Unable to intercept traffic on Android

181 views
Skip to first unread message

Razsienaj

unread,
Jun 28, 2023, 6:49:46 AM6/28/23
to OWASP ZAP User Group
I'm not able to see requests from Android in ZAP 1.12.0 on desktop. Thinks I did:
  • generate a new server certificate (just in case)
  • upload this certificate to Firefox on desktop and to Android
  • in ZAP -> Tools -> Options -> Network -> Local servers/proxies i have main proxy: 0.0.0.0:5000
  • in Network -> Connection I have all TLS protocols enabled, timeout 45 and TTL 30
  • set up proxy in Firefox on desktop to see if it works and I can see requests from desktop (and then set up system proxy again not to see traffic from desktop)
  • installed certificate on Android 13 as trusted user CA certificate (also tried installing it as WiFi and VPN certificates but wasn't successful so uninstalled them since my friend intercepted traffic with just OWASP CA certificate)
  • connected to the same WiFi on Android as on desktop where ZAP is (with no VPN)
  • for that WiFi selected manual proxy and entered local IP address of my desktop (checked via "ip a" on Linux; it was 192.168.1.123) and port 5000 (as in ZAP)
Checked both traffic from Android browser (Firefox beta) and mobile apps. I could see no new requests in ZAP. The weird thing was that I had "No data connection" for this WiFi and browser/Discord didn't work but was able to send and receive messages on Messenger.

Any ideas what I'm doing wrong?
Reply all
Reply to author
Forward
0 new messages