Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Bug] SSL Pinning bypass stopped working after latest TikTok update #54

Open
dellus1on opened this issue Oct 4, 2024 · 4 comments
Open
Assignees

Comments

@dellus1on
Copy link

Describe the bug
The latest patched APK (v31.5.3) with SSL pinning bypass has stopped working as of a few days ago. It seems like TikTok has updated their SSL pinning method, making the bypass ineffective

App info

  • Version: tiktok-v31.5.3
  • Arch: x86, x86_64, armeabi-v7a, arm64-v8a

Device info

  • Model: Xiaomi Mi10T
  • Android Version: 13

Proxy tool
http toolkit: v1.14.11
burp: v2023.10.2.4

Logs
Unfortunately, there are no specific logs, but the app appears to not send or receive any data through the proxy when SSL pinning is bypassed. I can provide detailed logs from Burp Suite if needed.

Additional context
Would it be possible to release an updated version of the APK with the new SSL pinning bypass? It seems like TikTok has changed their security method for SSL pinning. Thank you for your hard work on this project!

@Eltion
Copy link
Owner

Eltion commented Nov 3, 2024

Should be fixed in the new released version

@StarCrap
Copy link

StarCrap commented Nov 4, 2024

Hi Eltion, I just tried v.37.0.4, and it still doesn't seem to work. Has it worked for others?

@dellus1on
Copy link
Author

Hi Eltion, I just tried v.37.0.4, and it still doesn't seem to work. Has it worked for others?

also don`t work for me without root, with root work correctly

@StraightouttaIG
Copy link

StraightouttaIG commented Nov 10, 2024

Hi Eltion, I just tried v.37.0.4, and it still doesn't seem to work. Has it worked for others?

Same here. I can intercept other Apps fine but when I launch the patched APK the app says "No internet connection"

I reinstalled Burpsuite certifcate and made a new Memu instance but still whenever I try to intercept traffic it says "No internet connection"

  • When I don't use proxy the APK works fine.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants