Commit Graph
45 Commits
Author SHA1 Message Date
Tim Perry fa12f2010d Migrate to AGPLv3 to align licensing with core HTTP Toolkit projects
This shouldn't significantly affect any normal usage (for Frida
scripts, redistribution _is_ distribution of the source code) but limits
the ability of others to directly turn these scripts into proprietary
closed source products elsewhere.
2023-10-23 16:49:33 +02:00
Tim Perry 50a23a38be Update README and move Android-specific scripts into a subdirectory 2023-10-23 16:48:30 +02:00
Tim Perry 48dee79145 Add an patch against additional check config on native Android OkHttp
This seems to be used internally by some Android TLS connections - note
that this is OkHttp (v2 I think), but vendored into com.android and used
internally, not as a separate module.
2023-10-20 17:28:42 +02:00
Tim Perry 65ca2d4664 Add an Android auto-patching fallback script 2023-10-20 17:23:18 +02:00
Tim Perry 2860d14600 Remove OkHttp <v3 and TrustKit hostname verification patches
Looks like they're actually the same implementation, it's just that
TrustKit inlined OkHttp's version.

These aren't required, as they doesn't implement certificate pinning,
and it's trivial to work around with any functional MitM setup: you
just have to return valid certs with the right hostnames. No need to
mess with that, best to check it properly, so dropped.
2023-10-19 21:51:51 +02:00
Tim Perry 6f6d8cce6f Remove unnecessary webview unpinning patch
WebViews use the system trust successfully, so as soon as you inject
into the default TrustedCertificateIndex, they start trusting the
certificate happily.
2023-10-19 21:47:20 +02:00
Tim Perry f30d5b8c42 Widen & make safer Trustkit, Appcelerator & Appmattus unpinning hooks
Previously, all three allowed _any_ cert - they now delegate to our
pre-configured TrustManager that allows only the one trusted cert
(protecting against a meta-mitm). In addition, Appmattus now covers two
entirely new cases that were missed before (for HttpsUrlConn and manual
TLS validation).
2023-10-19 20:48:46 +02:00
Tim Perry 1c5dcb1d4a Rename & tweak docs of native connect hook 2023-10-18 19:19:44 +02:00
Tim Perry bc70add19c Match native hook logging to the other scripts 2023-10-18 19:16:53 +02:00
Tim Perry 66873783ec Remove unnecessary lax Conscrypt hooks
This is covered more effectively by our injection of our system
certificate into the default trust store for all Conscrypt
implementations via the index.
2023-10-18 19:13:15 +02:00
Tim Perry e91199642d Change native hook to capture all ports by default
Capturing just a few ports makes sense for device-wide capture, but for
targeted interception it makes more sense to intercept absolutely
everything and handle issues separately (or not at all).
2023-10-18 18:37:00 +02:00
Tim Perry ff1882f3d5 Improve debug logging: log activated hooks & more clearly list conns 2023-10-18 18:33:37 +02:00
Tim Perry eaf6075303 Widen CWAC-Netsecurity CertPinManager hook 2023-10-18 18:32:01 +02:00
Tim Perry 6279e6e7a6 Remove overly lax hook on TrustManagerImpl
This isn't required, because our system certificate injection
prepopulates the index used by all trust managers anyway, so they trust
our cert regardless. As configured, the previous hook just trusted _all_
certificates, exposing 3rd party MitM risk - better to keep it strict
for just our certificate where we can.
2023-10-18 18:29:25 +02:00
Tim Perry f9ed941ba5 Add clearer start/stop wrappers around debug output 2023-10-18 18:15:34 +02:00
Tim Perry 99b6adcd5d Remove unnecessary (maybe problematic) setTimeout delays 2023-10-18 18:15:27 +02:00
Tim Perry 7800b44d53 Improve webview interception & unpinning 2023-10-18 17:17:33 +02:00
Tim Perry 1b1dbe7d58 Disable unnecessary AbstractVerifier patch
This only applied to a specific backport of Apache's HttpClient to
Android, from 2014, so this is pretty niche anyway.

Regardless of that, this doesn't actually do cert pinning - it just
disables all normal checks entirely. These scripts are intended to be
used for a working interception setup, so those shouldn't be required.
AbstractVerifier (in every version I can find) doesn't support check for
a specific cert or CA at all.
2023-10-17 16:22:13 +02:00
Tim Perry 385f6368f8 Add patch for Cordova/PhoneGap Advanced HTTP Plugin 2023-10-17 16:20:10 +02:00
Tim Perry e8bb2a160b Simplify & improve hooks for IBM WorkLight 2023-10-17 15:53:48 +02:00
Tim Perry bd9699ee05 Fix hook from PhoneGap sslCertificateChecker plugin 2023-10-17 15:52:52 +02:00
Tim Perry 45c83b1499 Improve log output for easier debugging 2023-10-13 18:24:10 +02:00
Tim Perry 5e094e2e6b Fix lots of errors in unpinning patch application logic 2023-10-13 18:22:50 +02:00
Tim Perry 897bf0f58a Improve CertPinManager unpinning hook 2023-10-13 18:19:25 +02:00
Tim Perry 6d7e711787 Improve TrustManagerImpl patch to trust exactly one cert (not _all_ certs) 2023-10-13 18:18:43 +02:00
Tim Perry 369d66115f Convert all core unpinning patches to a structured declarative format
This notably also adds a NetworkSecurityConfig hook en route, which
disables even reading the pins from the config in the first place.
2023-10-06 13:00:17 +02:00
Tim Perry 0ec1820af8 Add DEBUG_MODE configuration to toggle detailed logging 2023-09-21 19:59:03 +03:00
Tim Perry 6ee3d4ebb1 Centralize config parameters and document the use of each script 2023-09-19 20:40:21 +02:00
Tim Perry 653cb60b9e Manually hook libc connect() to capture even more traffic 2023-09-19 19:43:39 +02:00
Tim Perry 6ba4419e1b Add a script to directly inject one always-trusted cert into Conscrypt
This is a notably different approach to the past certificate unpinning
setup. Through this new mechanism, we trust just one additional
certificate (instead of disabling cert verification entirely) and handle
just the standard Android certificate trust (we'll integrate unpinning
into this later).

This uses a hardcoded cert for now just for testing, but that will of
course be configurable in future.
2023-09-19 11:35:14 +02:00
Tim Perry 179d508e0f Set system proxy properties to catch even more cases 2023-09-15 17:10:33 +02:00
Tim Perry 95705e51f5 Update the readme, to migrate towards a new world of multiple scripts in this repo 2023-09-07 15:29:26 +02:00
Tim Perry f649806244 PoC for working Android proxy redirection
Tried a few different routes, this seems most promising - works fairly
quickly (~100ms, measured from the remote client), and should be
reliable for all plausible implementations of ProxySelector, which
should cover both default & proxy-overriding implementations.

Definitely needs a configurable route (most likely we'll go through
Android properties here, I think? There's a few possiblities) and this
notably doesn't handle Flutter, which ignores all Java's proper APIs for
this (but I think I have some plans for that...)
2023-09-06 19:38:28 +02:00
Tim PerryandGitHub 4d477da8c5 Merge pull request #34 from baltpeter/b_appmattus-checkServerTrusted
Add hook for Appmatus CertificateTransparencyTrustManager.checkServerTrusted
v1.0.0
2023-06-26 11:11:29 +01:00
Benjamin Altpeter feddf62e84 Add hook for Appmatus CertificateTransparencyTrustManager.checkServerTrusted 2023-06-23 14:52:20 +02:00
Tim PerryandGitHub f82daadf7d Merge pull request #23 from Kechinator/main
Add new hook for "Appmatus Certificate Transparency"
2022-08-01 12:31:36 +02:00
HardWorkandGitHub f35078db9b Update frida-script.js 2022-07-31 08:39:57 +02:00
HardWorkandGitHub cfcf8c499d New hook for Appmatus transparency. 2022-07-31 08:38:35 +02:00
Tim PerryandGitHub 0973d25a8a Add HTTP Toolkit links to the README 2022-03-03 17:14:32 +01:00
Tim Perry 91422adeda Add a *dynamic* patch for all code that throws SSL verification errors
This is crazy, but it seems to work! The case in point example here is
Vimeo, which is heavily obfuscated (so we can't reliably match method or
class names) but uses OkHttp internally, which uses the standard
exception types. We can spot those, so we do retrospective patching: the
first time a certificate validation fails, we disable the method that
threw the exception.

We'll still get one initial failure, but after that everything works
nicely. Wild.
2021-11-17 16:54:16 +01:00
Tim Perry b5a1340800 Fix 'unpinning completed' log message 2021-11-17 16:53:36 +01:00
Tim Perry 6c4225692d Fix unpinning of OkHTTP v3
In fact, the CertificatePinner.check() methods all throw if the
certificate is invalid, rather than returning a boolean, in v3
and older versions.
2021-09-22 16:27:27 +02:00
Tim Perry a0c61076f3 Link to the blog post in the README 2021-07-06 17:26:27 +02:00
Tim Perry 8a54e6324f Add the script 2021-07-01 17:17:13 +02:00
Tim PerryandGitHub cb08b55f5d Initial commit 2021-07-01 16:50:56 +02:00