Skip to content

Releases: sensepost/objection

v1.6.4

Choose a tag to compare

@leonjza leonjza released this 22 May 12:50
d3c8ba7

new

  • Add the ability to enumerate an iOS apps' included frameworks observable by NSBundle. This is available as the new ios bundles list_frameworks command.
  • Add a new --target-class flag to the Android patcher to inject a loadLibrary call for a Frida gadget in any arbitrary class' constructor (for example, to run before an applications onCreate()). The default is still to use the apps main launchable activity.
  • Add a new SSL Pinning bypass hook for iOS Cordova applications making use of this plugin. Thanks @aph3rson.

fixes

  • Improve application stability for the Android patcher when injecting a loadLibrary call into an existing class constructor by correctly incrementing the .locals count.

other

  • Bump agent dependencies

Code Changes Since v1.6.3

v1.6.3

Choose a tag to compare

@leonjza leonjza released this 11 Apr 06:58
391b590

new

  • Add the ability to enumerate the currently active Android activity. This can be done with the new android hooking get current_activity command.
  • Add a new R class helper to the agent for Android hooks.

fixes

  • Fix networked Frida connections. The the --host and --network flags will work again as intended.
  • Fix spawning on iOS (using a jailbroken environment) (thanks @aph3rson)

Code Changes Since v1.6.2

v1.6.2

Choose a tag to compare

@leonjza leonjza released this 02 Apr 07:12
0cca449

new

  • Add the ability to save modules and module exports as json.

fixes

  • Improve error handling when downloading Frida gadgets.

thanks

This release contains commits primarily contributed by @AV-IO 🎉

Code Changes Since v1.6.1

v1.6.1

Choose a tag to compare

@leonjza leonjza released this 01 Apr 06:37
32c1cab

fixes

  • Fix Frida remote connection capability. Specifying a host and port will be done in a future release.
  • Small typing fixes in the agent

Code Changes Since v1.6.0

v1.6.0 - Crash reporting, plugins and more!

Choose a tag to compare

@leonjza leonjza released this 29 Mar 11:52
0da9c79

new

  • Implement Frida crash reporting.
  • Add warnings before clearing the iOS keychain or the Android Keystore.
  • Report the Frida runtime in use as part of the frida command.
  • Add inspection of live instances of Java objects. This feature is available as a new command: android heap print_instances <class>.
  • Add an Android method searcher. This is available as a new command: android hooking search methods <search string>.
  • Add plugin support (thanks @SpeedyFireCyclone). For more information, see the wiki article here. Sample plugins can be seen here (Sample plugin used in tests), here (Stetho sideloader) and here (Objections clipboard monitor as a plugin).
  • Add the ability to delete files on an Android device. This is implemented as the rm command.

fixes

  • Fix class enumeration in the Android class watcher where methods with generics broke parsing.
  • Fix a cache key invalidation issue when uploading files.

Code Changes Since v1.5.4

v1.5.4

Choose a tag to compare

@leonjza leonjza released this 22 Mar 15:56
3f63fa5

fixes

  • Enumerate writable pages when searching memory with the memory search command

new

  • Improve the visual feedback of the memory search command. Small hexdump snippets will now be returned unless the --offsets-only flag is provided.

other

  • Bump the Frida agents' dependencies.

Code Changes Since v1.5.3

v1.5.3

Choose a tag to compare

@leonjza leonjza released this 18 Mar 17:26
008e327

fixes

  • Various path related fixes. #200
  • Reintroduce the import command to load external Frida scripts #196

other

Upgrade node dependencies for the agent, primarily bumping the frida-gum-types version to ^4. 613be5a

Code Changes Since v1.5.2

v.1.5.2 - Bug fixes

Choose a tag to compare

@leonjza leonjza released this 25 Feb 19:06
805bf86

fixes

  • Fix the iOS generic method return value override module. #193
  • Fix agent loading on operating systems that don't use UTF-8 encoding by default. #191

Thanks goes to @aph3rson for the fixes in this release.

Code Changes Since v1.5.1

v1.5.1

Choose a tag to compare

@leonjza leonjza released this 25 Feb 06:14
d000679

fixes

  • Fix an agent error condition when iOS AFNetworking was not available. #189
  • Small flow control and code simplification changes in the agent.
  • Fix various typos.

Code Changes Since v1.5.0

v1.5.0 - TypeScript agent, API and more!

Choose a tag to compare

@leonjza leonjza released this 22 Feb 20:21
ee7b75a

new

  • Completely rewritten Frida agent using TypeScript. All of the old hooks have been ported into this agent, replacing the old method of constantly loading and unloading Frida scripts with a single instance exposing methods via the Frida RPC.
  • An API! Read more about that here.
  • Support spawning Android applications when running on a rooted Android device.
  • Job output is no longer a single, random colour, but instead contains a job ID and more useful colouring of the overall output.
  • Include new SSL pinning disabling hooks.
  • Add command fuzzy completion.
  • Upgrade dependencies, most notably, prompt-toolkit to version 2.

fixes

  • A crazy amount of hook specific bug fixes (no really). This is primarily thanks to the TypeScript agent port work together with the help of the frida-gum TypeScript type definitions.
  • Vastly improved filesystem interactions for both Android and iOS, primarily when uploading/downloading files.
  • Better error reporting when the Frida server (both in a Gadget mode and server mode) goes away/crashes.
  • Improved data decoding for the iOS keychain dumping module.
  • Added a check when using --skip-resources flag for the APK builder to not try and inject the Internet permission.
  • Fix the directory separator when using on Windows.
  • Improve error handling when dumping memory regions.

Code Changes Since v1.4.1