culturally/Instagram-iOS-SSL-pinning-bypass
iOS Instagram with SSL pinning / certificate pinning bypassed. Latest version 395.0.0
Instagram iOS with SSL pinning bypassed / Instagram with certificate pinning bypassed.
Get your private api endpoints now!
- DO NOT NEED JAILBREAK
- DO NOT NEED FRIDA
SSL / Certificate Pinning
You can read more about SSL Pinning here: https://yinsolutions.org/blogs/how-to-bypass-certificate-pinning-ig.html
Support Me
Bitcoin: 1LightUfhnFKgZqcsfiKoxciQbPB384PqM
Solana: 4a91vFCz8SjnqWiJpFuLWwWFpWdT9dZq13hG4o8icv2n
Litecoin: MFi28zedB78kaNiRpi9eBkFRTtGZNoxcWv
Info
- Current version which was bypassed: 395.0.0 (unreleased, costs money)
- You can now intercept all requests
- iOS Only
- Tested on iOS 15.4.1
- Any support is appreciated
Installation
- Download the IPA file
- Sideload the file (I personally suggest Sideloadly or TrollStore)
- Set up the proxy before starting the app (Was tested only with mitmproxy)
- Intercept
Crashing Issue
- Many people experienced crashing after login this is caused somehow by sideloading you have to sideload it using TrollStore to stop the crashing
Bypassed:
| Icon | Bundle ID | Version | File Type | Download |
|---|---|---|---|---|
| com.burbn.instagram | 381.0.0 | IPA | Click here | |
| com.burbn.instagram | 367.0.0 | IPA | Click here | |
| com.burbn.instagram | 361.0.0 | IPA | Click here | |
| com.burbn.instagram | 354.0.0 | IPA | Click here | |
| com.burbn.instagram | 351.0.0 | IPA | Click here | |
| com.burbn.instagram | 337.0.2 | IPA | Click here | |
| com.burbn.instagram | 335.0.8 | IPA | Click here | |
| com.burbn.instagram | 323.0.3 | IPA | Click here |
Other apps
Wanna learn how to bypass SSL pinning in apps or Do you have custom request for an App?
Message me on Telegram: @undecryptable
Other apps available + Course
Evidence
What is SSL pinning?
SSL pinning, also known as certificate pinning or public key pinning, is a security mechanism used in digital communication to enhance the security of a connection, particularly within the context of Secure Sockets Layer (SSL) or its successor, Transport Layer Security (TLS).
When a client (such as a web browser or a mobile app) connects to a server over HTTPS, the server presents its SSL/TLS certificate to prove its identity. Normally, the client verifies the server's certificate by checking if it is signed by a trusted Certificate Authority (CA). However, SSL pinning adds an extra layer of security by requiring the client to validate the server's certificate against a known, pre-configured set of certificates or public keys, rather than solely relying on the CA's trust chain.
Disclaimer
This project is for educational purposes only. It demonstrates bypassing SSL pinning in binaries, such as those used by Instagram/Meta, to help developers and researchers understand security vulnerabilities.
There is no intent to harm, exploit, or encourage illegal activities. If Instagram/Meta or any other party has concerns, please contact me at 0day@yin.sh, and I will address the issue or take down the project as requested.
Use of this project is at your own risk; the creator is not responsible for any misuse.
