Posts

Showing posts from August, 2020

Intercepting a tvOS App on Burpsuite

Intro:  I've done countless pentests of websites and mobile apps, but when it comes to iOS or any Apple device app pentesting, I'll always have one or the other proxying issues. Mostly they are specific to TLS/not properly importing into Keychain or Burp acting weird (there are Java specific issues, compatibility issues with OpenJDK and Oracle Java i.e. if you are like me I've installed Oracle JDK on MacOS). So I thought I should write this up, hoping it will be useful to someone.  Note: this article is for advanced users, I've not detailed every step. At the time of writing this app, I found the following article very informative, I've pretty much followed the same steps, the article originally is meant for Charles Proxy but in the pentesting world who likes Charles Proxy ;-)  https://medium.com/@rwgrier/setting-up-charles-proxy-on-apple-tv-tvos-1ce64ee39b07 Credit to the author above, however it is not up-to-date. Pre-Reqs: Non-Jailbroken AppleTV (supervised state