adb-commands.md (8852B)
1 --- 2 title: "ADB Commands" 3 section: "Mobile" 4 sectionSlug: "mobile-pentesting" 5 sourcePath: "src/mobile-pentesting/android-app-pentesting/adb-commands.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/mobile-pentesting/android-app-pentesting/adb-commands.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # ADB Commands 14 15 **Adb is usually located in:** 16 17 ```bash 18 #Windows 19 C:\Users\<username>\AppData\Local\Android\sdk\platform-tools\adb.exe 20 21 #MacOS 22 /Users/<username>/Library/Android/sdk/platform-tools/adb 23 ``` 24 25 **Information obtained from:** [**http://adbshell.com/**](http://adbshell.com)<sup>[[1]](#references)</sup> 26 27 ## Connection 28 29 ```text 30 adb devices 31 ``` 32 33 This will list the connected devices; if "_**unathorised**_" appears, this means that you have to **unblock** your **mobile** and **accept** the connection. 34 35 This indicates to the device that it has to start and adb server in port 5555: 36 37 ```text 38 adb tcpip 5555 39 ``` 40 41 Connect to that IP and that Port: 42 43 ```text 44 adb connect <IP>:<PORT> 45 ``` 46 47 If you get an error like the following in a Virtual Android software (like Genymotion): 48 49 ```text 50 adb server version (41) doesn't match this client (36); killing... 51 ``` 52 53 It's because you are trying to connect to an ADB server with a different version. Just try to find the adb binary the software is using (go to `C:\Program Files\Genymobile\Genymotion` and search for adb.exe) 54 55 ### Several devices 56 57 Whenever you find **several devices connected to your machine** you will need to **specify in which one** you want to run the adb command. 58 59 ```bash 60 adb devices 61 List of devices attached 62 10.10.10.247:42135 offline 63 127.0.0.1:5555 device 64 ``` 65 66 ```bash 67 adb -s 127.0.0.1:5555 shell 68 x86_64:/ # whoami 69 root 70 ``` 71 72 ### Port Tunneling 73 74 In case the **adb** **port** is only **accessible** from **localhost** in the android device but **you have access via SSH**, you can **forward the port 5555** and connect via adb: 75 76 ```bash 77 ssh -i ssh_key username@10.10.10.10 -L 5555:127.0.0.1:5555 -p 2222 78 adb connect 127.0.0.1:5555 79 ``` 80 81 ## Packet Manager 82 83 ### Install/Uninstall 84 85 #### adb install \[option] \<path> 86 87 ```bash 88 adb install test.apk 89 90 adb install -l test.apk # forward lock application 91 92 adb install -r test.apk # replace existing application 93 94 adb install -t test.apk # allow test packages 95 96 adb install -s test.apk # install application on sdcard 97 98 adb install -d test.apk # allow version code downgrade 99 100 adb install -p test.apk # partial application install 101 ``` 102 103 #### adb uninstall \[options] \<PACKAGE> 104 105 ```bash 106 adb uninstall com.test.app 107 108 adb uninstall -k com.test.app Keep the data and cache directories around after package removal. 109 ``` 110 111 ### Packages 112 113 Prints all packages, optionally only those whose package name contains the text in \<FILTER>. 114 115 #### adb shell pm list packages \[options] \<FILTER-STR> 116 117 ```bash 118 adb shell pm list packages <FILTER-STR> 119 120 adb shell pm list packages -f <FILTER-STR> #See their associated file. 121 122 adb shell pm list packages -d <FILTER-STR> #Filter to only show disabled packages. 123 124 adb shell pm list packages -e <FILTER-STR> #Filter to only show enabled packages. 125 126 adb shell pm list packages -s <FILTER-STR> #Filter to only show system packages. 127 128 adb shell pm list packages -3 <FILTER-STR> #Filter to only show third party packages. 129 130 adb shell pm list packages -i <FILTER-STR> #See the installer for the packages. 131 132 adb shell pm list packages -u <FILTER-STR> #Also include uninstalled packages. 133 134 adb shell pm list packages --user <USER_ID> <FILTER-STR> #The user space to query. 135 ``` 136 137 #### adb shell pm path \<PACKAGE> 138 139 Print the path to the APK of the given . 140 141 ```bash 142 adb shell pm path com.android.phone 143 ``` 144 145 #### adb shell pm clear \<PACKAGE> 146 147 Delete all data associated with a package. 148 149 ```bash 150 adb shell pm clear com.test.abc 151 ``` 152 153 ## File Manager 154 155 ### adb pull \<remote> \[local] 156 157 Download a specified file from an emulator/device to your computer. 158 159 ```bash 160 adb pull /sdcard/demo.mp4 ./ 161 ``` 162 163 ### adb push \<local> \<remote> 164 165 Upload a specified file from your computer to an emulator/device. 166 167 ```bash 168 adb push test.apk /sdcard 169 ``` 170 171 ## Screencapture/Screenrecord 172 173 ### adb shell screencap \<filename> 174 175 Taking a screenshot of a device display. 176 177 ```bash 178 adb shell screencap /sdcard/screen.png 179 ``` 180 181 ### adb shell screenrecord \[options] \<filename> 182 183 Recording the display of devices running Android 4.4 (API level 19) and higher. 184 185 ```bash 186 adb shell screenrecord /sdcard/demo.mp4 187 adb shell screenrecord --size <WIDTHxHEIGHT> 188 adb shell screenrecord --bit-rate <RATE> 189 adb shell screenrecord --time-limit <TIME> #Sets the maximum recording time, in seconds. The default and maximum value is 180 (3 minutes). 190 adb shell screenrecord --rotate # Rotates 90 degrees 191 adb shell screenrecord --verbose 192 ``` 193 194 (press Ctrl-C to stop recording) 195 196 **You can download the files (images and videos) using **_**adb pull**_ 197 198 ## Shell 199 200 ### adb shell 201 202 Get a shell inside the device 203 204 ```bash 205 adb shell 206 ``` 207 208 ### adb shell \<CMD> 209 210 Execute a command inside the device 211 212 ```bash 213 adb shell ls 214 ``` 215 216 ## pm 217 218 The following commands are executed inside of a shell 219 220 ```bash 221 pm list packages #List installed packages 222 pm path <package name> #Get the path to the apk file of tha package 223 am start [<options>] #Start an activity. Whiout options you can see the help menu 224 am startservice [<options>] #Start a service. Whiout options you can see the help menu 225 am broadcast [<options>] #Send a broadcast. Whiout options you can see the help menu 226 input [text|keyevent] #Send keystrokes to device 227 ``` 228 229 ## Processes 230 231 If you want to get the PID of the process of your application you can execute: 232 233 ```bash 234 adb shell ps 235 ``` 236 237 And search for your application 238 239 Or you can do 240 241 ```bash 242 adb shell pidof com.your.application 243 ``` 244 245 And it will print the PID of the application 246 247 ## System 248 249 ```bash 250 adb root 251 ``` 252 253 Restarts the adbd daemon with root permissions. Then, you have to conenct again to the ADB server and you will be root (if available) 254 255 ```bash 256 adb sideload <update.zip> 257 ``` 258 259 flashing/restoring Android update.zip packages. 260 261 ## Logs 262 263 ### Logcat 264 265 To **filter the messages of only one application**, get the PID of the application and use grep (linux/macos) or findstr (windows) to filter the output of logcat: 266 267 ```bash 268 adb logcat | grep 4526 269 adb logcat | findstr 4526 270 ``` 271 272 #### adb logcat \[option] \[filter-specs] 273 274 ```bash 275 adb logcat 276 ``` 277 278 Notes: press Ctrl-C to stop monitor 279 280 ```bash 281 adb logcat *:V # lowest priority, filter to only show Verbose level 282 283 adb logcat *:D # filter to only show Debug level 284 285 adb logcat *:I # filter to only show Info level 286 287 adb logcat *:W # filter to only show Warning level 288 289 adb logcat *:E # filter to only show Error level 290 291 adb logcat *:F # filter to only show Fatal level 292 293 adb logcat *:S # Silent, highest priority, on which nothing is ever printed 294 ``` 295 296 #### adb logcat -b \<Buffer> 297 298 ```bash 299 adb logcat -b # radio View the buffer that contains radio/telephony related messages. 300 301 adb logcat -b # event View the buffer containing events-related messages. 302 303 adb logcat -b # main default 304 305 adb logcat -c # Clears the entire log and exits. 306 307 adb logcat -d # Dumps the log to the screen and exits. 308 309 adb logcat -f test.logs # Writes log message output to test.logs . 310 311 adb logcat -g # Prints the size of the specified log buffer and exits. 312 313 adb logcat -n <count> # Sets the maximum number of rotated logs to <count>. 314 ``` 315 316 ### dumpsys 317 318 dumps system data 319 320 #### adb shell dumpsys \[options] 321 322 ```bash 323 adb shell dumpsys 324 325 adb shell dumpsys meminfo 326 327 adb shell dumpsys battery 328 ``` 329 330 Notes: A mobile device with Developer Options enabled running Android 5.0 or higher. 331 332 ```bash 333 adb shell dumpsys batterystats collects battery data from your device 334 ``` 335 336 Notes: [Battery Historian](https://github.com/google/battery-historian) converts that data into an HTML visualization. **STEP 1** _adb shell dumpsys batterystats > batterystats.txt_ **STEP 2** _python historian.py batterystats.txt > batterystats.html_ 337 338 ```bash 339 adb shell dumpsys batterystats --reset erases old collection data 340 ``` 341 342 adb shell dumpsys activity 343 344 ## Backup 345 346 Backup an android device from adb. 347 348 ```bash 349 adb backup [-apk] [-shared] [-system] [-all] -f file.backup 350 # -apk -- Include APKs from third-party applications 351 # -shared -- Include removable storage 352 # -system -- Include system applications 353 # -all -- Include all the applications 354 355 adb shell pm list packages -f -3 #List packages 356 adb backup -f myapp_backup.ab -apk com.myapp # backup on one device 357 adb restore myapp_backup.ab # restore to the same or any other device 358 ``` 359 360 If you want to inspect the content of the backup: 361 362 ```bash 363 ( printf "\x1f\x8b\x08\x00\x00\x00\x00\x00" ; tail -c +25 myapp_backup.ab ) | tar xfvz - 364 ``` 365 366 ## References 367 368 - [1] [ADB Shell - Android ADB Commands Manual](http://adbshell.com/)