learning-frida icon indicating copy to clipboard operation
learning-frida copied to clipboard

Comments for "Sniffing https traffic on Android 11"

Open nibarius opened this issue 4 years ago • 15 comments

Comments made here will be shown on the "Sniffing https traffic on Android 11" article.

https://nibarius.github.io/learning-frida/2021/01/23/sniffing-https-traffic

nibarius avatar Jan 23 '21 20:01 nibarius

How to make this trick on unroot phone?

wonchoe avatar Dec 08 '21 23:12 wonchoe

To do this on an unrooted phone you have to use a phone with Android 6 or lower. Newer Android versions require root to be able to do this.

nibarius avatar Dec 11 '21 09:12 nibarius

To do this on an unrooted phone you have to use a phone with Android 6 or lower. Newer Android versions require root to be able to do this.

so with a new phones, there are no options like unroot the phone and do all these tricks? Did you try that with a new phones?

wonchoe avatar Dec 11 '21 14:12 wonchoe

I prefer working with emulators when root access is needed so I haven't tried this on a new phone. I'm also not really familiar with how you gain root access modern phones. "Magisk" seems to be a popular option for this, but I don't have any personal experience with it.

nibarius avatar Dec 11 '21 20:12 nibarius

I prefer working with emulators when root access is needed so I haven't tried this on a new phone. I'm also not really familiar with how you gain root access modern phones. "Magisk" seems to be a popular option for this, but I don't have any personal experience with it.

A lot of apps doesn't work with emulator. Will try to root my galaxy s9 on monday. Thanks for expirience!

wonchoe avatar Dec 11 '21 20:12 wonchoe

Hello , after the struggle it works and i can see the certificate on system root , but I am still getting tls error connection on burp :( Can you help me with this?

mizo25 avatar Dec 29 '21 01:12 mizo25

Hi, unfortunately I'm not sure what's wrong for you. My problems were usually with getting the system to recognize the certificate. Once that was in place and I could get the traffic to go trough my burp proxy everything just worked. But when things weren't working for me during setup I started over from scratch and deleted all intermediate certificates to eliminate the risk that I installed the wrong certificate. Once I had the certificate installed I checked that it was visible as a system certificate and then I directly after tried loading https://example.com in a browser to check if it was working. I selected a browser and example.com to be sure I was testing with something that doesn't use certificate pinning.

I'm sorry I can't be of more help, but I hope you can get it working somehow.

nibarius avatar Jan 02 '22 09:01 nibarius

Thanks for the great write up. I was able to install the certificate and see some traffic through Burp but doesn't seem to be all of it (seems actually fairly random, what gets shown in the history and what doesn't. Any clues?

gcorgnet avatar Mar 08 '22 21:03 gcorgnet

Unfortunately not, I haven't run into that myself so I don't have any ideas on what's wrong. But I hope you manage to find a solution.

nibarius avatar Mar 12 '22 14:03 nibarius

@gcorgnet I just wanted to let you know that I stumbled upon an article explaining that apps written using Flutter doesn't use the Android proxy or certificate information, so the normal ways of intercepting traffic can't be used. Maybe this could be the reason for some traffic not showing up for you? https://blog.nviso.eu/2019/08/13/intercepting-traffic-from-android-flutter-applications/

nibarius avatar Apr 14 '22 11:04 nibarius

@nibarius can you make a tutorial showing how to incercept traffic on a .apk that uses SSL pinning?

brunoaduarte avatar Nov 16 '22 04:11 brunoaduarte

How to bypass SSL pinning differs a bit depending on what app it is and how it does the pinning. Do you have any particular app in mind @brunoaduarte and maybe I could write a tutorial for that in case I manage to bypass pinning?

nibarius avatar Nov 16 '22 21:11 nibarius

How to bypass SSL pinning differs a bit depending on what app it is and how it does the pinning. Do you have any particular app in mind @brunoaduarte and maybe I could write a tutorial for that in case I manage to bypass pinning?

yes, whats.app

brunoaduarte avatar Nov 17 '22 19:11 brunoaduarte

Please check out https://nibarius.github.io/learning-frida/2022/11/18/bypassing-pinning @brunoaduarte

nibarius avatar Nov 18 '22 22:11 nibarius

Please check out https://nibarius.github.io/learning-frida/2022/11/18/bypassing-pinning @brunoaduarte

Awesome, thanks!

brunoaduarte avatar Nov 19 '22 05:11 brunoaduarte