Troubleshooting
Common failures during Android pentests and minimum-fix recipes.
Frida
"Failed to spawn: unable to find application"
Verify the exact package name.
adb shell pm list packages | grep <partial>
# or
list_installed_apps() # MCP"Failed to attach: process not found"
App isn't running — use frida_spawn(pkg) instead of frida_attach(pkg).
"Script terminated with error" — class/method not found
Likely obfuscation (class names become a, b, c…).
frida_enumerate_classes(pid, "*TargetClass*")Cross-reference jadx decompile to locate the renamed class.
Frida server crashes or version mismatch
frida --version # client version
# Download matching frida-server from github.com/frida/frida/releases
adb push frida-server /data/local/tmp/ && adb shell "su -c chmod 755 /data/local/tmp/frida-server"SSL pinning
Universal bypass does nothing
Custom pinner — decompile APK, search for certificate/pin/ssl/trust, then write a targeted hook. See workflows/ssl_pinning_bypass.md Method 2.
App still fails after bypass
Multiple pinning layers:
- Native SSL verification in
libssl.so— use Method 3 (SSL_CTX_set_custom_verify). - Frida-detection: run
anti_tampering_bypass.jsfirst. - Try
objection -g <pkg> explore→android sslpinning disable. - Consider embedding frida-gadget in the APK.
Root detection
App exits on launch with "rooted device"
frida_run_script(pid, "root_bypass.js")Additional layers:
- Enable Magisk Hide / Zygisk DenyList for the package.
- Native root checks → hook
fopen,access,statfrom libc. - Frida-gadget embedded in the APK for persistent injection.
App detects Frida itself
- Apply
anti_tampering_bypass.jsbefore other scripts. - Rename the
frida-serverbinary on device. - Hook
pthread_createto hide Frida threads.
ADB
"device unauthorized"
adb kill-server && adb start-server
# then accept the RSA key prompt on device"Permission denied" reading app data
adb root # userdebug builds only
adb shell su -c "cat /data/data/<pkg>/..." # rooted production devicesData extraction
SQLCipher-encrypted database
Capture the passphrase at open time:
frida_hook_method(pid, "net.sqlcipher.database.SQLiteDatabase", "openOrCreateDatabase")Or scan memory for PRAGMA key strings:
frida_memory_search(pid, "PRAGMA key")Files exist but are zero bytes after pull
Scoped storage (Android 10+) — use adb shell run-as <pkg> cat <path> on debuggable builds, or adb shell su -c cat on rooted devices.