mirror of
https://github.com/httptoolkit/frida-interception-and-unpinning.git
synced 2026-10-11 02:12:26 +02:00
91422adeda7982e32d761e7efe6ac95286eb8254
This is crazy, but it seems to work! The case in point example here is Vimeo, which is heavily obfuscated (so we can't reliably match method or class names) but uses OkHttp internally, which uses the standard exception types. We can spot those, so we do retrospective patching: the first time a certificate validation fails, we disable the method that threw the exception. We'll still get one initial failure, but after that everything works nicely. Wild.
frida-android-unpinning
A Frida script to disable SSL certificate pinning in a target application
For more information and detailed setup instructions, take a look at https://httptoolkit.tech/blog/frida-certificate-pinning/
Languages
JavaScript
70.7%
TypeScript
27.6%
Shell
1.7%