FRIDA
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Dynamic instrumentation toolkit for mobile and native app testing: hooking, tracing and bypassing client-side controls on apps you own or are authorized to assess.
INSTALL & SETUP#
pip install frida-tools frida
frida --version
Android (rooted or with a repackaged app):
# Push matching frida-server to device
adb push frida-server /data/local/tmp/
adb shell "chmod 755 /data/local/tmp/frida-server"
adb shell "/data/local/tmp/frida-server &"
iOS (jailbroken): install frida via Cydia/Sileo, connect over USB.
ENUMERATION#
frida-ps -U # processes on USB device
frida-ps -Ua # running apps
frida-ps -Uai # installed apps (with identifiers)
frida-ls-devices
ATTACH / SPAWN#
frida -U -f com.example.app -l hook.js --no-pause # spawn + load
frida -U com.example.app -l hook.js # attach
frida -U -n Twitter # by name
TRACING (frida-trace)#
frida-trace -U -f com.example.app -i "open" -i "recv"
frida-trace -U -n app -m "-[NSURLSession *]" # ObjC methods
frida-trace -U -n app -j 'com.example.*!*' # Java classes (Android)
ANDROID (JAVA) HOOKS#
Java.perform(function () {
var MainActivity = Java.use('com.example.app.MainActivity');
MainActivity.checkLicense.implementation = function () {
console.log('[+] checkLicense called, forcing true');
return true;
};
// Enumerate loaded classes
Java.enumerateLoadedClasses({ onMatch: function (n) { console.log(n); },
onComplete: function () {} });
// Instantiate & call
Java.choose('com.example.app.Session', {
onMatch: function (i) { console.log('token=', i.token.value); },
onComplete: function () {} });
});
NATIVE (C/OBJC) HOOKS#
// Intercept an exported function
Interceptor.attach(Module.getExportByName(null, 'strcmp'), {
onEnter: function (args) {
console.log('strcmp', args[0].readUtf8String(), args[1].readUtf8String());
},
onLeave: function (retval) { /* retval.replace(0); */ }
});
// Read/patch memory
Memory.protect(ptr('0x...'), 16, 'rwx');
COMMON BYPASSES (client-side controls)#
Root/jailbreak detection, SSL pinning, emulator/debugger checks:
frida --codeshare pcipolloni/universal-android-ssl-pinning-bypass-with-frida -U -f <app>
objection -g <app> explore
android sslpinning disable
android root disable
ios sslpinning disable
ios jailbreak disable
These are for testing apps in scope (your own, or with permission).
OBJECTION (frida wrapper)#
objection -g com.example.app explore
env # app environment / paths
android hooking list classes
android hooking search methods <keyword>
memory dump all app.bin
ios keychain dump
PREVENTION (blue side)#
- Client-side checks only slow attackers; enforce on the server.
- Use Play Integrity / DeviceCheck, obfuscation, anti-instrumentation
as defense-in-depth, not sole controls.
See also: MOBILE-PENTESTING, MOBILE-REVERSE-ENG, OWASP-MOBILE-TOP10, GHIDRA.