Tim Perry 91422adeda Add a *dynamic* patch for all code that throws SSL verification errors
This is crazy, but it seems to work! The case in point example here is
Vimeo, which is heavily obfuscated (so we can't reliably match method or
class names) but uses OkHttp internally, which uses the standard
exception types. We can spot those, so we do retrospective patching: the
first time a certificate validation fails, we disable the method that
threw the exception.

We'll still get one initial failure, but after that everything works
nicely. Wild.
2021-11-17 16:54:16 +01:00
2021-07-01 16:50:56 +02:00
2021-07-06 17:26:27 +02:00

frida-android-unpinning

A Frida script to disable SSL certificate pinning in a target application

For more information and detailed setup instructions, take a look at https://httptoolkit.tech/blog/frida-certificate-pinning/

S
Description
Frida scripts to rewrite mobile applications at runtime to directly MitM all HTTPS traffic
Readme AGPL-3.0
2.7 MiB
Languages
JavaScript 70.7%
TypeScript 27.6%
Shell 1.7%