Closed rlaphoenix closed 6 years ago
Probably the data is encrypted. It might use a custom library for encryption, I have to check, but this will not happen too soon, sorry.
Is there a way to find the function it checks if the certificate is valid and instead just override it and return true always? Which would allow me to sniff using Fiddler with a DO_NOT_TRUST Cert
I am not sure about a fully implemented project, maybe Interceptor by Casey Smith. It depends how each application is validating the certificate. Most of the time, the application does not use "SSL Pinning" and it is enough to just install your own root CA.
The Interceptor you mentioned seems to essentially be fiddler. Just I dont have a way to force a CA cert on LoL.
The Root CA (for any intercepting tool) has to be installed in the operating system Root CA Store. This way, the application (LoL) will probably use it and consider the certificate valid.
The Certificate Fiddler provides is a .cer file. This can be used correct?
Doesnt seem to work.
It looks like a bunch of spam
This saved to _WSASend.txt if it matters. is there a way to decrypt this?