
Frida scripts to rewrite mobile applications at runtime to directly MitM all HTTPS traffic
Part of HTTP Toolkit: powerful tools for building, testing & debugging HTTP(S)
This repo contains Frida scripts designed to do everything required for fully automated HTTPS MitM interception on mobile devices.
This set of scripts can be used all together, to handle interception, manage certificate trust & disable certificate pinning & transparency checks, for MitM interception of HTTP(S) traffic on Android and iOS, or they can be used and tweaked independently to hook just specific features.
The scripts can automatically handle:
-----BEGIN CERTIFICATE-----. You can open it with a text editor to see and extract this content.config.js, and add those details:
CERT_PEM: your CA certificate in PEM format.PROXY_PORT: the proxy's portPROXY_HOST: the address of your proxy, from the perspective of your device (or use adb reverse tcp:$PORT tcp:$PORT to forward the port over ADB, and use 127.0.0.1 as the host)frida-server from github.com/frida/frida, extract it, adb push it to your device, and then run it with the following 4 commands: adb shell, su, chmod +x /.../frida-server, /.../frida-server.adb devices) before running commands. Note that Frida will only run on the device as root, which is what su provides in the example above, when run on a rooted device. To check you are root after running su or similar, check that running whoami in the shell prints root.tech.httptoolkit.pinning_demo)config.js). Which scripts to use is up to you, but for Android a good command to start with is:
frida -U \
-l ./config.js \
-l ./native-connect-hook.js \
-l ./native-tls-hook.js \
-l ./android/android-proxy-override.js \
-l ./android/android-system-certificate-injection.js \
-l ./android/android-certificate-unpinning.js \
-l ./android/android-certificate-unpinning-fallback.js \
-l ./android/android-disable-root-detection.js \
-f $PACKAGE_ID