← All cheat sheets

FRIDA

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Dynamic instrumentation toolkit for mobile and native app testing:
hooking, tracing and bypassing client-side controls on apps you own or
are authorized to assess.

INSTALL & SETUP#

    pip install frida-tools frida
    frida --version

  Android (rooted or with a repackaged app):
    # Push matching frida-server to device
    adb push frida-server /data/local/tmp/
    adb shell "chmod 755 /data/local/tmp/frida-server"
    adb shell "/data/local/tmp/frida-server &"

  iOS (jailbroken): install frida via Cydia/Sileo, connect over USB.

ENUMERATION#

    frida-ps -U                 # processes on USB device
    frida-ps -Ua                # running apps
    frida-ps -Uai               # installed apps (with identifiers)
    frida-ls-devices

ATTACH / SPAWN#

    frida -U -f com.example.app -l hook.js --no-pause    # spawn + load
    frida -U com.example.app -l hook.js                  # attach
    frida -U -n Twitter                                  # by name

TRACING (frida-trace)#

    frida-trace -U -f com.example.app -i "open" -i "recv"
    frida-trace -U -n app -m "-[NSURLSession *]"         # ObjC methods
    frida-trace -U -n app -j 'com.example.*!*'           # Java classes (Android)

ANDROID (JAVA) HOOKS#

    Java.perform(function () {
      var MainActivity = Java.use('com.example.app.MainActivity');
      MainActivity.checkLicense.implementation = function () {
        console.log('[+] checkLicense called, forcing true');
        return true;
      };
      // Enumerate loaded classes
      Java.enumerateLoadedClasses({ onMatch: function (n) { console.log(n); },
                                    onComplete: function () {} });
      // Instantiate & call
      Java.choose('com.example.app.Session', {
        onMatch: function (i) { console.log('token=', i.token.value); },
        onComplete: function () {} });
    });

NATIVE (C/OBJC) HOOKS#

    // Intercept an exported function
    Interceptor.attach(Module.getExportByName(null, 'strcmp'), {
      onEnter: function (args) {
        console.log('strcmp', args[0].readUtf8String(), args[1].readUtf8String());
      },
      onLeave: function (retval) { /* retval.replace(0); */ }
    });
    // Read/patch memory
    Memory.protect(ptr('0x...'), 16, 'rwx');

COMMON BYPASSES (client-side controls)#

  Root/jailbreak detection, SSL pinning, emulator/debugger checks:
    frida --codeshare pcipolloni/universal-android-ssl-pinning-bypass-with-frida -U -f <app>
    objection -g <app> explore
      android sslpinning disable
      android root disable
      ios sslpinning disable
      ios jailbreak disable

  These are for testing apps in scope (your own, or with permission).

OBJECTION (frida wrapper)#

    objection -g com.example.app explore
      env                          # app environment / paths
      android hooking list classes
      android hooking search methods <keyword>
      memory dump all app.bin
      ios keychain dump

PREVENTION (blue side)#

  - Client-side checks only slow attackers; enforce on the server.
  - Use Play Integrity / DeviceCheck, obfuscation, anti-instrumentation
    as defense-in-depth, not sole controls.

  See also: MOBILE-PENTESTING, MOBILE-REVERSE-ENG, OWASP-MOBILE-TOP10, GHIDRA.