GithubHelp home page GithubHelp logo

android-ssl-trustkiller's Introduction

Android-SSL-TrustKiller

Blackbox tool to bypass SSL certificate pinning for most applications running on a device.

Description

This tool leverages Cydia Substrate to hook various methods in order to bypass certificate pinning by accepting any SSL certificate.

Usage

Notes

Use only on a test devices as anyone on the same network can intercept traffic from a number of applications including Google apps. This extension will soon be integrated into Introspy-Android (https://github.com/iSECPartners/Introspy-Android) in order to allow you to proxy only selected applications.

License

See ./LICENSE.

Authors

Marc Blanchou

android-ssl-trustkiller's People

Contributors

mblanchou avatar nabla-c0d3 avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

android-ssl-trustkiller's Issues

Not working on Nexus 7 4.4

When I try to install, I get the following:

XXXXX:platform-tools xxxxx$ ./adb install /Users/xxxxx/Downloads/Android-SSL-TrustKiller.apk
5262 KB/s (258231 bytes in 0.047s)
java.lang.NoSuchMethodException: getSystemSharedLibraryNames [int]
at java.lang.Class.getConstructorOrMethod(Class.java:472)
at java.lang.Class.getMethod(Class.java:857)
at com.devadvance.rootcloakplus.Main.initForPackageManager(Main.java:45)
at com.devadvance.rootcloakplus.Main.initialize(Main.java:31)
at dalvik.system.NativeStart.main(Native Method)
pkg: /data/local/tmp/Android-SSL-TrustKiller.apk

Cydia is installed and the device was rebooted.

Android 7?

Hello

Any chance to get this tool working with Android 7?

Thanks

No process running

Hi

I have installed the apk and i cant see it running

I assume it needs cydia to start it, isnt it? If so.... cydia doesnt support devices newer than 4.3

Do you have any plan to release a standalone version or compatible with other frameworks, as xposed?

Thanks

what is correct configuration for getting SSL Trustkiller to work?

i have installed fiddler cert on device and was able to intercept HTTPS traffic of google.com via chrome browser with fiddler proxy on windows 10

then i have installed cydia substrate on rooted samsung gt-s7562 with android 4.0.4, linked substrate files. restarted and installed android ssl trustkiller apk.

after that for checking am i doing right with cydia, i have installed winterboard and that was perfectly good.

but for testing :

i was going to intercept my sample app which pinned ssl, but still i couldnt see the traffic.

what is my wrongs?
how exactly your projects works?
specific android version? device?
or only work with google apps?

i'm going to bypass instagram!
is instagram method for ssl pinning the same you working on google apps?

thanks in advance

Lollipop

Any way to make this work on Lollipop ?

Cydia Substrate isn't supported.

Does not do anything?

I have Cydia Substrate installed on my rooted DROID 4 running Android 4.1.2. I installed Android SSL TrustKiller, then linked Substrate files, then restarted my phone. When using Charles Proxy, I continue to only intercept HTTP/HTTPS traffic from apps that don't use SSL Pinning.

Why is this not working?

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.