
Android certificate pinning bypass with Frida
A walkthrough of installing the Burp CA on an Android device, running frida-server and using an SSL re-pinning Frida script to intercept traffic from apps that pin certificates.

A walkthrough of installing the Burp CA on an Android device, running frida-server and using an SSL re-pinning Frida script to intercept traffic from apps that pin certificates.

Proxying OS X Spotlight through Burp showed it shipping the user’s latitude and longitude to api.smoot.apple.com on every search, with two ways to block the request.