Burp Suite User Forum

Create new post

Unable to get a response when android emulator is used

Arpit | Last updated: Apr 11, 2024 03:37PM UTC

Hi, I am learning mobile pentesting. Using Genymotion: v3.6.0 Burp Professional: v2024.2.1.3 Vulnerable apk: InsecureBankV2 Issue: After doing all the configuration, I am able to intercept the request but unable to get a response. The event log shows: "Failed to connect to 10.0.2.2:8888" I have converted the der certificate to pem(<hash>.0) format & hence, was able to intercept. But the app is unable to connect to the internet. However, the mobile's browser is able to connect to the internet with the proxy still intact. thanks, Arpit

Ben, PortSwigger Agent | Last updated: Apr 12, 2024 08:42AM UTC

Hi Arpit, If the browser on the mobile device is successfully proxying both HTTP and HTTPS traffic then that would suggest the issue lies with the mobile application. Are you able to email us at support@portswigger.net and include some some screenshots of the Event log (if you could enable all of the filters - the 'Debug' filter is disabled by default)? I presume the mobile application itself also displays errors itself at this point? Are we also able to get a screenshot of an example of what you see in the application as well? Finally, what version of Android are you using?

ARPIT | Last updated: Apr 27, 2024 11:21AM UTC

Hi Ben, I tried changing the apk too I think it is an issue only when I am trying to intercept the https traffic of any APK, not the http traffic. Precisely- Browser: Https & Http is getting intercepted APK: Https is not intercepted http is intercepted This means that, it is not an issue with the burp certificate, otherwise it wouldn't have intercepted any traffic. Android version: 11 & API 30 burp pro: v2024.3.1.3 vulnerable APK: securestorev2 Rest I will mail you the details. Thanks, Arpit

ARPIT | Last updated: Apr 29, 2024 09:46AM UTC

**Correction: Otherwise it wouldn't have intercepted any https traffic from browser.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.