Burp Suite User Forum

Create new post

How to intercept the traffic of application installed on Android Virtual Device

Abhishek | Last updated: Jan 25, 2016 02:33PM UTC

Hi Team, I have created the Android virtual device on the Windows system using the Android studio. Also I have installed an application on that AVD. Can anyone know how to intercept the traffic ?

Liam, PortSwigger Agent | Last updated: Jan 25, 2016 03:42PM UTC

Hi Abhishek Thanks for your message. One of our users created a short video on the process: https://vimeo.com/137672482 In the video they go over how to setup Android with ProxyDroid and FS Cert Installer to push HTTPS App traffic to Burp Suite. They also provided these basic instructions. Burp Suite Host: • Reset burp suite • Turn on listen to all interfaces Android Host: • Remove all User Certs • Stop task and remove data for ProxyDroid and FS Cert installer ( you can just uninstall reinstall ) • Put the phone in airplane mode then turn on WIFI • In FS Cert put in proxy IP and PORT then click the middle button Add CA and add it under WIFI Cert in the dropdown • Then click test chain and it should all be green yes for www.google.com • For Proxydroid just put in the IP and port and also tunnel DNS • Kill or reinstall any apps before you start to make sure they go through the proxy properly Please let us know if you need any further assistance.

Liam, PortSwigger Agent | Last updated: Feb 19, 2016 09:13AM UTC

The video has been removed but the steps are still valid. It's also worth noting that Android Nougat no longer trusts user or admin supplied CA certificates. We recommend that you use an older version of Android for your testing. If you must use Android Nougat then you will need to install a trusted CA at the Android OS level on a rooted device or emulator. - https://nvisium.com/blog/2017/07/12/advantages-and-disadvantages-of-android-n-network-security-configuration/

Burp User | Last updated: Nov 15, 2017 12:42PM UTC

Video is not visible or removed :/

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.