logo

OpenSSL, Certpinning and Memory patching. Sounds fun right?

ID: 9f2233ee-b764-510c-a7b3-5bd177f00b60

STIX ID: report--9f2233ee-b764-510c-a7b3-5bd177f00b60

Feed Name: SensePost Blog

Date Published: 2026-04-01

Date Updated: 2026-05-11

...
...

This technical blog documents research into bypassing Android certificate pinning by extracting and replacing certificate hashes and experimenting with memory patching of OpenSSL/Conscrypt X509 structures using Frida and an Objection plugin (memunpin). It includes example commands, a Frida script, an Objection plugin workflow, discussion of challenges when replacing full certificates, and lessons learned; it is a research write-up rather than a report of an active security incident.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.