logo

tip toeing past android 7’s network security configuration

ID: b7512a66-d47d-5097-ab42-802ba873d270

STIX ID: report--b7512a66-d47d-5097-ab42-802ba873d270

Feed Name: SensePost Blog

Date Published: 2018-03-12

Date Updated: 2026-04-29

...
...

Technical guide describing methods to bypass Android 7’s Network Security Configuration and certificate validation to enable HTTPS interception during assessments. It covers enhancing the objection tool to inject a permissive network_security_config via APK repackaging and a runtime Frida hook that overrides TrustManagerImpl.verifyChain to accept untrusted chains, restoring traffic visibility in tools like Burp.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.