Frida and Dynamic Analysis
Frida is the central tool of dynamic mobile pentesting: an instrumentation toolkit that injects JavaScript into a running app’s process, letting you intercept and modify function calls, read and change variables in memory, bypass checks (root/jailbreak detection, SSL pinning), and understand what the app does internally in real time. It’s what turns “reading the code” into “controlling the app while it runs.”
What it enables
Section titled “What it enables”- Hooking: intercept any function (native, Java, Objective-C/Swift) before/after it runs- Read/modify arguments, return values, and variables in memory- Call the app's internal functions from outside- Bypass checks: root/jailbreak detection, SSL pinning, anti-debugging- Dump secrets, encryption keys, decrypted data from memoryInstall and start
Section titled “Install and start”# on the computerpip install frida-tools# on the device# Android (root): a frida-server matching the version; run itadb push frida-server /data/local/tmp/ ; adb shell "/data/local/tmp/frida-server &"# iOS (jailbreak): install Frida from Cydia/Sileo# list processes/appsfrida-ps -U # device processes (USB)frida-ps -Ua # installed appsObjection: Frida without writing scripts
Section titled “Objection: Frida without writing scripts”Objection wraps Frida with ready-made commands for the most common tasks:
objection -g com.target.app explore# inside:android hooking list classes # list classesandroid hooking watch class com.target.Crypto # watch a classandroid sslpinning disable # bypass SSL pinningandroid root disable # bypass root detectionandroid keystore list ; ios keychain dump # secretsmemory search / dump # search memoryObjection is the starting point; for specific logic you write Frida scripts.
Frida scripts (custom hooking)
Section titled “Frida scripts (custom hooking)”# Android (Java): hook a method and see/change its behaviorJava.perform(function() { var Login = Java.use("com.target.LoginManager"); Login.checkPassword.implementation = function(pw) { console.log("entered password: " + pw); // intercept return true; // force login OK };});# iOS (Objective-C): hook a methodInterceptor.attach(ObjC.classes.LoginManager["- isValid:"].implementation, { onEnter: function(args) { ... }, onLeave: function(ret) { ret.replace(0x1); } // force true});# run the scriptfrida -U -f com.target.app -l script.js --no-pausePentest use cases
Section titled “Pentest use cases”# bypass client-side protections (which should NEVER be the only security)- SSL pinning bypass (see mob-ssl)- root/jailbreak detection bypass- biometrics / local PIN bypass# extract secrets at runtime- encryption keys, decrypted data, tokens in memory# understand/force logic- change return values (isPremium -> true), skip validations# discover the internal flow and feed the backend attackDetection and anti-Frida (what you’ll see)
Section titled “Detection and anti-Frida (what you’ll see)”Some apps detect Frida (ports, thread names, frida-gadget) or use anti-debugging. It can be evaded (anti-anti-Frida scripts, rename frida-server, gadget), but remember: these protections raise the cost, they don’t replace backend security.
For the defense
Section titled “For the defense”- Don’t trust client-side checks (pinning, root/jailbreak, local biometrics): an attacker with Frida bypasses them. Real security is in the backend.
- RESILIENCE (MASVS): instrumentation/Frida detection, anti-debugging, code integrity, obfuscation — as layers that raise the cost, not an absolute barrier.
- Minimal sensitive data in memory/client; encryption with non-extractable keys (hardware-backed keystore/Secure Enclave).
- Assume the device can be compromised: always validate and authorize on the server.
Testing checklist
Section titled “Testing checklist”- frida-server/gadget running and app detected (frida-ps)
- Objection: explore, list classes, basic hooks
- Bypass SSL pinning (SSL Pinning and Bypass) and root/jailbreak detection
- Custom hooks: intercept key arguments/returns
- Extract secrets/keys/decrypted data from memory
- Force logic (isPremium, validations, login)
- Evade anti-Frida if the app implements it
- Use what’s learned to attack the backend (Web section)