Skip to content

Defeating Cert Pinning

Jmaxxz edited this page Jul 30, 2016 · 15 revisions

Using Hidden Application Mode

The follow steps can be used to bypass the certificate pinning used by the August smartphone app without needing to jailbreak the device.

  1. Open settings
  2. Press and hold the application version number.
  3. Enter "DreadfulDow" in the prompt (case sensitive).
  4. Tap on https://api-production.august.com to change web-service the application will use.
  5. Tap other to specify a custom URL.
  6. Enter url of server you control which can relay requests to August's server. (Both HTTP and HTTPS can be used.)
  7. Monitor to, modify, and otherwise mess with traffic between the app and the August services.