Android Proxy Settings with iptables
A simple technique to redirect Android HTTPS traffic to Burp Suite when the application ignores proxy settings.
Only perform security testing against applications and systems you are authorized to assess.
Introduction
During an Android security assessment, I encountered an application that was ignoring traditional interception methods such as:
System proxy , Wi-Fi proxy configuration , VPN-based interception
The application was using direct sockets and native/custom networking, so the traffic never reached Burp Suite.
Using iptables
To force the traffic through Burp Suite, I used iptables at the kernel networking layer:
iptables -t nat -A OUTPUT \
-p tcp \ --dport 443 \
-j DNAT \
--to-destination <BURP_IP>:8080This redirects outgoing TCP traffic targeting port 443 to the Burp Suite listener.
Important Note
This technique handles traffic redirection, not TLS validation.
This is technique only supported rooted device
If the application uses certificate pinning, you may still need to handle pinning separately before HTTPS traffic can be inspected.
Also keep in mind that this rule targets TCP/443. Applications using QUIC/HTTP3 or other protocols may require a different approach.
Quick Reference
Useful when an Android application bypasses the normal proxy configuration and communicates directly with its backend.
Related Research
Flutter App SSL Pinning Bypass Using ReFlutter
A simple workflow to extract, merge, patch, sign, and install a Flutter APK for security testing.
What is SSL Pinning ?
A practical introduction to analyzing certificate pinning in Android applications.
HTTP Toolkit to Solve the Simcard required application proxy
A simple technique to intercept Android application traffic when the app works only over mobile data and ignores traditional proxy settings.