Workflow: SSL Pinning Bypass
Three progressive methods — try in order, escalate only on failure.
Method 1 — Universal Frida bypass
Covers OkHttp, TrustManager, WebView, and Conscrypt pinning.
pid = frida_spawn("com.target.app")
frida_bypass_ssl(pid)Method 2 — Custom app-specific pinner
Identify the pinner class with jadx (search: certificate, pin, ssl, trust), then:
frida_run_script(pid, """
Java.perform(function() {
var CustomPinner = Java.use('com.target.app.security.Pinner');
CustomPinner.verify.implementation = function() {
console.log('[+] Bypassed custom pinner');
return true;
};
});
""")Method 3 — Flutter / native SSL (BoringSSL)
frida_run_script(pid, """
Interceptor.attach(Module.findExportByName("libssl.so", "SSL_CTX_set_custom_verify"), {
onEnter: function(args) {
args[2] = new NativeCallback(function() { return 0; }, 'int', ['pointer', 'pointer']);
}
});
""")Escalation checklist if traffic still fails
- Confirm Burp CA installed into system store (not just user store on Android 7+).
- Check
network_security_config.xmlforcleartextTrafficPermitted=falseand custom trust anchors. - Try
objection -g com.target.app explore→android sslpinning disable. - Embed frida-gadget into APK for persistent injection.
- Hook
pthread_createto evade Frida-thread detection (see anti_tampering_bypass.js).
Verification
Drive a login through the proxy; confirm TLS handshake succeeds and request body appears in Burp.