Flutter App SSL Pinning Bypass Using ReFlutter
A simple workflow to extract, merge, patch, sign, and install a Flutter APK for security testing.
Flutter App Bypass
This is the workflow I used to bypass SSL pinning in a Flutter application during Android security testing.
1. Get the APK from the Device
First, identify the package name:
adb shell pm list packages | findstr <package_name>Check the APK path:
adb shell pm path <package_name>If the application uses split APKs, pull all the APK files from the device.
adb pull <apk_path>Repeat this for each APK path returned by pm path.
2. Merge Split APKs
Place all the APK files in the same directory and merge them using APKEditor:
java -jar APKEditor.jar m -i apk_filesThis generates a merged APK that can be processed further.
3. Patch the Flutter APK Using ReFlutter
Run ReFlutter against the merged APK:
reflutter merged.apkThe patched APK will be generated in the ReFlutter output directory.
4. Sign the APK
Sign the patched APK using Uber APK Signer:
java -jar uber-apk-signer.jar --apks _flutter_output_REdebug.apkUse the signed APK generated by Uber APK Signer for installation.
5. Install the Modified APK
Install the signed APK on the Android device:
adb install <signed_apk>.apkAfter installation, configure the device to route traffic through your interception proxy and test the application traffic.
Related Research
Android Proxy Settings with iptables
A simple technique to redirect Android HTTPS traffic to Burp Suite when the application ignores proxy settings.
What is SSL Pinning ?
A practical introduction to analyzing certificate pinning in Android applications.
HTTP Toolkit to Solve the Simcard required application proxy
A simple technique to intercept Android application traffic when the app works only over mobile data and ignores traditional proxy settings.