Closed AmaHacka closed 5 years ago
I also could not capture after patching :(
Yeah same here. Maybe Instagram added pinning in another function of libliger.so file. Also what program did you use to decompile the so file into the code above?
@pokeefer its a screenshot from IDA
same here :(
I've patched libliger.so for version 70.0.0.22.98 but still unable to see traffic Maybe yo have any suggestions how fix it?
Did you find anything?
@S00164379 Nope :(
Is there something?
is there any success?
Selling Instagram 75 version pinning ssl key signed skype: webqart_1
how much?
I think they created a custom ssl pinning in android layer :-\
I think they created a custom ssl pinning in android layer :-\
I solve this problem
this is a open source repository for researchers if you do it just share it publicly
I will create a new patch when I have free time in the next month :-)
@pouyadarabi I agree. Hopefully we can all benefit. Thanks a lot
I think they created a custom ssl pinning in android layer :-\
I solve this problem
this is a open source repository for researchers if you do it just share it publicly
I will create a new patch when I have free time in the next month :-)
There will be no next patch because facebook has fully implemented tls 1.3 in its apps which cannot be decrypted or sniffed, i have spent many hours reversing the 78.0 version and cannot find a solution for tls 1.3
I think they created a custom ssl pinning in android layer :-\
I solve this problem
this is a open source repository for researchers if you do it just share it publicly I will create a new patch when I have free time in the next month :-)
There will be no next patch because facebook has fully implemented tls 1.3 in its apps which cannot be decrypted or sniffed, i have spent many hours reversing the 78.0 version and cannot find a solution for tls 1.3
https://www.imperialviolet.org/2018/03/10/tls13.html
I do wonder which proxies do support TLS 1.3
I've written a step-by-step tutorial on how to circumvent Instagram SSL pinning protection on latest APK (v78): https://plainsec.org/how-to-bypass-instagram-ssl-pinning-on-android-v78
Enjoy!
Super amazing @marco thanks a lot for your very detailed tutorial.
Hi and thanks to @MarcoG3 for the tutorial. Sorry but I'm not familiar at all with Android. is it possible to someone post the patched APK here + if any other file needed?
@MarcoG3 Thanks, but I did everything you did with no success. Still can’t read all requests. here is my patched file: libliger 78.0.0.11.104.zip
Can somebody please upload unsigned instagram apk? Thank. Tried to decode it in 3 days, without luck...
https://github.com/tsarpaul/FBUnpinner Should work for Instagram. Replace lib-xzs/libcoldstart.so with lib-zstd/libliger.so
@RowanFazio @shadowzoom Check out guys, newest version of IG, Facebook and Facebook Messenger contains option that allows you to disable SSL-pinning and use your SSL-certificate to decrypt HTTP-traffic ^_^
@AmaHacka can you show us how to do that?
Has anyone tried Facebook's new method? I can't seem to make them work on my Android. I've enabled all the settings. I've added the IP of my computer as the proxy in the FB App's Proxy Setting and also tried on the wifi settings. but don't get any traffic.
@nemoryoliver Yep, everything works. Try to reproduce all steps from manual carefully and update your FB app.
I've patched libliger.so for version 70.0.0.22.98 but still unable to see traffic Maybe yo have any suggestions how fix it?