daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

make-apk-accept-ca-certificate.md (3491B)


      1 ---
      2 title: "Make an APK Trust a User CA Certificate"
      3 section: "Mobile"
      4 sectionSlug: "mobile-pentesting"
      5 sourcePath: "src/mobile-pentesting/android-app-pentesting/make-apk-accept-ca-certificate.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/mobile-pentesting/android-app-pentesting/make-apk-accept-ca-certificate.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Make an APK Trust a User CA Certificate
     14 
     15 Android applications can restrict which certificate authorities they trust. In an authorized test environment, repackaging an APK with a Network Security Configuration that trusts user-installed CAs can make HTTPS traffic inspection possible. This does not automatically bypass certificate pinning implemented elsewhere in the application.<sup>[[1]](#references)</sup>
     16 
     17 ## Automatic
     18 
     19 [`apk-mitm`](https://github.com/shroudedcode/apk-mitm) automates APK patching for HTTPS inspection and includes patches for several common certificate-pinning implementations.<sup>[[2]](#references)</sup>
     20 
     21 ## Manual
     22 
     23 Decompile the APK:
     24 
     25 ```bash
     26 apktool d app.apk
     27 ```
     28 
     29 ![Decompiling an APK with apktool](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/img9.png)
     30 
     31 In `AndroidManifest.xml`, add the following attribute to the `<application>` element if it is not already set:<sup>[[1]](#references)</sup>
     32 
     33 `android:networkSecurityConfig="@xml/network_security_config"`
     34 
     35 Before adding:
     36 
     37 ![Android manifest before adding the network security configuration](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/img10.png)
     38 
     39 After adding:
     40 
     41 ![Android manifest after adding the network security configuration](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/img11.png)
     42 
     43 Create or update `res/xml/network_security_config.xml` with the following content. The `system` source keeps the preinstalled trust anchors, while `user` adds user-installed CAs:<sup>[[1]](#references)</sup>
     44 
     45 ```html
     46 <network-security-config>
     47     <base-config>
     48         <trust-anchors>
     49             <!-- Trust preinstalled CAs -->
     50             <certificates src="https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/mobile-pentesting/android-app-pentesting/system" />
     51             <!-- Additionally trust user-added CAs -->
     52             <certificates src="https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/mobile-pentesting/android-app-pentesting/user" />
     53         </trust-anchors>
     54     </base-config>
     55 </network-security-config>
     56 ```
     57 
     58 Rebuild the APK:
     59 
     60 ```bash
     61 apktool b app -o patched.apk
     62 ```
     63 
     64 ![Rebuilding the patched APK with apktool](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/img12.png)
     65 
     66 Repackaging invalidates the original signature, so sign the rebuilt APK before installing it. [See the APK signing section](/hacktricks/mobile-pentesting/android-app-pentesting/smali-changes#sign-the-new-apk).
     67 
     68 ## References
     69 
     70 - [1] [Android Developers - Network Security Configuration](https://developer.android.com/privacy-and-security/security-config)
     71 - [2] [apk-mitm - Prepare Android APK files for HTTPS inspection](https://github.com/shroudedcode/apk-mitm)