app trailers exploit

17
iOS App Trailers Hacking By Decimator Materials: A computer (Obviously ) Fiddler 2 (http://www.getfiddler.com/dl/Fiddler2Setup.exe) Fiddler 2 Addon (http://www.fiddler2.com/dl/FiddlerCertMaker.exe) iPhone Configuration Utility (http://support.apple.com/downloads/DL1466/en_US/iPhone ConfigUtilitySetup.exe) iOS Device (iPhone 5, iPod 4, ect) Process List: -Lets get started! First download the needed programs from the list above.

Upload: jose-andres

Post on 26-Oct-2015

266 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: App Trailers Exploit

iOS App Trailers Hacking

By Decimator

Materials:

• A computer (Obviously )

• Fiddler 2 (http://www.getfiddler.com/dl/Fiddler2Setup.exe)

• Fiddler 2 Addon (http://www.fiddler2.com/dl/FiddlerCertMaker.exe)

• iPhone Configuration Utility (http://support.apple.com/downloads/DL1466/en_US/iPhoneConfigUtilitySetup.exe)

• iOS Device (iPhone 5, iPod 4, ect)

Process List:

-Lets get started! First download the needed programs from the list above.

Page 2: App Trailers Exploit

-Now its time to configure the programs.

-IMPORTANT NOTE: “Download and install the Addon

before you attempt to create the certificate, or else it won’t

sniff HTTPS properly.”

-Open up Fiddler 2. Go to Tools. Then “Fiddler Options”.

Page 3: App Trailers Exploit

-Make sure that Fiddler listens on port: 8888 and “Allow all

remote connections” is enabled.

Page 4: App Trailers Exploit

-Go to Tab named “HTTPS”, Click Capture, Decrypt,

“Select from all Processes”, Ignore, and save certificate to

Desktop.

- Connect iOS Device to the computer.

Page 5: App Trailers Exploit

- Open up iPhone Configuration Utility on your desktop.

-Click on “Configuration Profiles”

Page 6: App Trailers Exploit

-Select “New”

-Type anything in the Identifier Box (Com.XXXXXX.XXX)

-Scroll down to “Credentials”.

-Then click “Configure”

Page 7: App Trailers Exploit
Page 8: App Trailers Exploit

-Choose the Certificate you just made in Fiddler. (Look for “DO_NOT_TRUST_FIDDLER”)

-Click Ok.

Page 9: App Trailers Exploit

Click to your ios device that is plugged in, click “Configuration Profile” then install the profile you made.

Page 10: App Trailers Exploit

-Accept the installation of the Profile from your iOS device’s screen.

Page 11: App Trailers Exploit

-On your desktop type CMD into the search bar. Type in “ipconfig”. Find your

IPv4 Address. (Ex: 192.168.1.5)

-On your iOS Device go to (Settings->Wi-Fi-> (Your Wi-Fi’s Name)(Click arrow in the corner) ->Manual)

Page 12: App Trailers Exploit

- For the server, type in the your IPv4 (192.168.1.5 for me, yours might me different)

- The port number is 8888 (same thing you set in fiddler).

Page 13: App Trailers Exploit

THE HARD PART IS OVER NOW!!!!

-Open up Fiddler and if not already selected, select “Decode”.

Page 14: App Trailers Exploit
Page 15: App Trailers Exploit

On your iOS Device open AppTrailers. If you see a bunch of requests on Fiddler then you’re golden. Something like

that.

-On App trailers go to “videos” and scroll down to the

videos worth “+5”.

Page 16: App Trailers Exploit

- Watch the video, and in Fiddler after the Video is done there is a request that looks like this.

-Look for this link

(/redeem_video.php?uuid=Your UDID)

-Click on the request in Fiddler and hold “R”, doing so will

repeat the request. Adding +5 points each time. Each request takes less than a second to complete. So you can get a massive amount of points in a short time.

- This may not work the first time, but it will eventually work.

Page 17: App Trailers Exploit

IMPORTANT NOTICE:

-Don’t go overboard because you can get your

account banned if you redeem too many points at a time or too many redeems in a row. I redeemed twice within a couple minutes and by the third time I was banned. I am currently working on trying to get around the ban. If anyone wants to work on it with me, message me on hack forums. Decimator. If you would like to use any information in this tutorial in another post, just message me first. I’ll most likely say yes. Well that’s it, happy

hacking!!

~Decimator