Setup
Banking Apps
https://markuta.com/magisk-root-detection-banking-apps/ (opens in a new tab)
SSL Unpinning with frida
frida -U -l sslpinning.js — no-paus -f package
Intercepting applcation traffic in Burp
- CPU-Z
- Connect Android device.
- Start Burp and set proxy to listen on all interfaces at 8080.
- Manual proxy in Android's WIFI settings.
- Download the CA certificate from http://burp/ (opens in a new tab).
- Install the certificate in settings.
Bypassing SSL Pinning
- needs root, magisk, lsposed
- Modules -> RootCloak, SSL Pinning Bypass, Trust Me, SSLUnpinning