ProxymanApp / ProxymanApp/Proxyman

SSL Pinning is globally not working properly on Proxyman

Open
#1,835 3 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

bug
Dominant language
No language data
Stars
7k
Forks
237
PR merge metrics
No merged PRs in 30d

Description

Description

Few times in the past I've reported in the issues of this app that some requests from my jailbroken iPhone, with all the ssl bypass setup done, are mysteriously not being read on Proxyman, having the SSL error. And few weeks ago I switched to burp suite. And on burp suite I've not had once an issue with the requests that are failing to be decrypted on Proxyman.

Steps to Reproduce

The best step to reproduce to be sure is the Madrid identity lookup of FaceTime on iPhones. I guess that you won't have the appropriate stuff at disposition to test it yourself, but I'm writing it anyway.

  1. Get an iPhone 7
  2. Jailbreak it using palera1n and setup fakefs, then boot the phone with palera1n -f
  3. On the iPhone, install SSL Kill Switch 2. Switch it on.

You can follow more precisely on the gist I made here https://gist.github.com/novitae/2f04999039a6012813fb122d35a4c044

  1. Install the root certificate of Proxyman on the iPhone, and also the one of burp suite (I'm on not professional)
  2. Listen and do SSL Proxying on *
  3. Open FaceTime.
  4. Type an email or phone number, and validate.
  5. A request should be sent to query.ess.apple.com. This request is to check if the phone or email is connected to FaceTime, and so, callable.
  6. The request on Proxyman will fail. The request on burp (default settings) will be decrypted.

Current Behavior

Not decrypted.

Expected Behavior

Should've been read.

Environment

  • App version: e.g Proxyman 4.13.0
  • macOS version: e.g macOS Sonoma

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by following the linked gist and the listed iPhone 7 and FaceTime steps, then compare Proxyman's handling of query.ess.apple.com with Burp Suite using the stated certificates and SSL Proxying setup. Confirm the behavior on Proxyman 4.13.0 and macOS Sonoma; done means the request is decrypted in Proxyman rather than failing.

Written by the indexing model from the issue text.

Assessment

Tech stack
ios, macos
Domain
networking, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.