Workflow: Authentication & Session Testing
Maps to MASTG-TEST-0015/0016/0017. Requires SSL pinning already bypassed (see ssl_pinning_bypass.md).
1. Hook auth surface (parallel)
frida_hook_method(pid, "com.target.app.auth.AuthService", "login")
frida_hook_method(pid, "com.target.app.auth.TokenValidator", "validateToken")
frida_run_script(pid, "credential_hooks.js")2. Biometric bypass
frida_run_script(pid, "biometric_bypass.js")
# Drive the biometric prompt; script forces CryptoObject success callback.Checks: is success verified server-side, or only via local callback?
3. Session manipulation
frida_hook_method(pid, "com.target.app.session.SessionManager", "*")Look for: local JWT expiry checks, refresh without server round-trip, tokens kept after logout.
4. JWT analysis
frida_run_script(pid, """
Java.perform(function() {
var JWT = Java.use('com.auth0.jwt.JWT');
JWT.decode.implementation = function(token) {
console.log('[JWT] ' + token);
return this.decode(token);
};
});
""")Decode output at jwt.io — flag HS256 with guessable secret, alg=none, missing exp/iat, sensitive claims (pw hash, full PII).
5. Credential storage
dump_shared_prefs("com.target.app")
dump_databases("com.target.app")Look for plaintext tokens, password hints, PIN hashes, refresh tokens.
UI-driven flows
For OAuth redirects and multi-step MFA, use Mobile MCP get_screen_state + tap_element to drive the flow while hooks capture state transitions.
Reporting
Every finding: include MASTG ID, Frida PID, package, decoded JWT claims, and screenshot of the auth screen at point of bypass.