# Need help sniffing traffic between Android/iOS game and its server

**URL:** <https://discourse.mitmproxy.org/t/need-help-sniffing-traffic-between-android-ios-game-and-its-server/188>\
**Category:** help\
**Created:** [October 9, 2016, 11:50pm UTC](https://discourse.mitmproxy.org/t/need-help-sniffing-traffic-between-android-ios-game-and-its-server/188 "2016-10-09T23:50:44Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![celebeast](https://avatars.discourse-cdn.com/v4/letter/c/13edae/32.png) [@celebeast](https://discourse.mitmproxy.org/u/celebeast)\
**Post date:** [October 9, 2016, 11:50pm UTC](https://discourse.mitmproxy.org/t/need-help-sniffing-traffic-between-android-ios-game-and-its-server/188/1 "2016-10-09T23:50:44Z")

</div>

Hello devs and the community,

So as the topic says, I am having difficulties decrypting traffic between a phone MMORPG and their server. At first, I used Wireshark to analyse the traffic, and that’s when I realised the packets are all jumbled. My research led me to mitmproxy. So, I set up an Ubuntu VM with all proper transparency settings, used the VM’s IP as default gateway on my Windows 7 OS, installed the certificate on Android Emulator(Nox), launched the game, intercepted log-in packets but… They’re still encrypted? I did all posts on these forums, thought may be they’re using certificate pinning, so I also installed SSL TrustKiller on the emulator but that didn’t help. What am I missing?

 ![](https://canada1.discourse-cdn.com/flex030/uploads/mitmproxy1/original/1X/c00dd3ab2ee942352526aee38ec809169f04f839.PNG)

---

<div class="post-metadata">

**Author:** ![mhils](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.mitmproxy.org/mhils/32/7_2.png) [@mhils](https://discourse.mitmproxy.org/u/mhils)\
**Post date:** [October 14, 2016, 2:27am UTC](https://discourse.mitmproxy.org/t/need-help-sniffing-traffic-between-android-ios-game-and-its-server/188/2 "2016-10-14T02:27:55Z")

</div>

Hi @celebeast,

If mitmproxy couldn’t intercept and decrypt these requests, you wouldn’t see them in the UI like this. The SSL/TLS encryption is broken/stripped-off if you want so, but it looks like said developers also implemented a custom encryption/obfuscation layer below that. How exactly that works can only be determined by reverse-engineering. 😉  
Looking at the output, the bytes don’t seem to be entirely random, so it’s probably not super hard crypto. 🙂

---

<div class="post-metadata">

**Author:** ![celebeast](https://avatars.discourse-cdn.com/v4/letter/c/13edae/32.png) [@celebeast](https://discourse.mitmproxy.org/u/celebeast)\
**Post date:** [October 14, 2016, 2:47am UTC](https://discourse.mitmproxy.org/t/need-help-sniffing-traffic-between-android-ios-game-and-its-server/188/3 "2016-10-14T02:47:20Z")

</div>

Thank you for the response. 🙂  
So this is not certificate pinning? Because I was planning to unpack the .apk, find the certificate pinning code, disable it and repack. If it’s something else, I’ll have to look inside the .apk?

---

<div class="post-metadata">

**Author:** ![mhils](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.mitmproxy.org/mhils/32/7_2.png) [@mhils](https://discourse.mitmproxy.org/u/mhils)\
**Post date:** [October 14, 2016, 3:10am UTC](https://discourse.mitmproxy.org/t/need-help-sniffing-traffic-between-android-ios-game-and-its-server/188/4 "2016-10-14T03:10:23Z")

</div>

This is not certificate pinning - the TLS man-in-the-middle attack works, otherwise we wouldn’t be able to see the HTTP headers. What you have to look for? The code that obfuscates the body! 😉

---

<div class="post-metadata">

**Author:** ![celebeast](https://avatars.discourse-cdn.com/v4/letter/c/13edae/32.png) [@celebeast](https://discourse.mitmproxy.org/u/celebeast)\
**Post date:** [October 14, 2016, 3:28am UTC](https://discourse.mitmproxy.org/t/need-help-sniffing-traffic-between-android-ios-game-and-its-server/188/5 "2016-10-14T03:28:43Z")

</div>

That is great advice, that you for clearing everything up. I now have a way forward. 😊
