Commit Graph
14 Commits
Author SHA1 Message Date
Tim Perry 535b5a1c8c Wait for libnetwork on iOS in case to make connect script more reliable
This notably applied in simulator testing, but presumably could also be
required on devices in some real scenarios too.
2026-08-27 18:18:55 +01:00
Tim Perry aacc1579cb Update native TLS & iOS hooks to Frida 17 too 2025-06-20 16:59:52 +02:00
Tim Perry 185e91f62d Add a script to disable iOS jailbreak detection (WIP) 2024-07-16 18:18:29 +02:00
Tim Perry b96aac3d0a Avoid needless reallocation of host & port strings on iOS
This is also extremely likely a memory leak since we're never cleaning
these up - best to avoid that!
2024-06-12 12:40:36 +02:00
Tim Perry a1223136cd Extend iOS BoringSSL hook to hook BoringSSL in other cases too
This notably affects TikTok, but will also apply for any bundled use of
BoringSSL within apps elsewhere. This is now recommended for all Android
& iOS usage.

Note the per-lib difference at the start of the hooked callback - it
seems we may need to customize whether the callback is proactively
called for some individual cases, and that might need extending in
future.
2024-03-05 15:46:41 +01:00
Tim Perry a3ff3914a8 Update incomplete comment in iOS TLS script 2024-02-02 18:29:23 +01:00
Tim Perry 6136e1ac6e Document iOS scripts & interception setup 2024-02-02 18:25:08 +01:00
Tim Perry a1a80cb63b Update the comments documenting our new iOS TLS override hook 2024-02-02 17:59:17 +01:00
Tim Perry 08d4ef8bda Tweak & better document limitations of our iOS TLS validation 2024-02-02 17:59:16 +01:00
Tim Perry 713a628319 Make iOS BoringSSL hook fallback to the real verification callback
This is useful because it means that traffic which bypasses the proxy
(e.g. by using TLS passthrough or similar) will still succeed! This
makes it easier to handle any issues later on.
2024-02-02 17:59:16 +01:00
Tim Perry 140af9b8be Validate the certificate chain (for our CA) when hooking iOS BoringSSL
This is really cool. Rather than just blindly disabling all TLS
validation, we now verify the cert directly against the CA you provide.
We only do extremely basic checks (some more testing required to
validate this provides even basic guarantees) so this shouldn't be
relied for rock-solid TLS validation (probably even after it's been
tested tbh) and it won't handle many real-world cases of CA validation,
but in terms of "do a local MitM while retaining the basics of TLS
protection" it should do a reasonable job, hopefully.
2024-02-02 17:59:16 +01:00
Tim Perry 4e42ca8ed5 Handle missing get_psk_identity in iOS 2024-02-02 17:58:53 +01:00
Tim Perry 47307a53f3 Add iOS BoringSSL script for full TLS override 2024-02-02 17:58:52 +01:00
Tim Perry ab38296bb1 Add an iOS low-level hook for Network Framework 2024-02-02 17:58:52 +01:00