top of page
mascon-icon.png
mascon.png

Benjamin Faller

Security Tester
greg-fawson-foto.1024x1024 Kopie.jpg

After graduating with a Bachelor of Science in Applied Computer Science from HTWG Konstanz in 2022 I chose to pursue my career in information security. Currently, I work at Redguard as a Security Tester analyzing various applications and infrastructure for security vulnerabilities.

It Finally Works (Mostly): Rewiring Mobile App Network Interception

During mobile app penetration tests, assessing app backend APIs is a crucial step that necessitates interception of app network traffic. Testers typically rely on techniques like API hooking, proxy interception, or connecting via a Machine-in-the-Middle (MitM) Wi-Fi access point.

But not all techniques are equal. Some require specialized hardware, while others are highly situational. We are looking at you, flutter app on a non-jailbroken Android device ;)

In this lightning talk we give an overview of the current state of network interception during mobile app penetration tests, common pitfalls, and limitations.

We then present a simple, custom VPN-based solution which attempts to overcome these challenges for most Android and iOS apps.

bottom of page