Four ways to bypass Android SSL. Verification and Certificate Pinning

Mykhailo Antonishyn · Transfer of innovative technologies · 2020

Gone are the days when mobile applications stoically ignore all manners of SSL errors and allow you to intercept and modify their traffic at will. Instead, most modern applications at least check the presented certificate chains to a valid, trusted certificate authority (CA). All pentesters like to convince the app that our certificate is valid and trusted so we can man-in-the-middle (MITM) it and modify its traffic.

Read the paper · More papers on PaperTik