daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

avd-android-virtual-device.md (13843B)


      1 ---
      2 title: "AVD - Android Virtual Device"
      3 section: "Mobile"
      4 sectionSlug: "mobile-pentesting"
      5 sourcePath: "src/mobile-pentesting/android-app-pentesting/avd-android-virtual-device.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/mobile-pentesting/android-app-pentesting/avd-android-virtual-device.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # AVD - Android Virtual Device
     14 
     15 Thank you very much to [**@offsecjay**](https://twitter.com/offsecjay) for his help while creating this content.
     16 
     17 ## What is
     18 
     19 Android Studio can run Android Virtual Devices (AVDs) for testing APKs. An AVD defines the hardware profile, system image, storage, skin, and other characteristics used by the Android Emulator.<sup>[[4]](#references)</sup> To use one, install:
     20 
     21 - The **Android SDK tools** - [Download here](https://developer.android.com/studio/releases/sdk-tools).
     22 - Or **Android Studio** (with Android SDK tools) - [Download here](https://developer.android.com/studio).
     23 
     24 In Windows (in my case) **after installing Android Studio** I had the **SDK Tools installed in**: `C:\Users\<UserName>\AppData\Local\Android\Sdk\tools`
     25 
     26 In mac you can **download the SDK tools** and have them in the PATH running:
     27 
     28 ```bash
     29 brew tap homebrew/cask
     30 brew install --cask android-sdk
     31 ```
     32 
     33 Or from **Android Studio GUI** as indicated in [https://stackoverflow.com/questions/46402772/failed-to-install-android-sdk-java-lang-noclassdeffounderror-javax-xml-bind-a](https://stackoverflow.com/questions/46402772/failed-to-install-android-sdk-java-lang-noclassdeffounderror-javax-xml-bind-a) which will install them in `~/Library/Android/sdk/cmdline-tools/latest/bin/` and `~/Library/Android/sdk/platform-tools/` and `~/Library/Android/sdk/emulator/`
     34 
     35 For the Java problems:
     36 
     37 ```java
     38 export JAVA_HOME=/Applications/Android\ Studio.app/Contents/jbr/Contents/Home
     39 ```
     40 
     41 ## GUI
     42 
     43 ### Prepare Virtual Machine
     44 
     45 In current Android Studio versions, open **View** → **Tool Windows** → **Device Manager**, then select **Create Virtual Device**. Older versions exposed the same workflow as **Tools** → **AVD Manager**.<sup>[[4]](#references)</sup>
     46 
     47 <div align="center" data-full-width="false">
     48 
     49 <figure><img src="https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%281142%29.png" alt="" width="293"><figcaption></figcaption></figure>
     50 
     51 </div>
     52 
     53 Then, click on _**Create Virtual Device**_
     54 
     55 <figure><img src="https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%281143%29.png" alt="" width="188"><figcaption></figcaption></figure>
     56 
     57 Select the hardware profile you want to use and click **Next**.
     58 
     59 > [!WARNING]
     60 > If you need a phone with Play Store installed select one with the Play Store icon on it!
     61 >
     62 > <img src="https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%281144%29.png" alt="" data-size="original">
     63 
     64 In the current view you are going to be able to **select and download the Android image** that the phone is going to run:
     65 
     66 <figure><img src="https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%281145%29.png" alt="" width="375"><figcaption></figcaption></figure>
     67 
     68 So, select it and if it isn't downloaded click on the _**Download**_ symbol next to the name (**now wait until the image is downloaded).**\
     69 Once the image is downloaded, just select **`Next`** and **`Finish`**.
     70 
     71 The virtual machine will be created. Now **every time that you access AVD manager it will be present**.
     72 
     73 ### Run Virtual Machine
     74 
     75 In order to **run** it just press the _**Start button**_.
     76 
     77 ![Prepare Virtual Machine - Run Virtual Machine: In order to run it just press the Start button](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%28518%29.png)
     78 
     79 ## Command Line tool
     80 
     81 > [!WARNING]
     82 > On macOS, current SDK installations commonly place `avdmanager` under `~/Library/Android/sdk/cmdline-tools/latest/bin/` and the emulator under `~/Library/Android/sdk/emulator/`. Older SDK Tools installations used `~/Library/Android/sdk/tools/bin/avdmanager`; retain that legacy path when reproducing an older lab. Confirm the paths in your SDK installation.
     83 
     84 First of all you need to **decide which phone you want to use**, in order to see the list of possible phones execute:
     85 
     86 ```text
     87 C:\Users\<UserName>\AppData\Local\Android\Sdk\tools\bin\avdmanager.bat list device
     88 
     89 d: 0 or "automotive_1024p_landscape"
     90     Name: Automotive (1024p landscape)
     91     OEM : Google
     92     Tag : android-automotive-playstore
     93 ---------
     94 id: 1 or "Galaxy Nexus"
     95     Name: Galaxy Nexus
     96     OEM : Google
     97 ---------
     98 id: 2 or "desktop_large"
     99     Name: Large Desktop
    100     OEM : Google
    101     Tag : android-desktop
    102 ---------
    103 id: 3 or "desktop_medium"
    104     Name: Medium Desktop
    105     OEM : Google
    106     Tag : android-desktop
    107 ---------
    108 id: 4 or "Nexus 10"
    109     Name: Nexus 10
    110     OEM : Google
    111 [...]
    112 ```
    113 
    114 Once you have decided which device profile to use, choose the Android system image to run on it.\
    115 You can list all the options using `sdkmanager`:
    116 
    117 ```bash
    118 C:\Users\<UserName>\AppData\Local\Android\Sdk\tools\bin\sdkmanager.bat --list
    119 ```
    120 
    121 And **download** the one (or all) you want to use with:
    122 
    123 ```bash
    124 C:\Users\<UserName>\AppData\Local\Android\Sdk\tools\bin\sdkmanager.bat "platforms;android-28" "system-images;android-28;google_apis;x86_64"
    125 ```
    126 
    127 Once you have downloaded the Android image you want to use you can **list all the downloaded Android images** with:
    128 
    129 ```text
    130 C:\Users\<UserName>\AppData\Local\Android\Sdk\tools\bin\avdmanager.bat list target
    131 ----------
    132 id: 1 or "android-28"
    133      Name: Android API 28
    134      Type: Platform
    135      API level: 28
    136      Revision: 6
    137 ----------
    138 id: 2 or "android-29"
    139      Name: Android API 29
    140      Type: Platform
    141      API level: 29
    142      Revision: 4
    143 ```
    144 
    145 At this moment you have decided the device you want to use and you have downloaded the Android image, so **you can create the virtual machine using**:
    146 
    147 ```bash
    148 C:\Users\<UserName>\AppData\Local\Android\Sdk\tools\bin\avdmanager.bat -v create avd -k "system-images;android-28;google_apis;x86_64" -n "AVD9" -d "Nexus 5X"
    149 ```
    150 
    151 In the last command **I created a VM named** "_AVD9_" using the **device** "_Nexus 5X_" and the **Android image** "_system-images;android-28;google_apis;x86_64_".\
    152 Now you can **list the virtual machines** you have created with:
    153 
    154 ```bash
    155 C:\Users\<UserName>\AppData\Local\Android\Sdk\tools\bin\avdmanager.bat list avd
    156 
    157  Name: AVD9
    158   Device: Nexus 5X (Google)
    159     Path: C:\Users\cpolo\.android\avd\AVD9.avd
    160   Target: Google APIs (Google Inc.)
    161           Based on: Android API 28 Tag/ABI: google_apis/x86_64
    162 
    163 The following Android Virtual Devices could not be loaded:
    164     Name: Pixel_2_API_27
    165     Path: C:\Users\cpolo\.android\avd\Pixel_2_API_27_1.avd
    166    Error: Google pixel_2 no longer exists as a device
    167 ```
    168 
    169 ### Run Virtual Machine
    170 
    171 The macOS command paths are described under **Command Line tool** above.
    172 
    173 We have already seen how you can list the created virtual machines, but **you can also list them using**:
    174 
    175 ```bash
    176 C:\Users\<UserName>\AppData\Local\Android\Sdk\tools\emulator.exe -list-avds
    177 AVD9
    178 Pixel_2_API_27
    179 ```
    180 
    181 You can simply **run any virtual machine created** using:
    182 
    183 ```bash
    184 C:\Users\<UserName>\AppData\Local\Android\Sdk\tools\emulator.exe -avd "VirtualMachineName"
    185 C:\Users\<UserName>\AppData\Local\Android\Sdk\tools\emulator.exe -avd "AVD9"
    186 ```
    187 
    188 Or using more advance options you can run a virtual machine like:
    189 
    190 ```bash
    191 C:\Users\<UserName>\AppData\Local\Android\Sdk\tools\emulator.exe -avd "AVD9" -http-proxy 192.168.1.12:8080 -writable-system
    192 ```
    193 
    194 ### Command line options
    195 
    196 However there are **a lot of different command line useful options** that you can use to initiate a virtual machine. Below you can find some interesting options but can [**find a complete list here**](https://developer.android.com/studio/run/emulator-commandline)<sup>[[2]](#references)</sup>
    197 
    198 **Boot**
    199 
    200 - `-snapshot name` : Start VM snapshot
    201 - `-snapshot-list -snapstorage ~/.android/avd/Nexus_5X_API_23.avd/snapshots-test.img` : List all the snapshots recorded
    202 
    203 **Network**
    204 
    205 - `-dns-server 192.0.2.0, 192.0.2.255` : Allow to indicate comma separated the DNS servers to the VM.
    206 - **`-http-proxy 192.168.1.12:8080`** : Allow to indicate an HTTP proxy to use (very useful to capture the traffic using Burp)
    207     - If the proxy settings aren't working for some reason, try to configure them internally or using an pplication like "Super Proxy" or "ProxyDroid".
    208 - `-netdelay 200` : Set the network latency emulation in milliseconds.
    209 - `-port 5556` : Set the TCP port number that's used for the console and adb.
    210 - `-ports 5556,5559` : Set the TCP ports used for the console and adb.
    211 - **`-tcpdump /path/dumpfile.cap`** : Capture all the traffic in a file
    212 
    213 **System**
    214 
    215 - `-selinux {disabled|permissive}` : Set the Security-Enhanced Linux security module to either disabled or permissive mode on a Linux operating system.
    216 - `-timezone Europe/Paris` : Set the timezone for the virtual device
    217 - `-screen {touch(default)|multi-touch|o-touch}` : Set emulated touch screen mode.
    218 - **`-writable-system`** : Use this option to have a writable system image during your emulation session. You will need also to run `adb root; adb remount`. This is very useful to install a new certificate in the system.
    219 
    220 ## Linux CLI setup (SDK/AVD quickstart)
    221 
    222 The official CLI tools make it easy to create fast, debuggable emulators without Android Studio.<sup>[[1]](#references)</sup>
    223 
    224 ```bash
    225 # Directory layout
    226 mkdir -p ~/Android/cmdline-tools/latest
    227 
    228 # Download commandline tools (Linux)
    229 wget https://dl.google.com/android/repository/commandlinetools-linux-13114758_latest.zip -O /tmp/cmdline-tools.zip
    230 unzip /tmp/cmdline-tools.zip -d ~/Android/cmdline-tools/latest
    231 rm /tmp/cmdline-tools.zip
    232 
    233 # Env vars (add to ~/.bashrc or ~/.zshrc)
    234 export ANDROID_HOME=$HOME/Android
    235 export PATH=$ANDROID_HOME/cmdline-tools/latest/bin:$ANDROID_HOME/platform-tools:$ANDROID_HOME/emulator:$PATH
    236 
    237 # Install core SDK components
    238 sdkmanager --install "platform-tools" "emulator"
    239 
    240 # Install a debuggable x86_64 system image (Android 11 / API 30)
    241 sdkmanager --install "system-images;android-30;google_apis;x86_64"
    242 
    243 # Create an AVD and run it with a writable /system & snapshot name
    244 avdmanager create avd -n PixelRootX86 -k "system-images;android-30;google_apis;x86_64" -d "pixel"
    245 emulator -avd PixelRootX86 -writable-system -snapshot PixelRootX86_snap
    246 
    247 # Verify root (debuggable images allow `adb root`)
    248 adb root
    249 adb shell whoami  # expect: root
    250 ```
    251 
    252 Notes
    253 - System image flavors: google_apis (debuggable, allows adb root), google_apis_playstore (not rootable), aosp/default (lightweight).
    254 - Build types: userdebug often allows `adb root` on debug-capable images. Play Store images are production builds and block root.
    255 - On x86_64 hosts, prefer an x86/x86_64 system image. Some Android 11-era Google images provided per-app ARM translation, but availability and supported ABIs vary by emulator and image release.<sup>[[3]](#references)</sup> That translation runs many ARM-only applications inside an x86 system image; it is not the same as full-system ARM64 emulation, which older emulator releases did not provide for newer API images on x86_64 hosts.
    256 
    257 ### Snapshots from CLI
    258 
    259 ```bash
    260 # Save a clean snapshot from the running emulator
    261 adb -s emulator-5554 emu avd snapshot save my_clean_setup
    262 
    263 # Boot from a named snapshot (if it exists)
    264 emulator -avd PixelRootX86 -writable-system -snapshot my_clean_setup
    265 ```
    266 
    267 ## ARM→x86 binary translation (Android 11+)
    268 
    269 Google APIs and Play Store images on Android 11+ can translate ARM app binaries per process while keeping the rest of the system native x86/x86_64. This is often fast enough to test many ARM-only apps on desktop.<sup>[[3]](#references)</sup>
    270 
    271 > Tip: Prefer Google APIs x86/x86_64 images during pentests. Play images are convenient but block `adb root`; use them only when you specifically require Play services and accept the lack of root.
    272 
    273 ## Rooting a Play Store device
    274 
    275 If you downloaded a device with Play Store you are not going to be able to get root directly, and you will get this error message
    276 
    277 ```text
    278 $ adb root
    279 adbd cannot run as root in production builds
    280 ```
    281 
    282 Using [rootAVD](https://github.com/newbit1/rootAVD) with [Magisk](https://github.com/topjohnwu/Magisk) I was able to root it (follow for example [**this video**](https://www.youtube.com/watch?v=Wk0ixxmkzAI) **or** [**this one**](https://www.youtube.com/watch?v=qQicUW0svB8)).
    283 
    284 ## Install Burp Certificate
    285 
    286 Check the following page to learn how to install a custom CA cert:
    287 
    288 [Install Burp Certificate](/hacktricks/mobile-pentesting/android-app-pentesting/install-burp-certificate)
    289 
    290 ## Nice AVD Options
    291 
    292 ### Take a Snapshot
    293 
    294 You can **use the GUI** to take a snapshot of the VM at any time:
    295 
    296 ![Nice AVD Options - Take a Snapshot: You can use the GUI to take a snapshot of the VM at any time](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%28234%29.png)
    297 
    298 ## References
    299 
    300 - [1] [Build a Repeatable Android Bug Bounty Lab: Emulator vs Magisk, Burp, Frida, and Medusa](https://www.yeswehack.com/learn-bug-bounty/android-lab-mobile-hacking-tools)
    301 - [2] [Android Emulator command line](https://developer.android.com/studio/run/emulator-commandline)
    302 - [3] [Run ARM apps on the Android Emulator (x86 translation)](https://android-developers.googleblog.com/2020/03/run-arm-apps-on-android-emulator.html)
    303 - [4] [Android Developers – Create and manage virtual devices](https://developer.android.com/studio/run/managing-avds)