Why the host is harder to find than the paths
Relative paths are constants attached to methods. A host is a configuration value, and configuration arrives through resources, build variants, manifest entries, remote responses or a combination of them. An app can also hold several hosts at once and choose between them at runtime, so looking for one string will miss the rest.
Check the resources and the generated build class
String resources are a common home for a default host. A base URL stored in a resource can be overridden per locale or per configuration, and the value in the default resource file is the one most builds ship.
The generated build configuration class holds values the build system injected at compile time. Its fields cover environment selection, feature flags and sometimes the host itself. Because the class is generated, its layout follows the build file, so reading the app's build configuration in the decompiled output tells you which fields to expect.
Manifest metadata deserves the same treatment. Values placed there are readable without decompiling any logic, and they frequently name an environment or an override that the code reads at startup.
Follow assembly rather than the finished string
Many apps never hold the host as one literal. They concatenate a scheme, a host, a port and a path prefix, or they interpolate an environment name into a template. Search for the fragments instead of the whole value: the scheme, a domain suffix, the literal environment names, and any character sequence that looks like a prefix constant.
Single sign-on and content delivery add a second tier of hosts. Login flows often post to an identity host that differs from the application host, and images or documents come from object storage. A client built against one host will authenticate and then fail when it needs a signed asset URL from another.
Trace startup configuration
Read the application class and anything it initialises. A host selected at startup usually moves through a configuration object, a dependency injection module or a service locator. Follow the value to the place it is consumed, which is normally the HTTP client construction.
Some apps fetch their configuration before the first real call. A bootstrap or configuration request returns hosts, feature flags and sometimes signing parameters, and everything after that depends on the response. If that is the case, the host in the binary is a default and the live one may differ.
Environment switching makes this concrete. A debug build might read a developer override stored in preferences, while a release build uses the compiled default. Either path can produce the host at runtime, and the release path is the one that matters.
Confirm the host on the device
Reading code gives you candidates. The device tells you which one is in use.
- Watch DNS queries while the app starts. The domains it resolves are the hosts it intends to contact, including ones you have not found in code.
- Read the server certificate the connection presents. The subject and subject alternative names expose the real host and any others covered by the same certificate.
- Hook the client builder or the request construction and print the resolved URL for each call.
- Run the app under a controlled proxy after installing a certificate the app trusts, or instrument the process to bypass pinning, so the connection is visible.
Certificate pinning interrupts this step when an app pins a specific key. That is a transport-level obstacle rather than a configuration question, and it is worth separating the two in your notes because the fixes differ.
Record the host alongside its conditions
A host value without context is fragile. Note which build variant supplies it, whether a bootstrap response can replace it, which endpoints use a different host, and whether the value changes with an account, a region or a session. A client that hardcodes one host and ignores the conditions will work in testing and fail against a real account.
When the hosts and their conditions are known, the rest of the extraction is mechanical. The extraction work covers the host resolution together with the paths and the headers that go with them, so the result runs outside the app it came from.
Related work
Reviewed 28 September 2026 · SReverse research desk