Skip to main content

Objection

Objection is a runtime mobile-exploration toolkit that wraps Frida into a friendly REPL. It saves you from writing custom hooks for the common cases: SSL pinning, jailbreak detection, app storage browsing, and memory patching.

Install and Connect​

pip3 install objection
objection --help

Connect to a running app by name or bundle ID:

# Attach to a process on a USB device
objection -g com.example.app explore

# Attach by PID
objection -g 1234 explore

# Spawn a new instance (simulator or via gadget)
objection -g com.example.app --startup-command "ios jailbreak disable" explore

For the simulator, target the process the same way (no -U device flag needed):

objection -g "ExampleApp" explore

SSL Pinning Bypass​

The single most-used command in an iOS test:

(objection) ios sslpinning disable

This hooks the common SSL verification methods so the app trusts Burp's CA. Confirm it worked by reloading the app's HTTPS traffic in Burp — you should now see decrypted requests in HTTP history.

If the app uses a custom pinning library, ios sslpinning disable may fail; fall back to Frida with a targeted script.

Jailbreak Detection Bypass​

(objection) ios jailbreak disable

Objection neutralizes a set of common jailbreak checks. This is usually enough to get the app running in "clean" mode on a jailbroken test device. For stubborn checks, layer a Frida hook on top.

Exploring App Storage​

Objection exposes the app sandbox and its databases without digging through the filesystem manually.

# Browse the app container like a shell
(objection) ls
(objection) cd Documents
(objection) cat plist/Config.plist

# Enumerate files, dirs, databases
(objection) ios storage list

# Interact with SQLite databases found in the sandbox
(objection) ios sqlite dump Documents/db.sqlite
(objection) ios sqlite sql Documents/db.sqlite "SELECT * FROM users"

Dump the whole data directory for offline review:

(objection) ios storage download all

Hooking and Method Exploration​

# List methods on a class (heavily used during enumeration)
(objection) ios hooking list classes | grep -i api
(objection) ios hooking list class_methods NSURLSession
(objection) ios hooking list methods com.example.app.APIClient

# Live hook a method and log arguments/return values
(objection) ios hooking watch class NSURLSession
(objection) ios hooking watch class com.example.app.APIClient --dump-args --dump-return

# Search loaded classes for a string (great for finding interesting logic)
(objection) ios hooking search classes NSURLCache
(objection) ios hooking search classes api

# Watch all methods on a class
(objection) ios hooking watch class ViewController

Memory search and patch:

# Search the app's memory for a string
(objection) memory search "secret_token"

# Patch a string in memory (e.g., change an endpoint or a debug flag)
(objection) memory patch 0x16d9b3a8 "https://attacker" "https://legit"

# List modules and symbols to find function addresses
(objection) memory list modules
(objection) memory list exports libapp.dylib

App Environment Info​

(objection) ios info binary        # binary info, entitlements
(objection) ios info plist # the app's Info.plist
(objection) ios info app # bundle id, version, container paths
(objection) ios info cookies # the app's cookies
(objection) ios info keychain # keychain items
(objection) ios info preferences # NSUserDefaults

Non-Jailbroken Devices​

Objection needs Frida to run. On stock iOS you inject FridaGadget.dylib into the IPA and launch the patched app:

# Download a prebuilt gadget (matches your frida version)
# https://github.com/frida/frida/releases (frida-gadget-<ver>-ios-universal.dylib)

# Inject into the binary (requires a decrypted IPA for App Store apps)
# Then launch via idevicedebug and attach with objection
objection -g com.example.app explore

ios jailbreak disable and other hooks work through the gadget as well, which is why this is the standard path on non-jailbroken test devices.

Report-Ready Output​

Every hook you enable can be logged. Keep a clean transcript for the report:

(objection) ios hooking watch class NSURLSession --dump-args --dump-return

Then reproduce the traffic and capture the log. Combine with Burp history and MobSF output for a complete evidence set.

Gotchas​

  • ios sslpinning disable does not disable ATS; if the app refuses plain HTTP, patch Info.plist (see the Burp Suite page).
  • Pin methods in SecTrustEvaluate and friends are covered by objection, but custom-pinned stacks may need a manual Frida hook.
  • Objection attaches to the running app; if the app crashes on attach, spawn with the gadget and --startup-command.
  • On iOS 16+, ensure Developer Mode is enabled before attaching Frida/objection to a physical device.