Skip to content
KitploitKITPLOIT
도구블로그
Log in
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
frida-snippets — 직접 제작한 Frida 예제 | Kitploit
도구/GitHubGitHub/iddoeldor/frida-snippets
Android SecurityDynamic Analysis (Sandboxing)iOS SecurityReverse EngineeringDebuggersMobile SecurityBinary Analysis
GitHubiddoeldor/frida-snippets

frida-snippets

직접 제작한 Frida 예제

저장소 보기
2.5k439201년 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

PRs Welcome & 출력 예제도 포함

목차

네이티브
  • C/C++ 모듈 로드
  • 일회성 워치포인트
  • 소켓 활동
  • open 인터셉트
  • 셸 명령 실행
  • 모듈 목록
  • SQLite 쿼리 기록
  • 메서드 인자 기록
  • 전체 모듈 인터셉트
  • 메모리 세그먼트 덤프
  • 메모리 스캔
  • Stalker
  • Cpp Demangler
  • 조기 후크
Android
  • Binder 트랜잭션
  • 시스템 속성 가져오기
  • 수동으로 등록된 네이티브 심볼 표시
  • 로드된 클래스 나열
  • 클래스 설명
  • WiFi 끄기
  • 프록시 설정
  • IMEI 가져오기
  • io InputStream 후크
  • Android Toast 띄우기
  • 특정 모듈 로드 대기
  • Webview URL
  • 모든 런타임 문자열 및 스택 트레이스 출력
  • SharedPreferences 업데이트 출력
  • 문자열 비교
  • 주소로 JNI 후크
  • 생성자 후크
  • Java reflection 후크
  • 클래스 추적
  • Unity3d 후킹
  • Android ID 가져오기
  • 위치 변경
  • FLAG_SECURE 우회
  • SharedPreferences 업데이트
  • 모든 메서드 오버로드 후크
  • 브로드캐스트 수신자 등록
  • 걸음 수 증가
  • 클래스 로더로 인터페이스를 구현하는 클래스 나열
  • 파일 시스템 접근 후크 $ frida --codeshare FrenchYeti/android-file-system-access-hook -f com.example.app --no-pause
  • Java 후크를 제거/비활성화하는 방법? implementation 속성에 null을 할당하세요.
iOS
  • OS 로그
  • iOS 알림창
  • 파일 접근
  • 클래스 관찰
  • 애플리케이션 UUID 찾기
  • 쿠키 추출
  • 클래스 멤버 설명
  • 클래스 계층 구조
  • reflection 후크
  • 기기 속성
  • 스크린샷 캡처
  • SSH 명령 기록
Windows

HAHAHA. No.

Sublime 스니펫
{
    "scope": "source.js",
    "completions": [
	{"trigger": "fridainterceptor", "contents": "Interceptor.attach(\n    ptr,\n    {\n        onEnter:function(args) {\n\n        },\n        onLeave: function(retval) {\n\n        }\n    }\n)"},
	{"trigger": "fridaperform", "contents": "function main(){\n    console.log('main()');\n}\n\nconsole.log('script loaded');\nJava.perform(main);"},
	{"trigger": "fridause", "contents": "var kls = Java.use('kls');"},
	{"trigger": "fridahex", "contents": "hexdump(\n    ptr,\n    {\n         offset: 0,\n         length: ptr_size\n     }\n);" },
	{"trigger": "fridabacktrace", "contents": "console.log('called from:\\n' +\n        Thread.backtrace(this.context, Backtracer.ACCURATE)\n        .map(DebugSymbol.fromAddress).join('\\n') + '\\n'\n);"},
	{"trigger": "fridamods", "contents": "var mods = Process.enumerateModules().filter(function(mod){\n    return mod.name.includes(\"<name>\");\n});"},
	{"trigger": "fridaexport", "contents": "Module.findExportByName(null, \"<export_name>\");"},
	{"trigger": "fridabase", "contents": "Module.findBaseAddress(name);"},
	{"trigger": "fridaoverload", "contents": "kls.method_name.overload().implementation=function(){}"}
    ]
}
Vim 스니펫

약어를 나열하려면 :ab

key와 <Space>를 입력해 확장합니다

  • ~/.vimrc에 추가``` ab fridaintercept Interceptor.attach(ptr, {onEnter: function(args) {},onLeave: function(retval) {}}) ab fridabacktrace console.warn(Thread.backtrace(this.context, Backtracer.ACCURATE).map(DebugSymbol.fromAddress).join('\n'));F(3; ab fridadescribe console.log(Object.getOwnPropertyNames(Java.use('$').proto).join('\n\t'))F$
</details>


<details>
<summary>JEB</summary>	

키보드 단축키를 사용하는 Java 메서드 훅 생성기

1. `curl -o ~/$JEB$/scripts/FridaCodeGenerator.py https://raw.githubusercontent.com/iddoeldor/frida-snippets/master/scripts/FridaCodeGenerator.py` 
2. Java 메서드 시그니처에 커서를 놓습니다.
3. `Ctrl+Shift+Z`를 누릅니다.
4. 코드가 시스템 클립보드에 복사됩니다(`xclip` 사용).


</details>
<hr />
	

#### SSL 키 가져오기```js
var keylog_callback = new NativeCallback((ssl, line) => {
  send(Memory.readCString(line));
}, 'void', ['pointer', 'pointer']);

if (ObjC.available) {
  var CALLBACK_OFFSET = 0x2A8
  if (Memory.readDouble(Module.findExportByName('CoreFoundation', 'kCFCoreFoundationVersionNumber')) >= 1751.108) {
    CALLBACK_OFFSET = 0x2B8
  }
  Interceptor.attach(Module.findExportByName('libboringssl.dylib', 'SSL_CTX_set_info_callback'), {
    onEnter(args) {
      ptr(args[0]).add(CALLBACK_OFFSET).writePointer(keylog_callback)
    }
  })
} else if (Java.available) {
  var set_keylog_callback = new NativeFunction(Module.findExportByName('libssl.so', 'SSL_CTX_set_keylog_callback'), 'void', ['pointer', 'pointer']);
  Interceptor.attach(Module.findExportByName('libssl.so', 'SSL_CTX_new'), {
    onLeave(retval) {
      set_keylog_callback(retval, keylog_callback)
    }
  })
}


⬆ Back to top

CPP 모듈 로드```cpp

#include #include

extern "C" { void* create_stdstr(char data, int size) { std::string s = new std::string(); (*s).assign(data, size); return s; } }

### 사용하지 않는 환경 변수를 탐지, 표시, 보호하여 보안 강화```sh
$ ./android-ndk/toolchains/llvm/prebuilt/linux-x86_64/bin/aarch64-linux-android21-clang++ a.cpp -o a -shared -static-libstdc++ && adb push a /data/local/tmp/a

번역할 Markdown 콘텐츠가 제공되지 않았습니다.```js [device]-> function readStdString(str) { if ((str.readU8() & 1) === 1) { // size LSB (=1) indicates if it's a long string return str.add(2 * Process.pointerSize).readPointer().readUtf8String();
} return str.add(1).readUtf8String();
} [device]-> Module.load('/data/local/tmp/a'); [device]-> var fp_create_stdstr = Module.findExportByName('a', 'create_stdstr'); [device]-> var createStdString = new NativeFunction(fp_create_stdstr, 'pointer', ['pointer', 'int']); [device]-> var stdstr1 = createStdString(Memory.allocUtf8String("abcd"), 3); "0x07691234567" [device]-> readStdString(stdstr1); "abc"

#### C 모듈 로드

* https://frida.re/docs/javascript-api/#cmodule
* https://frida.re/news/2019/09/18/frida-12-7-released/```sh
$ ./aarch64-linux-android21-clang /tmp/b.c -o /tmp/a -shared ../sysroot/usr/lib/aarch64-linux-android/21/liblog.so && adb push /tmp/a /data/local/tmp/a

I don't see any content to translate — the input after "INPUT:" is empty. Please provide chunk 13 of 166 and I'll translate it into Korean.```c #include <stdio.h> #include <stdlib.h> #include <android/log.h>

#define TAG "TEST1" #define LOGI(...) __android_log_print(ANDROID_LOG_INFO, TAG, VA_ARGS) #define LOGE(...) __android_log_print(ANDROID_LOG_ERROR, TAG, VA_ARGS)

void test(void) { FILE* fp = popen("ls -l /sdcard 2>&1", "r"); if (fp == NULL) LOGE("executing cmd failed"); char b[256]; while (fgets(b, sizeof(b), fp) != NULL) { LOGI("%s", b); } pclose(fp); }

The input chunk is empty — no source text was provided to translate.```sh
$ frida -Uf com.app --no-pause --enable-jit -e "Module.load('/data/local/tmp/a')"
[ ] -> new NativeFunction(Module.findExportByName('a', 'test'), 'void', [])()


⬆ Back to top

일회성 워치포인트

도구 다운로드