Able to intercept app Traffic after choosing up the Secured Connection using SSL (HTTPS)
V
VK.com
Submitted None
Actions:
Reported by
bugwrangler
Vulnerability Details
Technical details and impact analysis
Install the app
Login with Valid credentials
Settings - Choose Secured connection (HTTPS)
Close the app
Set the proxy and Open the app
verify that Connection isn't Secured and able to intercept (PFA POC)
Expected Result : Secured layer & SSL PINING should be applied successfully.
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$100.00
Submitted
Weakness
Information Disclosure