A tool for automatic black-box detection of missing hostname verification, including for applications that use certificate pinning.
All of details of this work are described in the paper:
The paper above built on our previous work on an more general analysis of TLS in UK banking apps. This included various TLS certificate mis-verification vulnerabilites, in addition to phishing attacks. Details of this work can be found here: