Skip to content

Defeating Cert Pinning

Jmaxxz edited this page Jul 15, 2016 · 15 revisions

The follow steps can be used to bypass the certificate pinning used by the August Smart phone app without needing to jailbreak the device.

Using Hidden Application Mode

  1. Open settings
  2. Press and hold the application version number.
  3. Enter "DreadfulDow" in the prompt (case sensitive).
  4. Tap on https://api-production.august.com to change web-service the application will use.
  5. Tap other to specify a custom URL.
  6. Enter url of server you control which can relay requests to August's server. (Both HTTP and HTTPS can be used.)
  7. Monitor to, modify, and otherwise mess with traffic between the app and the August services.