TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Bypassing OpenSSL Certificate Pinning in iOS Apps

32 点作者 silenteh超过 10 年前

3 条评论

sjtgraham超过 10 年前
I don't even attempt to circumvent SSL pinning. IMO it's easier and safer to use Cydia substrate to decorate the networking classes to print args and return values to the console. I've reversed a few APIs in this way, including a bank's.
评论 #8853230 未加载
jrochkind1超过 10 年前
&gt; From a penetration testing perspective, this may cause practical problems<p>I was super confused what they were talking about, until I remembered that &quot;penetration testing&quot; really just means &quot;penetration&quot;, not &quot;testing&quot;, it&#x27;s just a euphemism for &quot;attacking&quot;. I think?
评论 #8853071 未加载
评论 #8854008 未加载
mwcampbell超过 10 年前
Wouldn&#x27;t it be much harder to patch the binary if it were stripped? Is it not common to strip release builds of iOS apps?
评论 #8853585 未加载