avd-android-virtual-device.md (13843B)
1 --- 2 title: "AVD - Android Virtual Device" 3 section: "Mobile" 4 sectionSlug: "mobile-pentesting" 5 sourcePath: "src/mobile-pentesting/android-app-pentesting/avd-android-virtual-device.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/mobile-pentesting/android-app-pentesting/avd-android-virtual-device.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # AVD - Android Virtual Device 14 15 Thank you very much to [**@offsecjay**](https://twitter.com/offsecjay) for his help while creating this content. 16 17 ## What is 18 19 Android Studio can run Android Virtual Devices (AVDs) for testing APKs. An AVD defines the hardware profile, system image, storage, skin, and other characteristics used by the Android Emulator.<sup>[[4]](#references)</sup> To use one, install: 20 21 - The **Android SDK tools** - [Download here](https://developer.android.com/studio/releases/sdk-tools). 22 - Or **Android Studio** (with Android SDK tools) - [Download here](https://developer.android.com/studio). 23 24 In Windows (in my case) **after installing Android Studio** I had the **SDK Tools installed in**: `C:\Users\<UserName>\AppData\Local\Android\Sdk\tools` 25 26 In mac you can **download the SDK tools** and have them in the PATH running: 27 28 ```bash 29 brew tap homebrew/cask 30 brew install --cask android-sdk 31 ``` 32 33 Or from **Android Studio GUI** as indicated in [https://stackoverflow.com/questions/46402772/failed-to-install-android-sdk-java-lang-noclassdeffounderror-javax-xml-bind-a](https://stackoverflow.com/questions/46402772/failed-to-install-android-sdk-java-lang-noclassdeffounderror-javax-xml-bind-a) which will install them in `~/Library/Android/sdk/cmdline-tools/latest/bin/` and `~/Library/Android/sdk/platform-tools/` and `~/Library/Android/sdk/emulator/` 34 35 For the Java problems: 36 37 ```java 38 export JAVA_HOME=/Applications/Android\ Studio.app/Contents/jbr/Contents/Home 39 ``` 40 41 ## GUI 42 43 ### Prepare Virtual Machine 44 45 In current Android Studio versions, open **View** → **Tool Windows** → **Device Manager**, then select **Create Virtual Device**. Older versions exposed the same workflow as **Tools** → **AVD Manager**.<sup>[[4]](#references)</sup> 46 47 <div align="center" data-full-width="false"> 48 49 <figure><img src="https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%281142%29.png" alt="" width="293"><figcaption></figcaption></figure> 50 51 </div> 52 53 Then, click on _**Create Virtual Device**_ 54 55 <figure><img src="https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%281143%29.png" alt="" width="188"><figcaption></figcaption></figure> 56 57 Select the hardware profile you want to use and click **Next**. 58 59 > [!WARNING] 60 > If you need a phone with Play Store installed select one with the Play Store icon on it! 61 > 62 > <img src="https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%281144%29.png" alt="" data-size="original"> 63 64 In the current view you are going to be able to **select and download the Android image** that the phone is going to run: 65 66 <figure><img src="https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%281145%29.png" alt="" width="375"><figcaption></figcaption></figure> 67 68 So, select it and if it isn't downloaded click on the _**Download**_ symbol next to the name (**now wait until the image is downloaded).**\ 69 Once the image is downloaded, just select **`Next`** and **`Finish`**. 70 71 The virtual machine will be created. Now **every time that you access AVD manager it will be present**. 72 73 ### Run Virtual Machine 74 75 In order to **run** it just press the _**Start button**_. 76 77  78 79 ## Command Line tool 80 81 > [!WARNING] 82 > On macOS, current SDK installations commonly place `avdmanager` under `~/Library/Android/sdk/cmdline-tools/latest/bin/` and the emulator under `~/Library/Android/sdk/emulator/`. Older SDK Tools installations used `~/Library/Android/sdk/tools/bin/avdmanager`; retain that legacy path when reproducing an older lab. Confirm the paths in your SDK installation. 83 84 First of all you need to **decide which phone you want to use**, in order to see the list of possible phones execute: 85 86 ```text 87 C:\Users\<UserName>\AppData\Local\Android\Sdk\tools\bin\avdmanager.bat list device 88 89 d: 0 or "automotive_1024p_landscape" 90 Name: Automotive (1024p landscape) 91 OEM : Google 92 Tag : android-automotive-playstore 93 --------- 94 id: 1 or "Galaxy Nexus" 95 Name: Galaxy Nexus 96 OEM : Google 97 --------- 98 id: 2 or "desktop_large" 99 Name: Large Desktop 100 OEM : Google 101 Tag : android-desktop 102 --------- 103 id: 3 or "desktop_medium" 104 Name: Medium Desktop 105 OEM : Google 106 Tag : android-desktop 107 --------- 108 id: 4 or "Nexus 10" 109 Name: Nexus 10 110 OEM : Google 111 [...] 112 ``` 113 114 Once you have decided which device profile to use, choose the Android system image to run on it.\ 115 You can list all the options using `sdkmanager`: 116 117 ```bash 118 C:\Users\<UserName>\AppData\Local\Android\Sdk\tools\bin\sdkmanager.bat --list 119 ``` 120 121 And **download** the one (or all) you want to use with: 122 123 ```bash 124 C:\Users\<UserName>\AppData\Local\Android\Sdk\tools\bin\sdkmanager.bat "platforms;android-28" "system-images;android-28;google_apis;x86_64" 125 ``` 126 127 Once you have downloaded the Android image you want to use you can **list all the downloaded Android images** with: 128 129 ```text 130 C:\Users\<UserName>\AppData\Local\Android\Sdk\tools\bin\avdmanager.bat list target 131 ---------- 132 id: 1 or "android-28" 133 Name: Android API 28 134 Type: Platform 135 API level: 28 136 Revision: 6 137 ---------- 138 id: 2 or "android-29" 139 Name: Android API 29 140 Type: Platform 141 API level: 29 142 Revision: 4 143 ``` 144 145 At this moment you have decided the device you want to use and you have downloaded the Android image, so **you can create the virtual machine using**: 146 147 ```bash 148 C:\Users\<UserName>\AppData\Local\Android\Sdk\tools\bin\avdmanager.bat -v create avd -k "system-images;android-28;google_apis;x86_64" -n "AVD9" -d "Nexus 5X" 149 ``` 150 151 In the last command **I created a VM named** "_AVD9_" using the **device** "_Nexus 5X_" and the **Android image** "_system-images;android-28;google_apis;x86_64_".\ 152 Now you can **list the virtual machines** you have created with: 153 154 ```bash 155 C:\Users\<UserName>\AppData\Local\Android\Sdk\tools\bin\avdmanager.bat list avd 156 157 Name: AVD9 158 Device: Nexus 5X (Google) 159 Path: C:\Users\cpolo\.android\avd\AVD9.avd 160 Target: Google APIs (Google Inc.) 161 Based on: Android API 28 Tag/ABI: google_apis/x86_64 162 163 The following Android Virtual Devices could not be loaded: 164 Name: Pixel_2_API_27 165 Path: C:\Users\cpolo\.android\avd\Pixel_2_API_27_1.avd 166 Error: Google pixel_2 no longer exists as a device 167 ``` 168 169 ### Run Virtual Machine 170 171 The macOS command paths are described under **Command Line tool** above. 172 173 We have already seen how you can list the created virtual machines, but **you can also list them using**: 174 175 ```bash 176 C:\Users\<UserName>\AppData\Local\Android\Sdk\tools\emulator.exe -list-avds 177 AVD9 178 Pixel_2_API_27 179 ``` 180 181 You can simply **run any virtual machine created** using: 182 183 ```bash 184 C:\Users\<UserName>\AppData\Local\Android\Sdk\tools\emulator.exe -avd "VirtualMachineName" 185 C:\Users\<UserName>\AppData\Local\Android\Sdk\tools\emulator.exe -avd "AVD9" 186 ``` 187 188 Or using more advance options you can run a virtual machine like: 189 190 ```bash 191 C:\Users\<UserName>\AppData\Local\Android\Sdk\tools\emulator.exe -avd "AVD9" -http-proxy 192.168.1.12:8080 -writable-system 192 ``` 193 194 ### Command line options 195 196 However there are **a lot of different command line useful options** that you can use to initiate a virtual machine. Below you can find some interesting options but can [**find a complete list here**](https://developer.android.com/studio/run/emulator-commandline)<sup>[[2]](#references)</sup> 197 198 **Boot** 199 200 - `-snapshot name` : Start VM snapshot 201 - `-snapshot-list -snapstorage ~/.android/avd/Nexus_5X_API_23.avd/snapshots-test.img` : List all the snapshots recorded 202 203 **Network** 204 205 - `-dns-server 192.0.2.0, 192.0.2.255` : Allow to indicate comma separated the DNS servers to the VM. 206 - **`-http-proxy 192.168.1.12:8080`** : Allow to indicate an HTTP proxy to use (very useful to capture the traffic using Burp) 207 - If the proxy settings aren't working for some reason, try to configure them internally or using an pplication like "Super Proxy" or "ProxyDroid". 208 - `-netdelay 200` : Set the network latency emulation in milliseconds. 209 - `-port 5556` : Set the TCP port number that's used for the console and adb. 210 - `-ports 5556,5559` : Set the TCP ports used for the console and adb. 211 - **`-tcpdump /path/dumpfile.cap`** : Capture all the traffic in a file 212 213 **System** 214 215 - `-selinux {disabled|permissive}` : Set the Security-Enhanced Linux security module to either disabled or permissive mode on a Linux operating system. 216 - `-timezone Europe/Paris` : Set the timezone for the virtual device 217 - `-screen {touch(default)|multi-touch|o-touch}` : Set emulated touch screen mode. 218 - **`-writable-system`** : Use this option to have a writable system image during your emulation session. You will need also to run `adb root; adb remount`. This is very useful to install a new certificate in the system. 219 220 ## Linux CLI setup (SDK/AVD quickstart) 221 222 The official CLI tools make it easy to create fast, debuggable emulators without Android Studio.<sup>[[1]](#references)</sup> 223 224 ```bash 225 # Directory layout 226 mkdir -p ~/Android/cmdline-tools/latest 227 228 # Download commandline tools (Linux) 229 wget https://dl.google.com/android/repository/commandlinetools-linux-13114758_latest.zip -O /tmp/cmdline-tools.zip 230 unzip /tmp/cmdline-tools.zip -d ~/Android/cmdline-tools/latest 231 rm /tmp/cmdline-tools.zip 232 233 # Env vars (add to ~/.bashrc or ~/.zshrc) 234 export ANDROID_HOME=$HOME/Android 235 export PATH=$ANDROID_HOME/cmdline-tools/latest/bin:$ANDROID_HOME/platform-tools:$ANDROID_HOME/emulator:$PATH 236 237 # Install core SDK components 238 sdkmanager --install "platform-tools" "emulator" 239 240 # Install a debuggable x86_64 system image (Android 11 / API 30) 241 sdkmanager --install "system-images;android-30;google_apis;x86_64" 242 243 # Create an AVD and run it with a writable /system & snapshot name 244 avdmanager create avd -n PixelRootX86 -k "system-images;android-30;google_apis;x86_64" -d "pixel" 245 emulator -avd PixelRootX86 -writable-system -snapshot PixelRootX86_snap 246 247 # Verify root (debuggable images allow `adb root`) 248 adb root 249 adb shell whoami # expect: root 250 ``` 251 252 Notes 253 - System image flavors: google_apis (debuggable, allows adb root), google_apis_playstore (not rootable), aosp/default (lightweight). 254 - Build types: userdebug often allows `adb root` on debug-capable images. Play Store images are production builds and block root. 255 - On x86_64 hosts, prefer an x86/x86_64 system image. Some Android 11-era Google images provided per-app ARM translation, but availability and supported ABIs vary by emulator and image release.<sup>[[3]](#references)</sup> That translation runs many ARM-only applications inside an x86 system image; it is not the same as full-system ARM64 emulation, which older emulator releases did not provide for newer API images on x86_64 hosts. 256 257 ### Snapshots from CLI 258 259 ```bash 260 # Save a clean snapshot from the running emulator 261 adb -s emulator-5554 emu avd snapshot save my_clean_setup 262 263 # Boot from a named snapshot (if it exists) 264 emulator -avd PixelRootX86 -writable-system -snapshot my_clean_setup 265 ``` 266 267 ## ARM→x86 binary translation (Android 11+) 268 269 Google APIs and Play Store images on Android 11+ can translate ARM app binaries per process while keeping the rest of the system native x86/x86_64. This is often fast enough to test many ARM-only apps on desktop.<sup>[[3]](#references)</sup> 270 271 > Tip: Prefer Google APIs x86/x86_64 images during pentests. Play images are convenient but block `adb root`; use them only when you specifically require Play services and accept the lack of root. 272 273 ## Rooting a Play Store device 274 275 If you downloaded a device with Play Store you are not going to be able to get root directly, and you will get this error message 276 277 ```text 278 $ adb root 279 adbd cannot run as root in production builds 280 ``` 281 282 Using [rootAVD](https://github.com/newbit1/rootAVD) with [Magisk](https://github.com/topjohnwu/Magisk) I was able to root it (follow for example [**this video**](https://www.youtube.com/watch?v=Wk0ixxmkzAI) **or** [**this one**](https://www.youtube.com/watch?v=qQicUW0svB8)). 283 284 ## Install Burp Certificate 285 286 Check the following page to learn how to install a custom CA cert: 287 288 [Install Burp Certificate](/hacktricks/mobile-pentesting/android-app-pentesting/install-burp-certificate) 289 290 ## Nice AVD Options 291 292 ### Take a Snapshot 293 294 You can **use the GUI** to take a snapshot of the VM at any time: 295 296  297 298 ## References 299 300 - [1] [Build a Repeatable Android Bug Bounty Lab: Emulator vs Magisk, Burp, Frida, and Medusa](https://www.yeswehack.com/learn-bug-bounty/android-lab-mobile-hacking-tools) 301 - [2] [Android Emulator command line](https://developer.android.com/studio/run/emulator-commandline) 302 - [3] [Run ARM apps on the Android Emulator (x86 translation)](https://android-developers.googleblog.com/2020/03/run-arm-apps-on-android-emulator.html) 303 - [4] [Android Developers – Create and manage virtual devices](https://developer.android.com/studio/run/managing-avds)