HTTP Toolkit to Solve the Simcard required application proxy
A simple technique to intercept Android application traffic when the app works only over mobile data and ignores traditional proxy settings.
Only perform security testing against applications and devices you are authorized to assess.
Introduction
During a recent Android security assessment, I encountered an interesting networking challenge.
The application:
- Required a valid SIM card.
- Worked only over mobile data.
- Refused to communicate over Wi-Fi.
- Did not send any traffic to Burp Suite, even with a manual proxy configured.
I tried several approaches:
- USB tethering
- Hotspot sharing
adb reverseiptables- VPN interception
- Packet capture apps
- Router-based MITM
None of them worked.
Using HTTP Toolkit Over ADB
After trying multiple approaches, I came across HTTP Toolkit's Android over ADB feature.
The setup was simple:
- Insert a valid SIM card and enable mobile data.
- Connect the Android device to the PC using ADB.
- Open HTTP Toolkit.
- Pair the device using the QR code provided by HTTP Toolkit.
- Launch the application.
- Start capturing the application's traffic.
The application continued using its mobile data connection while HTTP Toolkit intercepted the traffic through the ADB connection.
Result
This worked for the application and allowed me to capture its HTTP/HTTPS requests without relying on Wi-Fi proxy configuration.
Related Research
Extract and Install Split APK from Android Device
A simple guide to extracting split APK files from an Android device and reinstalling them using ADB.
Flutter App SSL Pinning Bypass Using ReFlutter
A simple workflow to extract, merge, patch, sign, and install a Flutter APK for security testing.
Android Proxy Settings with iptables
A simple technique to redirect Android HTTPS traffic to Burp Suite when the application ignores proxy settings.