hacking: security in practice
Angular app that checks for proxy
Hello, so I have an app that is build with angular (for android). I must say before starting that I am allowed to break into it. So I found the server the app communicates with and it even has a swagger api. The problem is that the webcalls all have an ApiKey in the headers of the request and the app uses https for the webcalls. So I found out you can use something called apk-mitm to use a self-signed certificate to sniff https comunnication using a proxy such as Charles or mitmproxy. The problem I am having is that the app checks if you are using a proxy, and if you are it disables the login of the app. It doesn’t let you do anything. My question is how can I configure android emulator to use the proxy without the app noticing.
Thank you in advance.
submitted by /u/Alternative_Image_87
[link] [comments]
Angular app that checks for proxy
Hello, so I have an app that is build with angular (for android). I must say before starting that I am allowed to break into it. So I found the server the app communicates with and it even has a swagger api. The problem is that the webcalls all have an ApiKey in the headers of the request and the app uses https for the webcalls. So I found out you can use something called apk-mitm to use a self-signed certificate to sniff https comunnication using a proxy such as Charles or mitmproxy. The problem I am having is that the app checks if you are using a proxy, and if you are it disables the login of the app. It doesn’t let you do anything. My question is how can I configure android emulator to use the proxy without the app noticing.
Thank you in advance.
submitted by /u/Alternative_Image_87
[link] [comments]
reddit
Angular app that checks for proxy
Hello, so I have an app that is build with angular (for android). I must say before starting that I am allowed to break into it. So I found the...
How to Harpon Big Blue!
A story about creating backdoors in IBM’s Websphere Portal! This is a feature I’m told…Continue reading on Medium »
Read more...
A story about creating backdoors in IBM’s Websphere Portal! This is a feature I’m told…Continue reading on Medium »
Read more...
A story about creating backdoors in IBM’s Websphere Portal! This is a feature I’m told…Continue reading on Medium » (https://medium.com/@clarkvoss/how-to-harpon-big-blue-c163722638d8?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
TryHackMe - Vulnversity
https://cdn-images-1.medium.com/max/1918/1*zoivXrGlcleb3fA7JRF40w.jpeg
A walkthrough of TryHackMe’s Vulnversity room
Continue reading on Medium »
TryHackMe - Vulnversity
https://cdn-images-1.medium.com/max/1918/1*zoivXrGlcleb3fA7JRF40w.jpeg
A walkthrough of TryHackMe’s Vulnversity room
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
[HTB] Passage HTB Write-up
https://cdn-images-1.medium.com/max/600/1*D1mnmOukHVIzBCAdyubVoQ.png
I always start by doing this Nmap command to see what ports are open on the box:
Continue reading on Medium »
[HTB] Passage HTB Write-up
https://cdn-images-1.medium.com/max/600/1*D1mnmOukHVIzBCAdyubVoQ.png
I always start by doing this Nmap command to see what ports are open on the box:
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
The Podesta Hack
https://cdn-images-1.medium.com/max/2600/0*4qs_mZki0ooBY7pZ
When Russian hackers sent John Podesta, Hillary Clinton’s campaign chairman, a “spearphishing” email — a fake message intended to fool him…
Continue reading on Medium »
The Podesta Hack
https://cdn-images-1.medium.com/max/2600/0*4qs_mZki0ooBY7pZ
When Russian hackers sent John Podesta, Hillary Clinton’s campaign chairman, a “spearphishing” email — a fake message intended to fool him…
Continue reading on Medium »
[Write-Up] Miss Configuration Solopos.com
Udah lama gak posting tentang security lagi dan emang udah jarang post juga sih, kebetulan lagi santai ajah kemarin kemarin mencoba…Continue reading on Medium »
Read more...
Udah lama gak posting tentang security lagi dan emang udah jarang post juga sih, kebetulan lagi santai ajah kemarin kemarin mencoba…Continue reading on Medium »
Read more...
Udah lama gak posting tentang security lagi dan emang udah jarang post juga sih, kebetulan lagi santai ajah kemarin kemarin mencoba…Continue reading on Medium » (https://medium.com/@endangalfarisi/write-up-miss-configuration-solopos-com-fcb1cf884882?source=rss------bug_bounty-5)
Siapa yang gak tau jalantikus.com situs dengan informasi yang menarik untuk di baca seputar teknologi dan tips trik, beberapa hari lalu…Continue reading on Medium » (https://medium.com/@endangalfarisi/write-up-xss-reflected-situs-jalantikus-com-c36c5facd46d?source=rss------bug_bounty-5)
[Write-Up] Suara.com AWS S3 Bucket Misconfiguration
https://medium.com/@endangalfarisi/write-up-suara-com-aws-s3-bucket-misconfiguration-d5650a3e676e?source=rss------bug_bounty-5
https://medium.com/@endangalfarisi/write-up-suara-com-aws-s3-bucket-misconfiguration-d5650a3e676e?source=rss------bug_bounty-5