4df Make sure config.js doesn't break in non-Java environments 2024-02-02 17:58:53 +01:00
Tim Perry 4e42ca8ed5 Handle missing get_psk_identity in iOS 2024-02-02 17:58:53 +01:00
Tim Perry 47307a53f3 Add iOS BoringSSL script for full TLS override 2024-02-02 17:58:52 +01:00
Tim Perry ab38296bb1 Add an iOS low-level hook for Network Framework 2024-02-02 17:58:52 +01:00
Tim PerryandGitHub 8cfe27b746 Merge pull request #69 from AlexPaiva/updated-readme
Updated ReadMe file for better understanding
2024-01-24 17:31:41 +01:00
Tim Perry 6e99adad29 Format extra README details a little for clarity 2024-01-24 17:08:08 +01:00
Alexandre Paiva 5ca233985b Updated ReadMe file for better understanding 2024-01-23 13:59:38 +00:00
Tim PerryandGitHub d081776d1f Update README to explain where to find HTTP Toolkit's CA & proxy details 2024-01-23 14:16:48 +01:00
Tim PerryandGitHub 64fc7d443a Note dependency between Android unpinning scripts in the README 2024-01-09 12:02:35 +01:00
Tim PerryandGitHub c58b0b9d76 Merge pull request #64 from Anon-Exploiter/patch-1
Word correction - Update config.js
2024-01-02 11:02:23 +01:00
Syed Umar ArfeenandGitHub 0e47a3779b Update config.js 2023-12-12 14:05:09 +11:00
Tim Perry 78fa288d46 Revert "Always loudly log intercepted connections that fail to reach the proxy"
This reverts commit 6eec741f5c.

This doensn't actually work correctly, as connect() will return -1
(treated here as failure) for sockets that are still in progress, when
opened non-blocking, and therefore we end up logging these as failures.
We need to handle async connection state detection - that's a bit fiddly
from inside Frida, so for now let's just roll this back.
2023-11-15 18:39:51 +01:00
Tim Perry 6eec741f5c Always loudly log intercepted connections that fail to reach the proxy 2023-11-14 10:26:59 +01:00
Tim Perry 90ebd192d7 More closely match fallback log output to other scripts
Previously it wasn't clear that the "[+] ..." message was another setup
script confirmation - it could easily be interpreted as some kind of
error.
2023-11-14 09:44:16 +01:00
Tim Perry 4a492973c3 Log actual details of unexpected TLS errors 2023-11-14 09:41:34 +01:00
Tim Perry de4493d1f7 Disable hostname verification for our CA certificate only
We previously left this in, since it's generally better to follow TLS
rules, but there's one case where it matters: when a client sends a
request without using SNI, and so the proxy may not show the right
certificate. We want to allow that, and to do so we need to ensure that
hostname checks are skipped (but only for our CA - not for any others,
which must still follow normal TLS rules).
2023-11-13 22:47:25 +01:00
Tim Perry 15869c6a7c Improve logging and error handling in Android cert injection 2023-11-10 14:12:22 +01:00
Tim Perry 61cb054e16 Handle non-message arguments in fallback script 2023-11-08 18:59:12 +01:00
Tim Perry 4cb2d44f6c Use targetMethod.call(this...) over this.[method](...)
This avoids the potential for bugs (calling the method directly does
dynamic lookup based on argument types, which may not match the called
method in ambiguous cases, e.g. int vs double are indistinguishable in
JS) and improves performance (skipping any dynamic method lookup).
2023-11-08 14:26:19 +01:00
Tim Perry dbbe864b35 Make the config structure a little clearer & easier to use 2023-11-08 13:48:37 +01:00
Tim Perry 676627d01f Handle the signature of built-in okhttp.Address in Android Nougat 2023-11-07 18:21:32 +01:00
Tim Perry 05d9b8ab44 Add more details about the multi-script structure & usage to the README 2023-11-03 19:11:39 +00:00
Tim PerryandGitHub ac328e719c Fix NLnet casing 2023-10-30 16:29:08 +01:00
Tim PerryandGitHub 4b7a49fb8a Tweak NLNet badge 2023-10-30 14:55:42 +01:00
Tim PerryandGitHub fae8b6024b Add NLNet funding details & badge to the README 2023-10-30 14:37:49 +01:00
Tim Perry 025ec5cc6c Add missing SPDX info to native-connect-hook 2023-10-24 18:08:46 +02:00
Tim Perry 996a76127e Update outdated CI step 2023-10-23 18:53:25 +02:00
Tim Perry 9fd6dfd249 Fix CI output artifact name 2023-10-23 18:45:56 +02:00
Tim Perry f3dff0bd63 Clear the certificate data, and add a helpful missing-config check 2023-10-23 18:43:53 +02:00
Tim Perry d88d6ef87a Add a nice blurb to script releases 2023-10-23 18:37:33 +02:00
Tim Perry f6fef5a46a Automatically publish pre-concatenated scripts for easy usage 2023-10-23 18:36:53 +02:00
Tim Perry 88d3796893 Leave a placeholder frida-script.js script to avoid broken URLs 2023-10-23 18:10:10 +02:00
Tim Perry 91d693f22d Tweak the README further 2023-10-23 17:53:02 +02:00
Tim Perry ae11390aee Add source & license info to script header comment 2023-10-23 17:49:41 +02:00
Tim Perry e126af2902 Expand and polish up the per-script documentation 2023-10-23 17:43:40 +02:00
Tim Perry fa12f2010d Migrate to AGPLv3 to align licensing with core HTTP Toolkit projects
This shouldn't significantly affect any normal usage (for Frida
scripts, redistribution _is_ distribution of the source code) but limits
the ability of others to directly turn these scripts into proprietary
closed source products elsewhere.
2023-10-23 16:49:33 +02:00