首页
社区
课程
招聘
[求助]APK HTTPS 如何突破证书锁定
发表于: 2015-2-17 15:31 19299

[求助]APK HTTPS 如何突破证书锁定

2015-2-17 15:31
19299
看了  http://bbs.pediy.com/showthread.php?t=179600

2楼的回复

你可以试试做SSL MITM攻击来分析,对没做证书锁定的软件可以查看到https数据。
工具可以用Burp Suite、Charles或者Fiddler。
如果对这种方法不熟悉,可以搜索这类关键词:<tool name> + SSL/HTTPS + Proxying

btw,对证书锁定的,可以试试重打包改掉pin的指纹。


重打包改pin指纹,具体是怎么操作的?

[培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课

收藏
免费 0
支持
分享
最新回复 (3)
雪    币: 233
活跃值: (285)
能力值: ( LV12,RANK:270 )
在线值:
发帖
回帖
粉丝
2
原来这东西叫“证书锁定”,好高大上的名字。

你只要找到一个样本,查看ssl连接创建部分的代码,就能找到猫腻了。
然后改一个文件即可。

具体细节还是自己动手试试吧,直接说出来就没意思了。
2015-2-17 17:18
0
雪    币: 193
活跃值: (1489)
能力值: ( LV6,RANK:90 )
在线值:
发帖
回帖
粉丝
3
Android-SSL-TrustKiller
This tool leverages Cydia Substrate to hook various methods in order to bypass certificate pinning by accepting any SSL certificate.
f01K9s2c8@1M7s2y4Q4x3@1q4Q4x3V1k6Q4x3V1k6Y4K9i4c8Z5N6h3u0Q4x3X3g2U0L8$3#2Q4x3V1k6A6f1@1g2o6f1r3q4J5N6r3&6W2M7Y4y4Q4x3V1k6m8L8X3c8J5L8$3W2V1i4K6u0V1f1#2y4x3i4K6u0V1g2s2u0#2M7%4c8w2K9h3I4D9k6i4t1`.

JustTrustMe
An xposed module that disables SSL certificate checking. This is useful for auditing an appplication which does certificate pinning.
4deK9s2c8@1M7s2y4Q4x3@1q4Q4x3V1k6Q4x3V1k6Y4K9i4c8Z5N6h3u0Q4x3X3g2U0L8$3#2Q4x3V1k6r3N6i4A6A6L8$3^5J5y4q4)9J5c8V1A6#2M7%4c8f1M7Y4g2K6N6p5#2W2

iOS Application Security Part 36 – Bypassing Certificate Pinning Using SSL Kill Switch
649K9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8X3S2A6k6$3S2S2L8s2c8A6N6s2g2V1k6h3S2S2j5$3E0K6i4K6u0W2j5$3!0E0i4K6u0r3x3U0l9I4y4q4)9J5c8U0p5I4i4K6u0r3x3o6y4Q4x3V1k6A6L8%4y4Q4x3X3c8S2M7s2m8D9K9h3y4S2N6r3W2G2L8W2)9J5k6s2y4W2j5%4g2J5K9i4c8&6i4K6u0V1M7r3q4J5N6q4)9J5k6o6x3$3i4K6u0V1j5Y4W2H3j5i4y4K6K9h3&6Y4i4K6u0V1j5$3g2J5N6r3W2X3K9h3y4S2N6r3g2Q4x3X3c8H3K9h3&6F1K9h3&6Y4i4K6u0V1N6i4y4A6L8X3N6Q4x3X3c8K6M7$3I4Q4x3X3c8C8K9h3I4D9i4K6u0V1M7%4N6A6N6r3y4Z5i4K6u0r3

Automated Man in the Middle Script for Attacking SSL Connections.
f2eK9s2c8@1M7s2y4Q4x3@1q4Q4x3V1k6Q4x3V1k6Y4K9i4c8Z5N6h3u0Q4x3X3g2U0L8$3#2Q4x3V1k6@1P5h3I4W2M7Y4l9&6y4W2)9J5c8W2y4@1j5i4u0@1e0f1W2f1e0b7`.`.

SSL/TLS Interception Proxies and Transitive Trust
493K9s2c8@1M7s2y4Q4x3@1q4Q4x3V1k6Q4x3V1k6%4N6%4N6Q4x3X3g2T1L8r3q4U0K9$3S2S2N6q4)9J5k6h3y4G2L8g2)9J5c8X3S2@1L8h3I4Q4x3V1k6T1K9q4)9J5k6r3g2#2i4K6u0V1x3e0u0Q4x3V1k6T1K9q4)9J5k6r3g2#2i4K6u0V1x3e0u0Q4x3X3c8S2M7X3y4Z5K9i4k6W2M7#2)9J5k6h3S2@1L8h3I4Q4x3U0y4B7j5i4u0E0L8$3x3`.

只能帮你到这里了
2015-2-17 18:55
0
雪    币: 3
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
4
谢谢你,miui系统安装不上Cydia Substrate
2015-2-17 21:38
0
游客
登录 | 注册 方可回帖
返回