Hacking Tinder for Fun and Profit
ydesouza.com
Hacking Tinder for Fun and Profit
1–10 of 16 posts
Re: Hacking Tinder for Fun and Profit
#2Re: Hacking Tinder for Fun and Profit
#3I've been looking into packet tracing some mobile games that operate entirely online. I'm sure the mobile space is packed to the brim with unrestricted APIs... Thanks for the motivation/tips.
Re: Hacking Tinder for Fun and Profit
#4I've been looking into packet tracing some mobile games that operate entirely online. I'm sure the mobile space is packed to the brim with unrestricted APIs... Thanks for the motivation/tips.
Re: Hacking Tinder for Fun and Profit
#5I've been looking into packet tracing some mobile games that operate entirely online. I'm sure the mobile space is packed to the brim with unrestricted APIs... Thanks for the motivation/tips.
I don't think it's an "unrestricted" API if it uses https and you have to intercept and extract an auth token from a valid session. But I get what you mean -- it is fun to look under the covers and see how the big companies do things.
I'd just imagine developers are a lot less wary about security holes because they assume that their client is "just" a smartphone and not a rooted packet sniffer.
Re: Hacking Tinder for Fun and Profit
#6Re: Hacking Tinder for Fun and Profit
#7Re: Hacking Tinder for Fun and Profit
#8Re: Hacking Tinder for Fun and Profit
#9Is it possible to mitigate this kind of thing by using certificate pinning?
Even if you were for some reason using client certificates, you'd just have to rip apart the Tinder APK to get the cert and you're done.