Discussion about this post

User's avatar
sneakersaddict's avatar

Hi,

I read your blog post on Hackney and tried to replicate your method on the Ever app. However, despite setting up HTTP Toolkit and properly bypassing the SSL Pinning (which is usually the main hurdle), it's still not working at all.

Given that the tools you presented don't seem to yield any results on the current version of the app, I'm wondering if your article omitted some key steps, or if the app's security has been updated since you wrote it.

Could you clarify how exactly you achieved this? Did you have to deal with additional security layers (like custom request encryption, root detection, or specific Frida scripts) that weren't mentioned in the post?

Ready for more?