Tim Perry 66873783ec Remove unnecessary lax Conscrypt hooks
This is covered more effectively by our injection of our system
certificate into the default trust store for all Conscrypt
implementations via the index.
2023-10-18 19:13:15 +02:00
2021-07-01 16:50:56 +02:00

Frida Mobile Interception Scripts

Part of HTTP Toolkit: powerful tools for building, testing & debugging HTTP(S)

This repo contains a selection of Frida scripts that can be used independently, or as a set for interception of HTTP(S) traffic on Android & iOS.

The scripts are:

android-proxy-override.js

A script to override the proxy configuration of a target application, allowing capture of HTTP traffic without changing device settings, using a VPN, or any other techniques.

Note that this only works for plain HTTP - you will also need a method to trust your CA certificate (either device-wide or using another script) if you would like to intercept HTTPS.

android-certificate-unpinning.js

A script to defeat SSL certificate pinning in a target application, by hooking & disabling all commonly known pinning techniques. For more information and detailed setup instructions for unpinning specifically, take a look at https://httptoolkit.com/blog/frida-certificate-pinning/


Each of these scripts can be used with HTTP Toolkit or any other HTTP debugging proxies to capture traffic.

S
Description
Frida scripts to rewrite mobile applications at runtime to directly MitM all HTTPS traffic
Readme AGPL-3.0
2.6 MiB
Languages
JavaScript 70.7%
TypeScript 27.6%
Shell 1.7%