Skip to content

Defeating Cert Pinning

Jmaxxz edited this page Jul 13, 2016 · 15 revisions

The follow steps can be used to bypass the certificate pinning used by the August Smart phone app without needing to jailbreak the device.

  1. Open settings
  2. Press and hold the application version number.
  3. Enter "DreadfulDow" in the prompt. The prompt is case sensitive.
  4. Tap on https://api-production.august.com to change webservice the application will use.
  5. Tap other to specify a custom url.
  6. Enter url of server you control which can relay requests to August's server. (Both HTTP and HTTPS can be used.)
  7. Monitor to, modify, and otherwise mess with traffic between the app and the August services.