I think the pros of open-sourcing this heavily outweigh the cons. You can probably get any job in Silicon Valley if you show how you did the investigative work and hacking here. Great job!
I read your blog post on Hackney and tried to replicate your method on the Ever app. However, despite setting up HTTP Toolkit and properly bypassing the SSL Pinning (which is usually the main hurdle), it's still not working at all.
Given that the tools you presented don't seem to yield any results on the current version of the app, I'm wondering if your article omitted some key steps, or if the app's security has been updated since you wrote it.
Could you clarify how exactly you achieved this? Did you have to deal with additional security layers (like custom request encryption, root detection, or specific Frida scripts) that weren't mentioned in the post?
I think the pros of open-sourcing this heavily outweigh the cons. You can probably get any job in Silicon Valley if you show how you did the investigative work and hacking here. Great job!
please add Cabify!
Hi,
I read your blog post on Hackney and tried to replicate your method on the Ever app. However, despite setting up HTTP Toolkit and properly bypassing the SSL Pinning (which is usually the main hurdle), it's still not working at all.
Given that the tools you presented don't seem to yield any results on the current version of the app, I'm wondering if your article omitted some key steps, or if the app's security has been updated since you wrote it.
Could you clarify how exactly you achieved this? Did you have to deal with additional security layers (like custom request encryption, root detection, or specific Frida scripts) that weren't mentioned in the post?