Tim Perry 1b1dbe7d58 Disable unnecessary AbstractVerifier patch
This only applied to a specific backport of Apache's HttpClient to
Android, from 2014, so this is pretty niche anyway.

Regardless of that, this doesn't actually do cert pinning - it just
disables all normal checks entirely. These scripts are intended to be
used for a working interception setup, so those shouldn't be required.
AbstractVerifier (in every version I can find) doesn't support check for
a specific cert or CA at all.
2023-10-17 16:22:13 +02:00
2021-07-01 16:50:56 +02:00

Frida Mobile Interception Scripts

Part of HTTP Toolkit: powerful tools for building, testing & debugging HTTP(S)

This repo contains a selection of Frida scripts that can be used independently, or as a set for interception of HTTP(S) traffic on Android & iOS.

The scripts are:

android-proxy-override.js

A script to override the proxy configuration of a target application, allowing capture of HTTP traffic without changing device settings, using a VPN, or any other techniques.

Note that this only works for plain HTTP - you will also need a method to trust your CA certificate (either device-wide or using another script) if you would like to intercept HTTPS.

android-certificate-unpinning.js

A script to defeat SSL certificate pinning in a target application, by hooking & disabling all commonly known pinning techniques. For more information and detailed setup instructions for unpinning specifically, take a look at https://httptoolkit.com/blog/frida-certificate-pinning/


Each of these scripts can be used with HTTP Toolkit or any other HTTP debugging proxies to capture traffic.

S
Description
Frida scripts to rewrite mobile applications at runtime to directly MitM all HTTPS traffic
Readme AGPL-3.0
2.7 MiB
Languages
JavaScript 70.7%
TypeScript 27.6%
Shell 1.7%