SSL Kill Switch 2
Bypass SSL Pinning iOS Applications
Basic setup
On a jailbroken test device:
iPhone
|
+-- Jailbreak
|
+-- Cydia/Sileo/Zebra
|
+-- SSL Kill Switch 2
|
+-- Burp CA certificate
|
+-- Wi-Fi proxy
|
+-- Burp SuiteConfigure Burp
Configure Burp -> Proxy -> Proxy Settings -> Proxy listener -> 0.0.0.0:8080 Make sure your PC and iPhone can commnunicate Find you PC's LAN IP ipconfig find the ip address like this: 192.168.1.10
Configure iPhone proxy
On the iPhone -> Settings -> Wi-FI -> Your Wifi network -> Configure Proxy -> Manual Set: Server : 192.168.1.10 Port: 8080
Install Burp CA
Go to the browser in the iPhone Hit the http://burp Download the CA certificate
Settings -> General -> VPN & Device Management After installing it, there is an additional important step: Settings -> General -> About -> Certificate Trust Settings -> Enable full trust for the Burp CA
Install SSL Kill Switch 2
Install the compatible package for your jailbroken iOS environment. After installation, reboot/respring if required. Then launch the target application. If the application uses networking APIs covered by the tweak: App -> TLS validation -> SSL Kill Switch -> validation bypass -> Burp Now, You should start seeing HTTPS requests in Burp.
You should start seeing HTTPS requests in Burp.
Use these techniques only in applications you are authorized to test.
Use Super Proxy
Try using this VPN app and configure it on the iPhone. It might work.
Why SSL Kill Switch doesn't bypass everything ?
If an application still doesn't appear in Burp after SSL Kill Switch is installed, don't immediately conclude that your proxy configuration is broken. The application might be using:
NSURLSession
CFNetwork
SecureTransportwhich may be covered, but it could instead use:
BoringSSL
OpenSSL
custom TLS implementation
Network.framework
native C/C++
custom certificate validation
certificate/public-key pinningFor example:
Swift/Objective-C
|
v
Custom networking library
|
v
BoringSSL
|
v
TLSSSL Kill Switch may not intercept the application's particular validation path.
Related Research
Static Analysis IPA file
Static Analysis IPA file using strings,
Get the IPA file
Get the IPA file from different resources
HTTP Toolkit to Solve the Simcard required application proxy
A simple technique to intercept Android application traffic when the app works only over mobile data and ignores traditional proxy settings.