Training
/
Masterclass
/
React Native

Bypassing SSL Certificate Pinning

3
min read
Payatu Research Team
Beginner
Four people working with laptops around a futuristic transparent table at sunset, with an illuminated blue atom-like digital graphic and floating lines of code in the background.

In the last blog of the React Native Pentesting for Android Masterclass, we covered understanding the Hermes bytecode. Let’s move forward!

What is SSL certificate pinning?

You might already be aware of SSL certificate pinning in the Android application. In short, SSL certificate pinning is a process of associating a host with its expected X509 certificate or public key.
In certificate pinning, the application is configured to accept only the certificate of a specific domain instead of any trusted CA root certificate in the device (such as the PortSwigger CA certificate)

Diagram illustrating SSL Pinning: a legitimate SSL certificate with a checkmark passes from a server to a trusted root CA list on a smartphone, while a bad SSL certificate with a red cross is blocked.

Bypassing certificate pinning with Frida

Frida by codeshare is the go-to tool for bypassing the certificate pinning in runtime. The famous “Universal Android SSL Pinning bypass script” also works great with React Native applications.

You can refer to the article below to perform a pinning bypass like a normal Android application: “Hail Frida!! The Universal SSL pinning bypass for Android applications“

But..

What if, due to any circumstances, we cannot dynamically hook the application and bypass certificate pinning, or do we want to bypass the certificate pinning permanently?

Manually Patching React Native application to bypass certificate pinning.

The most used technique to implement certificate pinning in React Native applications is by utilizing the “react-native-ssl-pinning” node module. The major disadvantage (perhaps an advantage for us

) of certificate pinning in React Native applications is the pinned certificate can be found in the “/assets” folder of the application. Hence, the attacker’s control over this certificate completely demolishes the certificate pinning implementation.

Steps:

  1. Change the extension of the .apk file to .zip and open the zip file using any compression tool such as WinRAR or 7zip.
  1. Go to the “/assets” folder and note the name of .cer certificates.
Screenshot of a zip archive named VulnerableApp.apk.zip opened in a file compression program showing two items: a folder named index.android.bundle and a security certificate file named reqres.cer, with details like size, packed size, modification date, and CRC32.

3. Delete all “.cer” certificates from the “/assets” folder.

4. Now configure BurpSuite with an Android device and generate a .der certificate from BurpSuite.

Screenshot of Burp Suite Professional interface showing the Proxy tab with the Proxy Listeners section displaying a running listener on interface 127.0.0.1:8080. The Import/export CA certificate button is highlighted. A CA Certificate export/import dialog box is open on top, with the 'Certificate in DER format' option selected under Export and the Next button visible.

5. Change the certificate extension from “.cer” to “.der” and Rename the newly generated “.cer” certificate from BurpSuite with the name copied in step 2.

File explorer window showing three files: VulnerableApp.apk.zip, reqres.cer highlighted with a red box, and loki.keystore.

6. Paste these new certificates in the “/assets” folder.

Screenshot of a ZIP archive named VulnerableApp.apk.zip opened in a file extracting program showing the contents of the assets folder, including index.android.bundle and a security certificate file named reqres.cer.

7. Delete files in META-INF and sign APK as instructed earlier.

Screenshot of a terminal window showing the use of the jarsigner command with verbose output and SHA1 signature to sign an APK file named VulnerableApp.apk using loki.keystore, followed by a list of signing actions for various META-INF Android manifest and metadata files.

8. Install the application and intercept the encrypted HTTP traffic.

Screenshot of Burp Suite Professional capturing HTTP GET requests to the API endpoint /api/users on host reqres.in, showing request headers including User-Agent and Response with JSON data of user information including emails and avatars, highlighted with red and blue boxes; alongside a mobile device display showing parsed fetched data with user details in JSON format on a demo app.

It is now time to learn how to identify manually installed npm packages and the different types of npm packages in React Native applications. We will learn this in our next blog.

Till then, keep pentesting!