Android
Π‘ΡΡΠ»ΠΊΠΈ
ΠΠ΅ΡΠ΅ΠΊΡ Π±ΠΈΠ±Π»ΠΈΠΎΡΠ΅ΠΊΠΈ Π΄Π»Ρ ΠΏΠΈΠ½Π½ΠΈΠ½Π³Π°: https://codeshare.frida.re/@akabe1/frida-multiple-unpinning/
universal script unpinning: https://codeshare.frida.re/@pcipolloni/universal-android-ssl-pinning-bypass-with-frida/
ΠΠ°Π±ΠΎΡ ΡΠΊΡΠΈΠΏΡΠΎΠ²: https://github.com/m0bilesecurity/Frida-Mobile-Scripts https://github.com/LizhangHuang/FridaScript
ΠΠ·Π²Π»Π΅ΡΠ΅Π½ΠΈΠ΅ ΠΈΠ½ΡΠΎΡΠΌΠ°ΡΠΈΠΈ ΠΎ Bluetooth: https://github.com/k3170makan/FridaAndroidScripts/tree/master/bluecrawl
Π‘ΠΊΡΠΈΠΏΡΡ
Common
Π‘ΠΏΠΈΡΠΎΠΊ ΠΌΠ΅ΡΠΎΠ΄ΠΎΠ² ΠΈ ΠΏΠΎΠ»Π΅ΠΉ ΠΊΠ»Π°ΡΡΠ°
// Get class
const java_class = Java.use('com.example.j$R')
// Object cast
const java_class_obj = Java.cast(data, java_class)
// Get object via constructor
const java_class_obj = java_class.$new() // ΠΈΠ»ΠΈ java_class.$init()
// Methods
Java.enumerateMethods(`com.example.j$R!*/isu`) // Include method signatures (s) and User-defined classes only, ignoring system classes. (u) and case sensitive (i)
// All Fields and Methods names
Object.getOwnPropertyNames(java_class)
Object.getOwnPropertyNames(java_class_obj)ΠΠ±ΡΠ°ΡΠ΅Π½ΠΈΠ΅ ΠΊ ΠΏΡΠΈΠ²Π°ΡΠ½ΡΠΌ ΠΏΠΎΠ»ΡΠΌ
ΠΠ±ΡΠ°ΡΠ΅Π½ΠΈΠ΅ ΠΊ Π»ΡΠ±ΡΠΌ ΠΏΠΎΠ»ΡΠΌ ΠΎΠ±ΡΠ΅ΠΊΡΠ° ΠΏΠΎ ΠΈΠΌΠ΅Π½ΠΈ
ΠΠ½Π°ΡΠ΅Π½ΠΈΠ΅ ΠΏΠΎΠ»Ρ
Π Π°Π±ΠΎΡΠ° Ρ ΠΌΠ°ΡΡΠΈΠ²Π°ΠΌΠΈ
ΠΡΠ²Π΅ΡΡΠΈ ΠΌΠ°ΡΡΠΈΠ² ΠΊΠ°ΠΊ hex-ΡΡΡΠΎΠΊΡ:
ΠΡΠ²Π΅ΡΡΠΈ ΠΌΠ°ΡΡΠΈΠ² ΠΊΠ°ΠΊ ΡΡΡΠΎΠΊΡ:
ΠΡΠ²Π΅ΡΡΠΈ ΠΎΠ±ΡΠ΅ΠΊΡ
Wrapper
PhoneGap & Outsystem ssl pinning bypass
src: https://github.com/clviper/android/blob/master/pinning.js
OkHttp3 SSL Pinning bypass
Last updated
Was this helpful?