Example: Authentication Bypass
Goal: find logic flaws in login, biometric, and session handling.
Tool-call blueprint
frida_run_script(pid, "credential_hooks.js")
frida_run_script(pid, "biometric_bypass.js")
frida_hook_method(pid, "com.megabank.mobile.auth.SessionManager", "*")
frida_run_script(pid, """
Java.perform(function() {
var JWT = Java.use('com.auth0.jwt.JWT');
JWT.decode.implementation = function(t) { console.log('[JWT] ' + t); return this.decode(t); };
});
""")Observations to flag
credential_hooks.js: password written to SharedPreferences, token appears inAuthorization: Bearer …headerbiometric_bypass.js:BiometricPrompt.authenticate()success callback invoked without server verification → bypassSessionManager.*:validateSession()only checks local JWT expiry;refreshSession()skips server round-trip- JWT decode:
alg=HS256with low-entropy secret, claims includeaccount_id,role,permissions
Findings table
| Issue | Severity | MASTG | Impact |
|---|---|---|---|
| Biometric bypass (client-only) | HIGH | MASTG-TEST-0015 | Full account access |
| Client-side session validation | HIGH | MASTG-TEST-0016 | Persistent unauth access |
| Weak JWT algorithm + sensitive claims | MEDIUM | MASTG-TEST-0014 | Token forgery |
UI-driven repro
Use Mobile MCP get_screen_state → tap_element to replay the biometric prompt while hooks are active; capture a screenshot at the unlocked-home state as evidence.