objection VS ssl-kill-switch2

Compare objection vs ssl-kill-switch2 and see what are their differences.

objection

đŸ“± objection - runtime mobile exploration (by sensepost)

ssl-kill-switch2

Blackbox tool to disable SSL certificate validation - including certificate pinning - within iOS and macOS applications. (by nabla-c0d3)
Our great sponsors
  • WorkOS - The modern identity platform for B2B SaaS
  • InfluxDB - Power Real-Time Data Analytics at Scale
  • SaaSHub - Software Alternatives and Reviews
objection ssl-kill-switch2
17 7
6,993 2,981
2.2% -
3.9 0.0
3 months ago 10 months ago
Python Objective-C
GNU General Public License v3.0 only GNU General Public License v3.0 or later
The number of mentions indicates the total number of mentions that we've tracked plus the number of user suggested alternatives.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.

objection

Posts with mentions or reviews of objection. We have used some of these posts to build our list of alternatives and similar projects. The last one was on 2022-12-14.

ssl-kill-switch2

Posts with mentions or reviews of ssl-kill-switch2. We have used some of these posts to build our list of alternatives and similar projects. The last one was on 2022-08-31.
  • [$50][14.5.1][OPT] SSL Kill Switch / Bypass
    2 projects | /r/TweakBounty | 31 Aug 2022
  • SSL Kill Switch / Bypass not working on 14.5.X
    2 projects | /r/jailbreakdevelopers | 31 Aug 2022
  • Is this networking knowledge enough ?
    5 projects | /r/AskNetsec | 17 Mar 2022
    Another tip is looking at the source code of well-known tools that feature root/jailbreak/cert pinning bypasses like Objection, SSL Kill Switch 2, and Shadow to learn reverse engineering stuff.
  • [Free Release] SSLUnpin
    5 projects | /r/jailbreak | 9 Aug 2021
  • [$50][14] SSL Kill Switch 2 Update Needed
    1 project | /r/TweakBounty | 18 Apr 2021
    Sadly, the tweak (source: https://github.com/nabla-c0d3/ssl-kill-switch2) doesn't work on iOS 14 after installing (and calling Frida every time to disable Certificate Pinning is too annoying). Will gladly pay $50 to anyone that makes it work on A8 devices (I'm using iPad Mini 4) on iOS 14 (I'm using iOS 14.4.2). Thanks.
  • Clubhouse data leak: 1.3M user records leaked online for free
    1 project | news.ycombinator.com | 11 Apr 2021
    Jailbreaking an iPhone and using a tool like SSL Kill Switch [1] or just plain, old Frida with a script like [2] will do the job. Jailbreaking is the hard part, especially for an up to date iPhone, after that there's loads of guides you can follow that disable certificate validation for pretty much every application. It all boils down to hooking the necessary validation functions and having the APIs lie to the app code.

    Some apps package their own crypto helpers (often with big crypto problems) to make this harder and require actual reverse engineering, but those are a pain to maintain and it's only a matter of time before someone finds a way around them. If you can extract the symbols (so if the app has not been obfuscated well) you can use Frida's API to hook those as well through any language you like. There's even an interactive Javascript console you can hook into the apps you're hooking!

    Certificate pinning is a great way to protect users' security and privacy, especially in countries with questionable governments or ISPs, but it won't protect your app's secrets.

    [1]: https://github.com/nabla-c0d3/ssl-kill-switch2

What are some alternatives?

When comparing objection and ssl-kill-switch2 you can also consider the following projects:

frida - Clone this repo to build Frida

SSLUnpin - Bypass SSL pinning on iOS 8 to iOS 14

drozer - The Leading Security Assessment Framework for Android.

SSLBypass - iOS SSL Pinning Bypass (iOS 8 - 14)

Free-RASP-Community - SDK providing app protection and threat monitoring for mobile devices, available for Flutter, Cordova, Android and iOS.

shadow - A jailbreak detection bypass for modern iOS jailbreaks.

awesome-frida - Awesome Frida - A curated list of Frida resources http://www.frida.re/ (https://github.com/frida/frida)

MonkeyDev - CaptainHook Tweak、Logos Tweak and Command-line Tool、Patch iOS Apps, Without Jailbreak.

Apktool - A tool for reverse engineering Android apk files

IPAPatch - Patch iOS Apps, The Easy Way, Without Jailbreak.

pwndbg - Exploit Development and Reverse Engineering with GDB Made Easy

plcrashreporter - Reliable, open-source crash reporting for iOS, macOS and tvOS