OpenSSL, Certpinning and Memory patching. Sounds fun right?
ID: 9f2233ee-b764-510c-a7b3-5bd177f00b60
STIX ID: report--9f2233ee-b764-510c-a7b3-5bd177f00b60
Feed Name: SensePost Blog
This technical blog documents research into bypassing Android certificate pinning by extracting and replacing certificate hashes and experimenting with memory patching of OpenSSL/Conscrypt X509 structures using Frida and an Objection plugin (memunpin). It includes example commands, a Frida script, an Objection plugin workflow, discussion of challenges when replacing full certificates, and lessons learned; it is a research write-up rather than a report of an active security incident.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
