Spinner

A tool for automatic black-box detection of missing hostname verification, including for applications that use certificate pinning.

About

Usage Instructions

Vulnerabilities

Publications

Contact

Publications

All of details of this work are described in the paper:

The paper above built on our previous work on an more general analysis of TLS in UK banking apps. This included various TLS certificate mis-verification vulnerabilites, in addition to phishing attacks. Details of this work can be found here: