Workflow: Cryptography Analysis
Maps to MASTG-TEST-0013 / 0014 / 0018. Detect weak algos, hardcoded keys, non-Keystore key handling.
1. Global crypto trace
frida_run_script(pid, "crypto_hooks.js")Logs every Cipher.getInstance, MessageDigest, Mac, KeyGenerator, SecretKeySpec.
2. Flag weak primitives inline
frida_run_script(pid, """
Java.perform(function() {
var Cipher = Java.use('javax.crypto.Cipher');
Cipher.getInstance.overload('java.lang.String').implementation = function(algo) {
console.log('[CRYPTO] ' + algo);
if (algo.indexOf('ECB') !== -1) console.log('[!] WEAK: ECB mode');
if (algo.indexOf('DES') !== -1) console.log('[!] WEAK: DES');
if (algo.indexOf('RC4') !== -1) console.log('[!] WEAK: RC4');
if (algo.indexOf('MD5') !== -1) console.log('[!] WEAK: MD5');
return this.getInstance(algo);
};
});
""")3. Hardcoded key discovery
frida_memory_search(pid, "-----BEGIN RSA PRIVATE KEY-----")
frida_memory_search(pid, "-----BEGIN PRIVATE KEY-----")
frida_memory_search(pid, "AES_SECRET_KEY")Also grep the decompiled sources from pull_apk for key-looking constants.
4. Keystore usage audit
frida_run_script(pid, "keystore_hooks.js")Confirm: hardware-backed (isInsideSecureHardware()), setUserAuthenticationRequired(true), setInvalidatedByBiometricEnrollment(true).
5. Runtime key dump
frida_hook_method(pid, "javax.crypto.spec.SecretKeySpec", "$init")
frida_hook_method(pid, "javax.crypto.spec.IvParameterSpec", "$init")Common findings
| Pattern | Finding |
|---|---|
AES/ECB/* |
Weak mode — no semantic security |
| Static IV literal | IV reuse — GCM catastrophic, CBC leaky |
new SecretKeySpec("hardcoded...") |
Hardcoded key |
MD5/SHA1 for passwords |
Weak hash |
| Key in SharedPreferences plain | Key storage violation |