Packet Sniffing and SSL Pinning on an Android Game - Android Q&A, Help & Troubleshooting

Hello XDA forum,
I've tried everything in my knowledge so far, so I've finally decide to come on to this forum as I've completely ran out of idea as to how to move forward with this problem at this point.
I'm not that tech savvy so please excuse my terminologies or any assumptions as I describe the problem as they could be completely wrong.
Background:
Currently I'm playing a game called Fate/Grand Order. This game has many servers, and published by different companies in certain regions. In the beginning I was playing the Global/North American (NA) version of the game, but later I've began exploring different servers.
While playing the CN version of the game, and I was able to successfully packet sniff on this version of the game. The CN version of the game is published by Bilibili and downloaded via their games site (link) as Google (Play) is blocked in China, and its online interactions communicates with the Bilibili server. Whereas the other versions of the game such as NA, JP or KR are downloaded via Google Play.
Since I was able to packet sniff the CN version of the game, it got me curious into packet sniff the other versions of the game (I have tried with NA and JP). However, when I did my proxy software Fiddler was unable to pick up any of the important packets once the game has started.
What I have tried so far:
Initially I did a bit of digging around as to why after "Tunnel to cdn.data.fate-go.jp:443" or "Tunnel to data.fate-go.us:443", no more important packets would show up again.
At first I thought it was me not setting up my Fiddler's cert properly, however I can exclude that possibility for 2 reasons.
The first is that if I hadn't set it properly the first time around, I wouldn't be able to properly see and read the CN's server packets, secondly when I used HTTP Toolkit instead of Fiddler, the same situation is happening.
After bit of research, I was suggested that it could be modern Android Apps utilising SSL Pinning to prevent MITMs and so I've decide to find a way to disable SSL Pinning for the JP and NA version. After installing Frida, launching the Frida server on my device (an Emulator), and using Objection to boot the App and using "android sslpinning disable"
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
the results were still the same, therefore leaving me extremely confused whether I have gotten this all wrong. This lead me to speculate whether I have successfully unpinned the SSL or even if it uses pinned certs. I've tried to install this APK (an SSL Unpinning Demo), but I can't seem to be able to install it on my emulator. I then looked into whether I could manually swap out the pinned certs with my own, but when I opened the game APK in APK Studio there were no certs to be found.
So right now I'm not sure how to tackle this problem further. Maybe someone could explain what this game is doing to protect itself from having its packets read/modified, or if there's any way around it., or maybe I'm just an idiot and probably got my steps wrong somewhere along the way. This is all the info I can provide from the top of my head right now, let me know you need anything else.

I would like to try the same with Smash Legends so I will just leave my reply here hoping someone may know the answer.

I've met the same question now. Do you find any method for fgo.jp sniffing? If so, pls email me at [email protected].

Related

Bubble Witch 2 Facebook connection issue

OK, so I don't know if anyone can help me but let's see. Since I emailed King Support but no reply to my issue. So when I try to play the Bubble Witch 2 game and continue my progress and log on to Facebook through the app. It won't work. says connection failed error. It's the only game I have issues with. Wtf I just want to play the game. Won't connect to Facebook. so I have to restart the game every time I play the game. Anyone have ideas? I am using the Alliance v3 Rom. It was working fine. Just stopped connecting. I even unistalling it. Cleared cache but still a no go. Thanks [emoji27]
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
Killing Aliens with my S5!
No one has any ideas huh? Dam no replies from King Tech support Ether. Bs
Killing Aliens with my S5!
This isn't a gaming forum per se and most people here will have no direct experience with your game. I've never heard of it and don't know why the game would even need a link to a Facebook account anyway? You'd surely get more replies if you searched for the game's support forum or thread.
Or in the alternative a forum catering to game enthusiasts of games similar to this one. I'd urge you to try that as it would be by far your most effective way to get peer to peer support from people who are actually familiar with your game.
You did mention that you'd contacted "King". You didn't explain who that was, but you probably meant the game developer's support. Perhaps try that a second time in case your original request got buried or misdirected. And you might want to see if they have a support forum or IRC channel that might provide more timely replies than email.
As a generic attempt to resolve your game issue.. you said that you tried clearing "the cache". Did you mean the system cache from recovery mode? You should also try wiping the game cache and "data" from the Application manager inside the Settings menu. And failing that, also try uninstalling, then reinstall the game on your phone. Those two things have a reasonable chance of succeeding.
Good luck
.

System notification update Huawei Mobile Services

Hi I recently received a notification about Huawei Mobile Services that open me a browser page with this:
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
Error loading page
hiapp://com.huawei.appmarket?activityName=activityUri|appdetail.activity&params={%22params%22:[{%22name%22:%22uri%22,%22type%22:%22String%22,%22value%22:%22app|C10132067%22}]}&channelId=123412
Received another update that give me this
You can visit the Huawei Community to report this issue. You should get help from there.
Hackolu78 said:
You can visit the Huawei Community to report this issue. You should get help from there.
Click to expand...
Click to collapse
Doesn't look like a problem to me. It's a normal update notification.
Earlier I had huawei. How is it without google support?
Einwod said:
Doesn't look like a problem to me. It's a normal update notification.
Click to expand...
Click to collapse
Oh...ok! Thought you couldn't get around it.
n20661 said:
Earlier I had huawei. How is it without google support?
Click to expand...
Click to collapse
I have Google GMS on my device and it works well. However, without Google services, the device functions quite normally, you just don't have Gmail, Youtube, Maps, Music, Keep, Duo and the other Google apps. Most you can get access through a web browser and they work just fine. Youtube is full of ads anyway. You can download and install YoutubeVanced which is a far better app without all the bull**** that Youtube has. It's the Google "Nerds" that want Google services, but quite honestly, the phone is fine without them, you can learn to live without Google always spying on you. HMS will eventually catch up with GMS and may even become better, who knows. Do not let the lack of Google put you off buying one of the best designed and made mobile phones on the planet. Google is NOT everything. Why do you think they are begging the merican administration for extensions to keep working with Huawei and others that the arsehole Trump deems unsuitable for mericans to deal with?

Must I upgrade to latest Android version to continue receiving security patches?

Hello all, I searched extensively for an answer about this on here and the Android docs but found nothing.
I'm using a Pixel 3AXL that still has security updates thru 03/22(-ish)
Google is trying to beg me to upgrade to Android 12 and I don't want the upgrade. I tested Android 12 while it was in beta and I simply don't like the bubbly interface it's the opposite of what I prefer.
That being said there's no option to refuse the upgrade and continue on with updates for Android 11 until my security end of life occurs...
Anyone know how I can get just security updates on Android 11? Will I need to manual update by "side loading" update files with adb? (or if that's even possible?)
Don't know. Android 12 might as well be malware if it screws up you're device's functionality or usability
Backup all critical data redundantly to at least 2 hdds that are physically and electronically isolated from each other and the PC. Never encrypt data drives and make sure the data is all there, intact and readable. That's your best protection against all that can happen.
In real time use it doesn't seem to matter as long as you're running on Android 9 or higher. It's fairly secure.
This N10+ hasn't been updated in over 2 years and the current load is over 1.5 yo.
Malware hasn't been an issue but I'm careful with what I install, download and back out of or close the browser, sometimes clear the cache if things get sketchy, etc. I hawk the download folder daily. Wifi is locked down as well.
Most malware is downloaded* by the user... and there's no saving dumb bunnies.
*and/or they they fail to detect malware in the download folder such as a trojan preloader. Had one breach the Samsung browser 22 months ago in spite of file settings. Tricky little rascal. It got perished before it could download its payload
Thanks, my greatest concern these days is a fdroid package gone rogue or infiltrated with malware... I suppose the same thing can and sometimes does happen on Googles play store as well. So yeah mostly package manager attacks or supply chain or whatever they're known as.
bladerunnernexus said:
Thanks, my greatest concern these days is a fdroid package gone rogue or infiltrated with malware... I suppose the same thing can and sometimes does happen on Googles play store as well. So yeah mostly package manager attacks or supply chain or whatever they're known as.
Click to expand...
Click to collapse
When side loading scan with online Virustotal.
Scan occasionally with Malwarebytes as it will pick off one every now and then. It found a raskily trojan preloader in the download folder once that snuck in before it could retrieve its payload.
Lol, just because it's on Playstore doesn't mean I trust it. All my apps have been in use for a long time and I don't "sample" apps unless I need too.
It's rare but a poorly written Android app will sometimes do a dirty uninstall and leave you with a mess. My current OS load is over 1.5 yo, still fast and stable. In part because I'm careful what I install.
I firewall block apps that don't need internet access with Karma Firewall.
I also use this setting modification to kill ads globally...
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
Excellent idea. Can some apps hide from karma? I'm using a KeePass compatible open source password manager downloaded from fdroid and it's not listed on my karma firewall apps list.
All my other apps and fdroid apps are listed though...
bladerunnernexus said:
Excellent idea. Can some apps hide from karma? I'm using a KeePass compatible open source password manager downloaded from fdroid and it's not listed on my karma firewall apps list.
All my other apps and fdroid apps are listed though...
Click to expand...
Click to collapse
Nothing can hid from Karma's logging feature that I'm aware of. Problem is that feature is only active on Android 9 and below.
I've use this feature a lot as you can see what accessed the internet and when.
It's "piggybacking" on another Android service be my guess or you just didn't spot it.
Some apks show only as UID numbers.
I use the logging feature to determine their purpose.

Question Microsoft Confirms There's a 'Strange' Problem in Stable Version of Windows 11

{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
Microsoft has confirmed a 'weird' issue in the stable version of Windows 11, some users may not be able to log in after adding a new Microsoft account user to the operating system. The company has shared details about the bug on the official Windows Health Dashboard website and explained how to fix it.
According to Microsoft, users are briefly locked out after the first restart or logout. The issue only appears once and for a short time on devices using Microsoft accounts, while Active Directory domain users and Azure Active Directory accounts remain unaffected. It only occurs on systems running the client version of Windows 11 21H2.
Reporting from Neowin, Thursday (8/9/2022), those who are having problems logging into their accounts on Windows 11 21H2 should not do anything to remedy the situation. The operating system will allow users to log in after a few minutes, plus Microsoft resolved the issue using the Known Issue Rollback system.
The latter automatically undoes problematic changes without any action required from the end user. In case you missed it, Microsoft recently alerted Windows Chile customers about a potential issue due to daylight saving time (Daylight saving time).
The company says users need to manually change their time and date settings to avoid problems with notifications, incorrect system times and other annoyances. Fortunately, this bug does not apply to customers outside of Chile.
Source:
heldean.com
Glad I've not "upgraded" to 11.
Happy with 10 and will stay until 2029, then maybe change to Windows 12 if Microsoft learned their lesson from 11. If not, Linux will be.
PhilipF8_2010 said:
Glad I've not "upgraded" to 11.
Happy with 10 and will stay until 2029, then maybe change to Windows 12 if Microsoft learned their lesson from 11. If not, Linux will be.
Click to expand...
Click to collapse
You do know windows 11 is basically a skin on windows 10.
Android-Desire said:
You do know windows 11 is basically a skin on windows 10.
Click to expand...
Click to collapse
With more restrictions and instability.
PhilipF8_2010 said:
With more restrictions and instability.
Click to expand...
Click to collapse
No, that is cause you think that, the people that think that are not really good on windows or PCs in general.
You got the same system/kernel behind, you got the same apps and you even got more theme options.
Just cause there is some new things does not mean restrictions or instability, i have 16 PCs in my home with different hardware, from AMD only systems to Intel 12gen and Nvidia, even got a few Arm based machines here all running windows 11.
People that say windows 11 is unstable is cause they did not upgrade drivers and or is lying about said instability.
If you don't even try to understand how a computer works then maybe go Apple?`They dont need as much knowledge as windows.

Question Unable to pay after upgrading to android 13!

Hello. I have a problem with phone payments after updating to android 13 in GT2 Pro. Payments stopped working. I checked through google wallet and directly through the bank application. A message appears on the terminal that the card is not supported, card reading error. I've already reset the banking app and cleared the app's memory, but it didn't help. Could the problem occur because I downloaded this system via VPN Germany? If I knew, I wouldn't install this android because I really care about phone payments. I do not know what to do. In Samsung, the matter was easier, among other things, because the Internet is full of Polish forums and Samsung has very good support and such problems were eliminated within a week. I don't even know where to write to get help. I factory reset my phone and it worked for two days and now it stopped working again. Card reading error pops up every time. What else can I do?
After updating to Android 13, I paid for the first time and it works for me so far.
After a factory reset it worked for 2 days. I will add that before the reset it was not working at all. I bought this phone because of payments and here's something. After a factory reset it worked for 2 days. I will add that before the reset it was not working at all. I bought this phone because of payments and here's something.
Thanks for pointing out this issue, I'll keep an eye on it.
I found on the forum:
realme Community
Welcome to realme Community, your virtual playground to learn the latest tech news, win exclusive prizes, or simply chat about realme!
c.realme.com
I saw it too. My play store is certified so the problem lies elsewhere. Sorry for the wording, but I'm using google translate.
Hello everyone. Probably the problem with payments occurs only for people who have additional profiles on their phones, additional users, or a business profile for work. I just had a work profile and payments didn't work. I deleted the profile and everything is ok. But to be honest, I care about payments and the work profile, so I hope that some action will be taken to remove the error. I have no idea why this is happening but then the phone goes stupid and you can't pay. If you have any cloned apps, you may also have a problem. Let me know if I helped you and if the payments started working. Regards
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
Same situation as yours, tried all means (I heard about clone wallet app that will help but I assume the work profile somehow corrupts the nfc payment.)
manage to find an alternative "fix" create a sub account (multi user) and nfc/payment works in that sub account.
I am not using real me, I have an Xperia 10 III and updated to Android 13
I now have the same problem (and yes I have a work profile)

Categories

Resources