Posts

Showing posts with the label Android

Inspecting HTTP traffic using OWASP Zed Attack Proxy tool

Image
Whether I develop or debug a mobile application for Android or iOS with some networking functionality I might want to inspect HTTP traffic. Even for a web development there might be a need to intercept and modify the HTTP requests. There are number of tools available to intercept HTTP/HTTPS traffic. One of the most popular and well documented is probably Fiddler . That’s what I used on Windows platform. If you are on MAC, you have to configure Fiddler to run in a virtual machine or use some alternative tools. This post is about the second option. Specifically, OWASP Zed Attack Proxy (ZAP) tool -  free, open source, easy to install and use, penetration testing tool for finding vulnerabilities in web applications. This tool provides a lot of functionality whereas I am going to cover here only how to configure and use it as an intercepting  proxy on Mac. Also I include the steps to configure Android and iPhone devices in order to intercept the HTTP traffic. ZAP docu...

User authentication on Android against hashed passwords created with Asp.Net Identity

Microsoft shipped a new membership system called ASP.NET Identity with Visual Studio 2013 and .Net 4.5.1. It allows us to add login features to the applications built for the web, phone, or store. By default the ASP.NET Identity system will store all the user information in a database. ASP.NET Identity uses Entity Framework Code First to implement all of its persistence mechanism. What if we going to build an Android app with offline capabilities, where the users would sync the stored credentials created by Asp.Net Identity on the server in order to login? We would have to verify the provided user password against locally stored hashed password to authenticate the user. Below is the code that can be used for this task: /** * Verifies provided plain text password against hash * @param hashedPass * @param password * @return true or false */ private boolean verifyPassword(String hashedPass, String password){ if (hashedPass == null){ return false; } byte[] n...