Skip to content

绕过 frida 端口检测 ​

🚪 App 检测 frida 标准端口 27042,用非标准端口绕过。

思路 ​

frida-server 默认监听 27042,部分 App 扫描这个端口检测 frida。把 frida-server 开到非标准端口,用 -H 连接。

步骤 ​

1. frida-server 开非标准端口 ​

bash
adb shell "su -c '/data/local/tmp/frida-server -l 0.0.0.0:8888 &'"

2. adb forward 转发(若 USB 真机) ​

bash
adb forward tcp:8888 tcp:8888

3. r0capture 用 -H 连 ​

bash
python3 r0capture.py -H 127.0.0.1:8888 -f com.app -v -p out.pcap

进阶:frida-server 改名 ​

部分 App 还扫 /data/local/tmp/frida-server 文件名。改名:

bash
adb shell "cp /data/local/tmp/frida-server /data/local/tmp/abc"
adb shell "su -c '/data/local/tmp/abc -l 0.0.0.0:8888 &'"

进阶:magisk 模块隐藏 ​

  • MagiskHide / Shamiko 隐藏 root
  • frida-gadget 静态注入(不用 frida-server)

适用判断 ​

若 r0capture 抓普通 App 正常,唯独某 App 抓不到且该 App 有反调试,多半是检测了 frida。用本配方。

相关文档 ​

基于 VitePress 构建 · 教学用途