Coder Social home page Coder Social logo

culturally / instagram-ios-ssl-pinning-bypass Goto Github PK

View Code? Open in Web Editor NEW
8.0 2.0 1.0 424 KB

iOS Instagram with SSL pinning / certificate pinning bypassed. Latest version 335.0.8

bypass certificate-pinning instagram instagram-api instagram-ios instagram-ssl-pinning intercept ios mitmproxy sniffing

instagram-ios-ssl-pinning-bypass's Introduction

Instagram

Instagram iOS with SSL pinning bypassed / Instagram with certificate pinning bypassed. Get your private api endpoints now!

  • DO NOT NEED JAILBREAK
  • DO NOT NEED FRIDA

Support Me

Bitcoin: bc1qlj6685zpthj6kp5fe7cu47pp80xk0d3tzg650m
Solana: 4a91vFCz8SjnqWiJpFuLWwWFpWdT9dZq13hG4o8icv2n
Litecoin: MFi28zedB78kaNiRpi9eBkFRTtGZNoxcWv

Info

  • Current version which was bypassed: 337.0.2
  • You can now intercept all requests
  • iOS Only
  • Tested on iOS 15.4.1
  • Any support is appreciated

Installation

  1. Download the IPA file
  2. Sideload the file (I personally suggest Sideloadly or TrollStore)
  3. Set up the proxy before starting the app (Was tested only with mitmproxy)
  4. Intercept

Crashing Issue

  • Many people experienced crashing after login this is caused somehow by sideloading you have to sideload it using TrollStore to stop the crashing

Bypassed:

Icon Bundle ID Version File Type Download
com.burbn.instagram 337.0.2 IPA Click here
com.burbn.instagram 335.0.8 IPA Click here
com.burbn.instagram 323.0.3 IPA Click here

Wanna learn how to bypass SSL pinning in apps or Do you have custom request?

Message me on Telegram: @undecryptable

Evidence

What is SSL pinning?

SSL pinning, also known as certificate pinning or public key pinning, is a security mechanism used in digital communication to enhance the security of a connection, particularly within the context of Secure Sockets Layer (SSL) or its successor, Transport Layer Security (TLS).

When a client (such as a web browser or a mobile app) connects to a server over HTTPS, the server presents its SSL/TLS certificate to prove its identity. Normally, the client verifies the server's certificate by checking if it is signed by a trusted Certificate Authority (CA). However, SSL pinning adds an extra layer of security by requiring the client to validate the server's certificate against a known, pre-configured set of certificates or public keys, rather than solely relying on the CA's trust chain.

Disclaimer

This project is for educational purposes only. It demonstrates bypassing SSL pinning in binaries, such as those used by Instagram/Meta, to help developers and researchers understand security vulnerabilities.

There is no intent to harm, exploit, or encourage illegal activities. If Instagram/Meta or any other party has concerns, please contact me at [email protected], and I will address the issue or take down the project as requested.

Use of this project is at your own risk; the creator is not responsible for any misuse.

instagram-ios-ssl-pinning-bypass's People

Contributors

culturally avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar

Forkers

420646826

instagram-ios-ssl-pinning-bypass's Issues

ios 17 and iphone 14 problem

there is a problem on the iPhone 14 pro max with iOS 17 that during the first installation I saw requests before logging in, then the application crashed, after which it only wrote an error, I used Sideloadly and burpsuite

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.