# HTTPS Sniffing on Android (Certificate Pinning)

**URL:** <https://discourse.mitmproxy.org/t/https-sniffing-on-android-certificate-pinning/550>\
**Category:** Uncategorized\
**Created:** [July 15, 2017, 8:43pm UTC](https://discourse.mitmproxy.org/t/https-sniffing-on-android-certificate-pinning/550 "2017-07-15T20:43:47Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![bilaljawed](https://avatars.discourse-cdn.com/v4/letter/b/e68b1a/32.png) [@bilaljawed](https://discourse.mitmproxy.org/u/bilaljawed)\
**Post date:** [July 15, 2017, 8:43pm UTC](https://discourse.mitmproxy.org/t/https-sniffing-on-android-certificate-pinning/550/1 "2017-07-15T20:43:47Z")

</div>

Hi,

So i have this app that on login uses certificate pinning (i dont see the data at all), right now i have mitmproxy certificate installed from [mitm.it](http://mitm.it) how do i define custom certificate in android? also how can i actually bypass certificate pinning? do i need to download the real certificate of host for it to work?

Thanks!

---

<div class="post-metadata">

**Author:** ![ujjwal96](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.mitmproxy.org/ujjwal96/32/111_2.png) [@ujjwal96](https://discourse.mitmproxy.org/u/ujjwal96)\
**Post date:** [July 17, 2017, 4:51pm UTC](https://discourse.mitmproxy.org/t/https-sniffing-on-android-certificate-pinning/550/2 "2017-07-17T16:51:21Z")

</div>

Hi,  
If an app uses certificate pinning you need to manually patch the app (decompile and add the certificate) or you need to root your android device.  
[http://docs.mitmproxy.org/en/stable/certinstall.html#certificate-pinning](http://docs.mitmproxy.org/en/stable/certinstall.html#certificate-pinning)

---

<div class="post-metadata">

**Author:** ![liran](https://avatars.discourse-cdn.com/v4/letter/l/e19adc/32.png) [@liran](https://discourse.mitmproxy.org/u/liran)\
**Post date:** [January 7, 2018, 11:06am UTC](https://discourse.mitmproxy.org/t/https-sniffing-on-android-certificate-pinning/550/4 "2018-01-07T11:06:57Z")

</div>

if the device is rooted it is enough? I am using a rooted device and still have the problem. can you specify what should be done?

---

<div class="post-metadata">

**Author:** ![liran](https://avatars.discourse-cdn.com/v4/letter/l/e19adc/32.png) [@liran](https://discourse.mitmproxy.org/u/liran)\
**Post date:** [January 7, 2018, 11:12am UTC](https://discourse.mitmproxy.org/t/https-sniffing-on-android-certificate-pinning/550/5 "2018-01-07T11:12:29Z")

</div>

also, it the pinned domain is not of the app itself, but of a domain the app tries to connect to, is there anything to do?

---

<div class="post-metadata">

**Author:** ![Al-Anoud](https://avatars.discourse-cdn.com/v4/letter/a/2bfe46/32.png) [@Al-Anoud](https://discourse.mitmproxy.org/u/Al-Anoud)\
**Post date:** [January 31, 2018, 3:45pm UTC](https://discourse.mitmproxy.org/t/https-sniffing-on-android-certificate-pinning/550/6 "2018-01-31T15:45:22Z")

</div>

Hi  
I was searching for something similar to your question please see the link below for help

> **[Four Ways to Bypass Android SSL Verification and Certificate Pinning](https://blog.netspi.com/four-ways-bypass-android-ssl-verification-certificate-pinning/)**
>
> As pentesters, we’d like to convince the app that our certificate is valid and trusted so we can man-in-the-middle (MITM) it and modify its traffic. In this blog I’ll go through 4 techniques you can use to bypass SSL certificate checks on Android.
