Jump to content

Pengu - Virtual Pets (DIY Charles Proxy exploit)


20 posts in this topic

Recommended Posts

Updated (edited)

Charles installation: Step 1.

 

  • Install Charles Proxy following the standard directions. https://www.charlesproxy.com/download/
  • Start the program.
  • Go to Proxy > Proxy Settings.
  • Select the Proxies tab, enter "8888" in the HTTP Proxy Port field then select Ok.
  • Go back to the proxy tab and select “SSL Proxy settings”
  • Select (“Enable SSL Proxying”), Then Select “Add”
  •                 In The “Host” Field Input your Ipv4 address. Also in the “Port” field make sure to input 8888
  •                 *IMPORTANT* To find your Ipv4 In “Charles Proxy”, select (Help > SSL Proxying > Install charles root certificate on a mobile device or remote browser. Follow the directions Prompted! (Please Read everything to avoid issues)

 

Charles Installation IOS (Step 2)

 

  • On your iphone navigate to Settings > Wi-Fi > Select the “I’ next to your connected wifi > scroll to the bottom and select "Configure PROXY". > Select Manual > type in the SAME Ipv4 and Port you’re using!
  • Open Safari on your iPhone.
  • Browse to https://chls.pro/ssl.
  • Safari will prompt you to install the SSL certificate.
  • If you are on iOS 10.3 or later, open the Settings app and navigate to General > About > Certificate Trust Settings.
  • Find the Charles Proxy certificate and enable the certificate.

Now, your iPhone is set up to use Charles Proxy for intercepting and monitoring HTTPS traffic.

 

 

Into the exploit Step 1.

 

Now that everything is enabled! Make sure that Pengu is installed on your device!

 

  • Open Pengu on you iOS Device.
  • Sign up and create your pet. 
  • Once you have your pet, Go to the controller in the bottom left corner ( the arcade)
  • Stay on the arcade page and navigate to your computer.
  • Within Charles proxy you should already see some data popping up (Noise) Condense this by typing in “Pengu” In the “filter” field below the data(noise). It will single out the App we’re trying to exploit.
  • Start the SSL proxying by selecting the lock ( To the left of the turtle icon)
  • Once you’ve selected the Lock. The lock should no longer look opened. (locked) You are now SSL Pinning
  • Click the brush to clear the Pengu data. ( left of the record icon)
  • Navigate to your iOS device and start a Pengu flappy bird game!
  • Play the Pengu bird game legit ( just get more than 1 point)
  • After you played a game. You should have 2 hearts left. (Stay on this page)
  • Navigate to Charles Proxy (Computer) you should see https://Penguapp.co select the arrow for the drop down menu and navigate to, v1 > games > flappy-pengu > (Pengu Id) > Select "Report"
  • To the right of report you should see two lists Request(Top)/Response(Bottom) Select (JSON) for both menus These are going to contain your score( which we will change)

 

 

Changing Values ( Step 2)

 

Now that you have survived the first step This will be easier >Trust<

 

  • Right click on the “Report” option mentioned in *Step 1*
  • Navigate to “Breakpoints” and Select it. ( It will now have a check mark next to it)
  • EVERYTHING BELOW THIS POINT IS TIMED ( IF YOU TAKE TO LONG IT WILL TIME OUT) {READ THIS THEN EXECUTE ACCORDINGLY)
  • Return to the IOS Device and play another game! (Try again)
  • Once your second game has been played a breakpoint should appear on Charles proxy.
  • Select the tab “Edit Request” (next to Overview)
  • Select JSON Right above Execute (Not Json Text)
  • You should see the Legit score you achieved.
  • Double click on the score you achieved and modify the value to a (Reasonable number) I.e (60000)
  • Now EXECUTE THAT BAD BOY. 
  • Once executed. Another menu should pop up ( the response). Select “Edit response” and make sure (score is what you set it too.
  • NOW EXECUTE THAT!

 

You now should have a modified value and the game will input your Modified score. 

 

Once you have the desired coins then you’re all set!

 

(Disconnecting Charles)

 

  • Select the Lock (Left of the turtle) *it will stop ssl pinning
  • Navigate to your iOS device and go to your settings > wifi > blue I next to the connected wifi > configure proxy > select OFF > Save
  • Navigate to General > About > Certificate Trust Settings > Select the Charles proxy to turn it off

 

Update 01/16/25

 

I found a work around for mac, It's going to require you to have frida-ps and objection (Bypass ssl pinning detection

https://prnt.sc/OEAMeSl-MIUw

 

I hope you guys enjoy this little exploit. If you have any questions let me know!

 

Updated by SkyVexy
Workaround found
  • Like 1
  • Agree 1
  • Informative 1
Posted

For some reason instead of v1 on the dropdown, I have 2 'unknown' fields, one arrow up (blue) and one arrow down(green).
Any ideas what could be the issue ?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Our picks

    • DESERTOPIA v4.21.0 [ +1 Cheats ] Gems Max
      Modded/Hacked App: DESERTOPIA By Gamtropy Co., Ltd.
      Bundle ID: com.gamtropy.desertopia
      iTunes Store Link: https://apps.apple.com/us/app/desertopia/id1265572046?uo=4


      🤩 Hack Features

      - Gems Max [ Earn Some ]
        • Thanks
        • Like
      • 5 replies
    • DESERTOPIA v4.21.0 [ +1 Jailed ] Gems Max
      Modded/Hacked App: DESERTOPIA By Gamtropy Co., Ltd.
      Bundle ID: com.gamtropy.desertopia
      iTunes Store Link: https://apps.apple.com/us/app/desertopia/id1265572046?uo=4
       

      🤩 Hack Features

      - Gems Max [ Earn Some ]
        • Like
      • 2 replies
    • From Pawn to King - Idle RPG v6.2.1 [ +18 Jailed ] Currency Max
      Modded/Hacked App: From Pawn to King - Idle RPG By Toward Inc.
      Bundle ID: com.towardmobile.fromsoldiertoking
      iTunes Store Link: https://apps.apple.com/us/app/from-pawn-to-king-idle-rpg/id1645843355?uo=4


      Hack Features:

      - ADS NO [ Reward Free ]

      - Speed UP 2x

      - Gems 

      - Gold 

      - Smelt Stone 

      - Mileage Point 

      - Normal Raid Ticket 

      - Quest Completed [ Earn 1 Point ]

      - Heroes Ticket +6 

      - Heroes LvL Up Medal 

      - Heroes LvL Up Magic Stone 

      - Stage Pass Unlocked [ Premium ]

      - Mine LvL Up [ Gems Reward Unlimited ]

      - ATK Speed 

      - Hero Status

      - Enemy Status 

      - Boss Status 

      - Boss Time Unlimited
        • Like
      • 27 replies
    • From Pawn to King - Idle RPG v6.2.1 [ +18 Cheats ] Currency Max
      Modded/Hacked App: From Pawn to King - Idle RPG By Toward Inc.
      Bundle ID: com.towardmobile.fromsoldiertoking
      iTunes Store Link: https://apps.apple.com/us/app/from-pawn-to-king-idle-rpg/id1645843355?uo=4


      Hack Features:
      - ADS NO [ Reward Free ]

      - Speed UP 2x

      - Gems 

      - Gold 

      - Smelt Stone 

      - Mileage Point 

      - Normal Raid Ticket 

      - Quest Completed [ Earn 1 Point ]

      - Heroes Ticket +6 

      - Heroes LvL Up Medal 

      - Heroes LvL Up Magic Stone 

      - Stage Pass Unlocked [ Premium ]

      - Mine LvL Up [ Gems Reward Unlimited ]

      - ATK Speed 

      - Hero Status

      - Enemy Status 

      - Boss Status 

      - Boss Time Unlimited

        • Thanks
        • Winner
        • Like
      • 44 replies
    • Dream Resort - Match 3 Games v1.7.1 [ +7 Jailed ] Auto Win
      Modded/Hacked App: Dream Resort - Match 3 Games By F.O.G LIMITED
      Bundle ID: com.dream.resort.candy.match.mania.ios
      iTunes Store Link: https://apps.apple.com/us/app/dream-resort-match-3-games/id6737011572?uo=4
       

      🚀 Hack Features

      - Auto ADS Disable

      - Coins

      - Diamonds

      - Lives Cost

      - Moves Freeze

      - Booster [ Buy Get Unlimited After use Then work ]

      - Auto win 


      🍏 Jailbreak iOS hacks: https://iosgods.com/forum/5-game-cheats-hack-requests/
      🤖 Modded Android APKs: https://iosgods.com/forum/68-android-section/
        • Agree
        • Winner
        • Like
      • 29 replies
    • Dream Resort - Match 3 Games v1.7.1 [ +7 Cheats ] Auto Win
      Modded/Hacked App: Dream Resort - Match 3 Games By F.O.G LIMITED
      Bundle ID: com.dream.resort.candy.match.mania.ios
      iTunes Store Link: https://apps.apple.com/us/app/dream-resort-match-3-games/id6737011572?uo=4

       

      🔧 Mod Requirements

      - Jailbroken iPhone or iPad.
      - iGameGod / Filza / iMazing.
      - Cydia Substrate, ElleKit, Substitute or libhooker depending on your jailbreak (from Cydia, Sileo or Zebra).

       

      🚀 Hack Features

      - Auto ADS Disable

      - Coins

      - Diamonds

      - Lives Cost

      - Moves Freeze

      - Booster [ Buy Get Unlimited After use Then work ]

      - Auto win 


      🍏 For Non-Jailbroken & No Jailbreak required hacks: https://iosgods.com/forum/79-no-jailbreak-section/
      🤖 Modded Android APK(s): https://iosgods.com/forum/68-android-section/
        • Thanks
        • Like
      • 28 replies
    • Paradise Paws: Merge Animals v1.0.18 [ +9 Cheats ] Currency Max
      Modded/Hacked App: Animal Sanctuary By Wildlife Studios, Inc
      Bundle ID: com.wildlifestudios.merge.animal.sanctuary
      App Store Link: https://apps.apple.com/us/app/animal-sanctuary/id6741805691?uo=4
       

      🤩 Hack Features

      - Gems

      - Coins

      - Heart

      - Spin

      - LvL

      - Exp

      - Fog Auto Remove [ Linked With LvL ]

      - Premum Lands Unlocked [ Just Tap ]

      - Store Free [ IAP Not ]

      Note:- Game Close After Currency Hack Don't Worry
        • Haha
        • Thanks
        • Like
      • 35 replies
    • Paradise Paws: Merge Animals v1.0.18 [ +9 Jailed ] Currency Max
      Modded/Hacked App: Animal Sanctuary By Wildlife Studios, Inc
      Bundle ID: com.wildlifestudios.merge.animal.sanctuary
      App Store Link: https://apps.apple.com/us/app/animal-sanctuary/id6741805691?uo=4


      🤩 Hack Features

      - Gems

      - Coins

      - Heart

      - Spin

      - LvL

      - Exp

      - Fog Auto Remove [ Linked With LvL ]

      - Premum Lands Unlocked [ Just Tap ]

      - Store Free [ IAP Not ]

      Note:- Game Close After Currency Hack Don't Worry
        • Agree
        • Thanks
        • Like
      • 34 replies
    • Bloody Bastards Cheats v4.2.3 +2
      Modded/Hacked App: Bloody Bastards By Tibith Ltd
      Bundle ID: com.tibith.badboxing2
      iTunes Store Link: https://apps.apple.com/us/app/bloody-bastards/id1593430099?uo=4


      Hack Features:
      - Infinite Coins
      - Dumb Enemy (Single Player)


      Non-Jailbroken & No Jailbreak required hack(s): https://iosgods.com/topic/158327-bloody-bastards-v315-jailed-cheats-1/


      iOS Hack Download Link: https://iosgods.com/topic/158325-bloody-bastards-cheats-v315-2/
        • Informative
        • Agree
        • Haha
        • Thanks
        • Winner
        • Like
      • 168 replies
    • Hungry Shark World v7.2.2 [ +9 Cheats ] Currency Max
      Modded/Hacked App: Hungry Shark World By Ubisoft
      Bundle ID: com.ubisoft.hungrysharkworld
      iTunes Store Link: https://apps.apple.com/us/app/hungry-shark-world/id1046846443?uo=4


      Hack Features:
      - ADS NO

      - Gems

      - Coins 

      - Pearls 

      - Premium Pass

      - Health Auto Drain [ OFF ]

      - Boost Max 

      - Score Multi 

      - Revive Max 


      Non-Jailbroken & No Jailbreak required hack(s): https://iosgods.com/forum/79-no-jailbreak-section/
      Modded Android APK(s): https://iosgods.com/forum/68-android-section/
      For more fun, check out the Club(s): https://iosgods.com/clubs/
        • Informative
        • Agree
        • Haha
        • Thanks
        • Winner
        • Like
      • 81 replies
    • Vampirio: Defend & Survive v1.3.6 [ +2 Cheats ] Currency Max
      Modded/Hacked App: Vampirio: Defend & Survive By Outfit7 Neo Limited
      Bundle ID: com.outfit7neo.onehelsing
      App Store Link: https://apps.apple.com/ph/app/vampirio-defend-survive/id6670539564?uo=4

       

      🤩 Hack Features

      - Currency Max [ Disable After Get ]
      - Resources Max [ Use Only Resources - Disable After Get ] Becasue Linked Population When You Build Disable OtherWise Crash

        • Winner
        • Like
      • 12 replies
    • Vampirio: Defend & Survive v1.3.6 [ +2 Jailed ] Currency Max
      Modded/Hacked App: Vampirio: Defend & Survive By Outfit7 Neo Limited
      Bundle ID: com.outfit7neo.onehelsing
      App Store Link: https://apps.apple.com/ph/app/vampirio-defend-survive/id6670539564?uo=4


      🤩 Hack Features

      - Currency Max [ Disable After Get ]
      - Resources [ Use Only Resources - Disable After Get ] Becasue Linked Population When You Build Disable OtherWise Crash
        • Agree
        • Haha
        • Winner
        • Like
      • 16 replies
×
  • Create New...

Important Information

We would like to place cookies on your device to help make this website better. The website cannot give you the best user experience without cookies. You can accept or decline our cookies. You may also adjust your cookie settings. Privacy Policy - Guidelines