Android

Бсылки

Π”Π΅Ρ‚Π΅ΠΊΡ‚ Π±ΠΈΠ±Π»ΠΈΠΎΡ‚Π΅ΠΊΠΈ для ΠΏΠΈΠ½Π½ΠΈΠ½Π³Π°: https://codeshare.frida.re/@akabe1/frida-multiple-unpinning/

universal script unpinning: https://codeshare.frida.re/@pcipolloni/universal-android-ssl-pinning-bypass-with-frida/

Набор скриптов: https://github.com/m0bilesecurity/Frida-Mobile-Scripts https://github.com/LizhangHuang/FridaScript

Π˜Π·Π²Π»Π΅Ρ‡Π΅Π½ΠΈΠ΅ ΠΈΠ½Ρ„ΠΎΡ€ΠΌΠ°Ρ†ΠΈΠΈ ΠΎ Bluetooth: https://github.com/k3170makan/FridaAndroidScripts/tree/master/bluecrawl

Π‘ΠΊΡ€ΠΈΠΏΡ‚Ρ‹

Common

Бписок ΠΌΠ΅Ρ‚ΠΎΠ΄ΠΎΠ² ΠΈ ΠΏΠΎΠ»Π΅ΠΉ класса

// Get class
const java_class = Java.use('com.example.j$R')

// Object cast
const java_class_obj = Java.cast(data, java_class)

// Get object via constructor
const java_class_obj = java_class.$new() // ΠΈΠ»ΠΈ java_class.$init()

// Methods
Java.enumerateMethods(`com.example.j$R!*/isu`) // Include method signatures (s) and User-defined classes only, ignoring system classes. (u) and case sensitive (i)

// All Fields and Methods names
Object.getOwnPropertyNames(java_class)
Object.getOwnPropertyNames(java_class_obj)

ΠžΠ±Ρ€Π°Ρ‰Π΅Π½ΠΈΠ΅ ΠΊ ΠΏΡ€ΠΈΠ²Π°Ρ‚Π½Ρ‹ΠΌ полям

ΠžΠ±Ρ€Π°Ρ‰Π΅Π½ΠΈΠ΅ ΠΊ Π»ΡŽΠ±Ρ‹ΠΌ полям ΠΎΠ±ΡŠΠ΅ΠΊΡ‚Π° ΠΏΠΎ ΠΈΠΌΠ΅Π½ΠΈ

Π—Π½Π°Ρ‡Π΅Π½ΠΈΠ΅ поля

Π Π°Π±ΠΎΡ‚Π° с массивами

ВывСсти массив ΠΊΠ°ΠΊ hex-строку:

ВывСсти массив ΠΊΠ°ΠΊ строку:

ВывСсти ΠΎΠ±ΡŠΠ΅ΠΊΡ‚

Wrapper

PhoneGap & Outsystem ssl pinning bypass

src: https://github.com/clviper/android/blob/master/pinning.js

OkHttp3 SSL Pinning bypass

Last updated

Was this helpful?