Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Firebase & X-Android-Cert #295

Open
tcmaps opened this issue May 31, 2024 · 1 comment
Open

Firebase & X-Android-Cert #295

tcmaps opened this issue May 31, 2024 · 1 comment

Comments

@tcmaps
Copy link

tcmaps commented May 31, 2024

A modified and resigned apk will usually not be able to access Firebase Auth and other APIs that are bound to the original SHA1. Though it's possible to modify the header with an intercepting proxy like Burp, having the option to hook the signature check directly would be preferable. Can this toolkit take care of that already?

@jayluxferro
Copy link
Collaborator

@tcmaps No it can’t do that. You can write a burp plugin to handle that for you.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants