ProxymanApp / ProxymanApp/Proxyman
SSL Pinning is globally not working properly on Proxyman
Nobody has claimed this yet.
- Dominant language
- No language data
- Stars
- 7k
- Forks
- 237
- PR merge metrics
- No merged PRs in 30d
Description
Description
Few times in the past I've reported in the issues of this app that some requests from my jailbroken iPhone, with all the ssl bypass setup done, are mysteriously not being read on Proxyman, having the SSL error. And few weeks ago I switched to burp suite. And on burp suite I've not had once an issue with the requests that are failing to be decrypted on Proxyman.
Steps to Reproduce
The best step to reproduce to be sure is the Madrid identity lookup of FaceTime on iPhones. I guess that you won't have the appropriate stuff at disposition to test it yourself, but I'm writing it anyway.
- Get an iPhone 7
- Jailbreak it using palera1n and setup fakefs, then boot the phone with
palera1n -f - On the iPhone, install SSL Kill Switch 2. Switch it on.
You can follow more precisely on the gist I made here https://gist.github.com/novitae/2f04999039a6012813fb122d35a4c044
- Install the root certificate of Proxyman on the iPhone, and also the one of burp suite (I'm on not professional)
- Listen and do SSL Proxying on
* - Open FaceTime.
- Type an email or phone number, and validate.
- A request should be sent to
query.ess.apple.com. This request is to check if the phone or email is connected to FaceTime, and so, callable. - The request on Proxyman will fail. The request on burp (default settings) will be decrypted.
Current Behavior
Not decrypted.
Expected Behavior
Should've been read.
Environment
- App version: e.g Proxyman 4.13.0
- macOS version: e.g macOS Sonoma
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by following the linked gist and the listed iPhone 7 and FaceTime steps, then compare Proxyman's handling of query.ess.apple.com with Burp Suite using the stated certificates and SSL Proxying setup. Confirm the behavior on Proxyman 4.13.0 and macOS Sonoma; done means the request is decrypted in Proxyman rather than failing.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- ios, macos
- Domain
- networking, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 30/100