android-applications.md (27164B)
1 --- 2 title: "Android Application" 3 section: "Methodology" 4 sectionSlug: "methodology" 5 sourcePath: "docs/methodology/android-applications.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/methodology/android-applications.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Android Application 12 13 ## Lab 14 15 * [payatu/diva-android](https://github.com/payatu/diva-android) - Damn Insecure and vulnerable App for Android 16 * [HTB VIP - Pinned](https://app.hackthebox.com/challenges/282) - Hack The Box challenge 17 * [HTB VIP - Manager](https://app.hackthebox.com/challenges/283) - Hack The Box challenge 18 19 ## Extract APK 20 21 ### ADB Method 22 23 Connect to ADB shell and list/download packages. 24 You might need to enable `Developer mode` and `Debugging` in order to connect with `adb` 25 26 ```powershell 27 adb shell pm list packages 28 adb shell pm path com.example.someapp 29 adb pull /data/app/com.example.someapp-2.apk 30 ``` 31 32 ### Stores 33 34 Warning: Downloading APK files from unofficial stores can compromise your device's security. These sources often host malware and malicious software. Always use trusted and official app stores for downloads. 35 36 * [Google Play](https://play.google.com/store/apps) - Official Store 37 * [Apkpure.fr](https://apkpure.fr/fr/) - Alternative to Google Play 38 * [Apkpure.co](https://apkpure.co) - Alternative to Google Play 39 * [Aptoide](https://fr.aptoide.com/) - Alternative to Google Play 40 * [Aurora Store](https://f-droid.org/fr/packages/com.aurora.store/) - Alternative to Google Play 41 42 Download APK from Google Play using a 3rd Party: 43 44 * [apkcombo.com](https://apkcombo.com/downloader/) 45 * [apps.evozi.com](https://apps.evozi.com/apk-downloader/) 46 47 ## Static Analysis 48 49 ### Extract Contents From APK 50 51 Search for strings `flag`,`secret`, the default string file is `Resources/resources.arsc/res/values/strings.xml`. 52 53 ```powershell 54 apktool d application.apk 55 ``` 56 57 ### Decompile Data as Java Code 58 59 * Rename `application.apk` to `application.zip`: `mv application.apk application.zip` 60 * Extract `classes.dex`: `unzip application.zip` 61 * Use `dex2jar` to obtain a jar file: `/usr/bin/d2j-dex2jar classes.dex` 62 * Use `jadx` using full CPU: `jadx classes.dex -j $(grep -c ^processor /proc/cpuinfo) -d Downloads/app/ > /dev/null` 63 64 ```powershell 65 jadx-gui 66 --deobf # remove obfuscation by AndroGuard 67 -e # generate a gradle project for Android Studio (easy to find function) 68 ``` 69 70 To reverse `.odex` you need to provide the `/system/framework/arm`, fortunately since we have the firmware we have it. 71 72 ```powershell 73 java -jar baksmali-2.3.4.jar x application.odex -d k107-mb-8.1/system/framework/arm -o application 74 apktool d application.apk 75 apktool b rebuild_folder -o rebuilt.apk 76 ``` 77 78 ### Decompile Native Code 79 80 Native library are represented as `.so` files. 81 These libraries by default are included in the APK at the file path `/lib/<cpu>/lib<name>.so` or `/assets/<custom_name>`. 82 83 Use `IDA`, `Radare2/Cutter` or `Ghidra` to reverse them. 84 85 | CPU Native | Library Path | 86 | -------------------- | -------------------------- | 87 | "generic" 32-bit ARM | lib/armeabi/libcalc.so | 88 | x86 | lib/x86/libcalc.so | 89 | x64 | lib/x86_64/libcalc.so | 90 | ARMv7 | lib/armeabi-v7a/libcalc.so | 91 | ARM64 | lib/arm64-v8a/libcalc.so | 92 93 :warning: The shared object file (`.so`) doesn't need to be embedded in the app. 94 95 ### Mobile Security Framework Static 96 97 > Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. 98 99 * [MobSF - Documentation](https://mobsf.github.io/docs/#/) 100 * [MobSF - Github](https://github.com/MobSF/Mobile-Security-Framework-MobSF) 101 * [MobSF - Live Demo](https://mobsf.live/) 102 103 Run [MobSF/Mobile-Security-Framework-MobSF](https://github.com/MobSF/Mobile-Security-Framework-MobSF) 104 105 * Latest version from DockerHub 106 107 ```powershell 108 docker run -it --name mobsf -p 8000:8000 opensecurity/mobile-security-framework-mobsf:latest 109 ``` 110 111 * Enable persistence on the Docker container 112 113 ```powershell 114 docker run -it --rm --name mobsf -p 8000:8000 -v <your_local_dir>:/root/.MobSF opensecurity/mobile-security-framework-mobsf:latest 115 ``` 116 117 ### Online Assets 118 119 :warning: Uploading APKs to uncontrolled websites risks data leaks, malware, intellectual property theft, and privacy violations. Use trusted platforms only to ensure the security and integrity of your app. 120 121 * [appetize.io](https://appetize.io/) - Instantly run mobile apps in your browser 122 * [mobsf.live](https://mobsf.live/) - Demo version of MobSF 123 * [hybrid-analysis.com](https://www.hybrid-analysis.com/sample/573df0b1cb5ffc0a25306be5ec83483ed1b2acdba37dd93223b9f14f42b2fdea?environmentId=200) - Sandbox analysis of APK files 124 125 ### React Native and Hermes 126 127 Identify React Native app with `index.android.bundle` inside the `assets` folder 128 129 ```ps1 130 Hermes: pip install hbctool 131 ╰─$ hbctool disasm index.android.bundle indexasm 132 [*] Disassemble 'index.android.bundle' to 'indexasm' path 133 [*] Hermes Bytecode [ Source Hash: 4013cb75f7e16d4474f5cf258edc45ee16585560, HBC Version: 74 ] 134 [*] Done 135 ``` 136 137 ### Flutter 138 139 Indentify Flutter use in the `MANIFEST.MF` and search for `libflutter.so`. 140 141 * [worawit/blutter](https://github.com/worawit/blutter) - Flutter Mobile Application Reverse Engineering Tool 142 143 ```ps1 144 blutter jadx/resources/lib/arm64-v8a/ ./blutter_output 145 ``` 146 147 ## APK Patching 148 149 * [MadSquirrels/apkpatcher](https://gitlab.com/MadSquirrels/mobile/apkpatcher) 150 151 ```ps1 152 docker run --rm -v .:/pwd -it madsquirrels/apkpatcher -a base.apk 153 154 # Java dependencies 155 apt install -y default-jre 156 157 # sdktools dependendies installation 158 wget https://dl.google.com/android/repository/commandlinetools-linux-6200805_latest.zip 159 mkdir /usr/lib/android-sdk 160 cd /usr/lib/android-sdk 161 unzip commandlinetools-linux-6200805_latest.zip 162 mkdir cmdline-tools 163 mv tools/ cmdline-tools/ 164 echo 'export ANDROID_SDK_ROOT=/usr/lib/android-sdk' >> ~/.bashrc 165 166 # installation of platform-tools 167 sdkmanager "platform-tools" "platforms;android-36" "build-tools;36.0.0" "emulator" 168 169 # install apkpatcher 170 pip install apkpatcher 171 ``` 172 173 ### Sign and Package APK 174 175 * [iBotPeaches/apktool](https://github.com/iBotPeaches/Apktool) + `jarsigner` 176 177 ```powershell 178 apktool b ./application.apk 179 keytool -genkey -v -keystore application.keystore -alias application -keyalg RSA -keysize 2048 -validity 10000 180 jarsigner -verbose -sigalg SHA1withRSA -digestalg SHA1 -keystore application.keystore application.apk application 181 zipalign -v 4 application.apk application-signed.apk 182 ``` 183 184 * [iBotPeaches/apktool](https://github.com/iBotPeaches/Apktool) + `signapk` 185 186 ```powershell 187 apktool b app-release 188 ./signapk app-release/dist/app-release.apk 189 ``` 190 191 * [patrickfav/uber-apk-signer](https://github.com/patrickfav/uber-apk-signer) (Linux only) 192 193 ```powershell 194 java -jar uber-apk-signer.jar --apks /path/to/apks 195 ``` 196 197 * [APK Toolkit v1.3](https://xdaforums.com/t/tool-apk-toolkit-v1-3-windows.4572881/) (Windows only) 198 199 ### Unpack Resources 200 201 ```ps1 202 apkpatcher -a <apk> --only-unpack dir 203 apkpatcher -a <new_apk> --only-repack dir 204 ``` 205 206 ### Inject Proxy Certificate 207 208 Accept user certificate 209 210 ```ps1 211 apkpatcher -a <apk> -e 212 ``` 213 214 Add a custom certificate 215 216 ```ps1 217 apkpatcher -a <apk> -c burp.der 218 ``` 219 220 ### Add Permissions 221 222 ```ps1 223 apkpatcher -a <apk> --add-permissions <my_permission> 224 ``` 225 226 ### Debug Mode 227 228 Inject the `android:debuggable` option into an application `AndroidManifest.xml`, allowing users to debug applications even when they are in release mode. 229 230 ```ps1 231 apkpatcher -a <apk> --enable-debug 232 ``` 233 234 Set the application to be the debug target. 235 236 ```ps1 237 adb shell am set-debug-app --persistent 238 ``` 239 240 Start the application’s activity in debug mode. 241 242 ```ps1 243 adb shell am start -D -a android.intent.action.MAIN -n <package>/<Activity> 244 ``` 245 246 Then use `gdbserver` for Native Code or Java Debugger like `jdb`. 247 248 ```ps1 249 adb forward tcp:12345 jdwp:$(adb shell pidof <package> ) 250 jdb -attach localhost:12345 251 ``` 252 253 ## Dynamic Analysis 254 255 Dynamic analysis for Android malware involves executing and monitoring an app in a controlled environment to observe its behavior. This technique detects malicious activities like data exfiltration, unauthorized access, and system modifications. Additionally, it aids in reverse engineering app features, revealing hidden functionalities and potential vulnerabilities for better threat mitigation. 256 257 ### Burp Suite 258 259 * Proxy > Listen to all interfaces 260 * Import/Export CA certificate 261 * `adb push burp.der /sdcard/burp.crt` 262 * Open the Settings on the device and search "Install Cert" 263 * Click Install certificates from SD card 264 * Configure the AVD to use the proxy 265 266 ```ps1 267 # Convert Burp certificate for Android 268 openssl x509 -inform DER -in burp.der -out burp.pem 269 openssl x509 -inform PEM -subject_hash_old -in burp.pem |head -1 270 mv burp.pem <hash output>.0 271 272 # Push the certificate in the AVD 273 emulator -list-avds 274 emulator -avd Pentesting_Device -writable-system 275 adb root 276 adb remount 277 adb push <hash>.0 /sdcard/ 278 279 # Change the permissions 280 adb shell 281 mv /sdcard/<hash>.0 /system/etc/security/cacerts/ 282 chmod 644 /system/etc/security/cacerts/<hash>.0 283 chown root:root /system/etc/security/cacerts/<hash>.0 284 ``` 285 286 ### Frida 287 288 * [Frida - Documentation](https://frida.re/docs/android) 289 * [Frida - Github](https://github.com/frida/frida/) 290 291 Download [frida/frida](https://github.com/frida/frida/releases) from releases. 292 293 ```ps1 294 pip install frida-tools 295 unxz frida-server.xz 296 adb root # might be required 297 adb push frida-server /data/local/tmp/ 298 adb shell "chmod 755 /data/local/tmp/frida-server" 299 adb shell "/data/local/tmp/frida-server &" 300 ``` 301 302 Inject frida inside the APK. 303 304 ```ps1 305 $ pip install frida-tools 306 $ frida --version 307 16.7.13 308 309 $ apkpatcher -a <apk> --download_frida_version <version> 310 $ apkpatcher -a <apk> --download_frida_version 16.7.13 311 ``` 312 313 Interesting Frida scripts: 314 315 * [Universal Android SSL Pinning Bypass with Frida](https://codeshare.frida.re/@pcipolloni/universal-android-ssl-pinning-bypass-with-frida/) - `frida --codeshare pcipolloni/universal-android-ssl-pinning-bypass-with-frida -f YOUR_BINARY` 316 * [frida-multiple-unpinning](https://codeshare.frida.re/@akabe1/frida-multiple-unpinning/) - `frida --codeshare akabe1/frida-multiple-unpinning -f YOUR_BINARY` 317 * [aesinfo](https://codeshare.frida.re/@dzonerzy/aesinfo/) - `frida --codeshare dzonerzy/aesinfo -f YOUR_BINARY` 318 * [fridantiroot](https://codeshare.frida.re/@dzonerzy/fridantiroot/) - `frida --codeshare dzonerzy/fridantiroot -f YOUR_BINARY` 319 * [anti-frida-bypass](https://codeshare.frida.re/@enovella/anti-frida-bypass/) - `frida --codeshare enovella/anti-frida-bypass -f YOUR_BINARY` 320 * [xamarin-antiroot](https://codeshare.frida.re/@Gand3lf/xamarin-antiroot/) - `frida --codeshare Gand3lf/xamarin-antiroot -f YOUR_BINARY` 321 * [Intercept Android APK Crypto Operations](https://codeshare.frida.re/@fadeevab/intercept-android-apk-crypto-operations/) - `frida --codeshare fadeevab/intercept-android-apk-crypto-operations -f YOUR_BINARY` 322 * [Android Location Spoofing](https://codeshare.frida.re/@dzervas/android-location-spoofing/) - `frida --codeshare dzervas/android-location-spoofing -f YOUR_BINARY` 323 * [java-crypto-viewer](https://codeshare.frida.re/@Serhatcck/java-crypto-viewer/) - `frida --codeshare Serhatcck/java-crypto-viewer -f YOUR_BINARY` 324 325 ### Runtime Mobile Security 326 327 > Runtime Mobile Security (RMS) 📱🔥 - is a powerful web interface that helps you to manipulate Android and iOS Apps at Runtime 328 329 * [RMS - Github](https://github.com/m0bilesecurity/RMS-Runtime-Mobile-Security) 330 331 **Requirements**: 332 333 * `adb` 334 * `frida`: server up and running on the target device 335 336 In case of issue with your favorite Browser, please use Google Chrome (fully supported). 337 338 * Install RMS 339 340 ```powershell 341 npm install -g rms-runtime-mobile-security 342 ``` 343 344 * Make sure `frida-server` is up and running on the target device. 345 * Launch RMS: `rms` 346 * Open your browser at `http://127.0.0.1:5491/` 347 * Attach to the app, find name with `adb shell pm list package | grep NAME` 348 349 ### Genymotion 350 351 Genymotion is a robust Android emulator designed for developers, offering fast and reliable virtual devices for app testing. It features GPS, battery, and network simulation, enabling comprehensive testing and development 352 353 * [Genymotion](https://www.genymotion.com/) 354 * [Genymotion Desktop](https://www.genymotion.com/product-desktop/) 355 * [Genymotion Device Image](https://www.genymotion.com/product-device-image/) 356 * [Genymotion SaaS](https://www.genymotion.com/product-cloud/) 357 358 ### Android SDK emulator 359 360 Android Virtual Device (AVD) without Google Play Store. 361 362 * Download the files for an API 25 build 363 364 ```powershell 365 sdkmanager "system-images;android-25;google_apis;x86_64" 366 ``` 367 368 * Create a device based on what we downloaded previously 369 370 ```powershell 371 avdmanager create avd x86_64_api_25 -k "system-images;android-25;google_apis;x86_64" 372 ``` 373 374 * Run the emulator 375 376 ```powershell 377 emulator @x86_64_api_25 378 379 emulator -list-avds 380 emulator -avd <non_production_avd_name> -writable-system -no-snapshot 381 emulator -avd Pixel_XL_API_31 -writable-system -http-proxy 127.0.0.1:8080 382 ``` 383 384 * Install the APK 385 386 ```powershell 387 adb install ./challenge.apk 388 ``` 389 390 * Start the App 391 392 ```powershell 393 adb shell monkey -p com.scottyab.rootbeer.sample 1 394 ``` 395 396 ### Mobile Security Framework Dynamic 397 398 :warning: Dynamic Analysis will not work if you use MobSF docker container or setup MobSF inside a Virtual Machine. 399 400 **Requirements**: 401 402 * Genymotion (Supports x86_64 architecture Android 4.1 - 11.0, upto API 30) 403 * Android 5.0 - 11.0 - uses Frida and works out of the box with zero configuration or setup. 404 * Android 4.1 - 4.4 - uses Xposed Framework and requires MobSFy 405 * Genymotion Cloud 406 * [Amazon Marketplace - TCP 5555](https://aws.amazon.com/marketplace/seller-profile?id=933724b4-d35f-4266-905e-e52e4792bc45) 407 * [Azure Marketplace - TCP 5555](https://azuremarketplace.microsoft.com/en-us/marketplace/apps/genymobile.genymotion-cloud) 408 * Android Studio Emulator (only Android images upto API 28 are supported) 409 * AVD without Google Play Store 410 411 Dynamic Analysis from MobSF grants you the following features: 412 413 * Web API Viewer 414 * Frida API Monitor 415 416 ### Appium 417 418 Appium is an open-source project and ecosystem of related software, designed to facilitate UI automation of many app platforms, including mobile (iOS, Android, Tizen), browser (Chrome, Firefox, Safari), desktop (macOS, Windows), TV (Roku, tvOS, Android TV, Samsung), and more! 419 420 * Install appium: `npm install -g appium` 421 * Install and validate the `uiautomator2` driver 422 423 ```ps1 424 export JAVA_HOME=/usr/lib/jvm/default-java 425 export ANDROID_HOME=/home/user/Android/Sdk/ 426 wget https://github.com/google/bundletool/releases/download/1.17.1/bundletool-all-1.17.1.jar 427 sudo mv bundletool-all-1.17.1.jar /usr/local/bin 428 appium driver install uiautomator2 429 appium driver doctor uiautomator2 430 ``` 431 432 * Start the server on the default host (0.0.0.0) and port (4723): `appium server` 433 * Install the Appium Python client: `pip install Appium-Python-Client` 434 * Use the [appium/appium-inspector](https://github.com/appium/appium-inspector) with the following capability 435 436 ```json 437 { 438 "platformName": "Android", 439 "appium:automationName": "UiAutomator2" 440 } 441 ``` 442 443 Examples: 444 445 * [quickstarts/py/test.py](https://github.com/appium/appium/blob/master/packages/appium/sample-code/quickstarts/py/test.py) 446 * [quickstarts/js/test.js](https://github.com/appium/appium/blob/master/packages/appium/sample-code/quickstarts/js/test.js) 447 * [quickstarts/js/test.rb](https://github.com/appium/appium/blob/master/packages/appium/sample-code/quickstarts/rb/test.rb) 448 449 ### Flutter 450 451 Repackage a Flutter Android application to allow Burp Suite proxy interception. 452 453 * [ptswarm/reFlutter](https://github.com/ptswarm/reFlutter) - Flutter Reverse Engineering Framework 454 455 ```ps1 456 pip3 install reflutter 457 reflutter application.apk 458 ``` 459 460 * Sign the apk with [patrickfav/uber-apk-signer](https://github.com/patrickfav/uber-apk-signer/releases/tag/v1.2.1) 461 462 ```ps1 463 java -jar ./uber-apk-signer-1.3.0.jar --apks release.apk 464 java -jar ./uber-apk-signer.jar --allowResign -a release.RE.apk 465 ``` 466 467 An alternative way to do it is using a rooted Android device with `zygisk-reflutter`. 468 469 * [yohanes/zygisk-reflutter](https://github.com/yohanes/zygisk-reflutter) - Zygisk-based reFlutter (Rooted Android with Magisk installed and Zygisk Enabled) 470 471 ```ps1 472 adb push zygiskreflutter_1.0.zip /sdcard/ 473 adb shell su -c magisk --install-module /sdcard/zygiskreflutter_1.0.zip 474 adb reboot 475 ``` 476 477 ## SSL Pinning Bypass 478 479 SSL certificate pinning in an APK involves embedding a server's public key or certificate directly into the app. This ensures the app only trusts specific certificates, preventing man-in-the-middle attacks by rejecting any certificates not matching the pinned ones, even if they are otherwise valid. 480 481 :warning: Android 9.0 is changing the defaults for Network Security Configuration to block all cleartext traffic. 482 483 * [shroudedcode/apk-mitm](https://github.com/shroudedcode/apk-mitm) - A CLI application that automatically prepares Android APK files for HTTPS inspection 484 485 ```powershell 486 $ npx apk-mitm application.apk 487 npx: 139 installé(s) en 12.206s 488 ╭ apk-mitm v0.6.1 489 ├ apktool v2.4.1 490 ╰ uber-apk-signer v1.1.0 491 Using temporary directory: 492 /tmp/87d3a4921ddf86cde634205480f89e90 493 ✔ Decoding APK file 494 ✔ Modifying app manifest 495 ✔ Modifying network security config 496 ✔ Disabling certificate pinning 497 ✔ Encoding patched APK file 498 ✔ Signing patched APK file 499 Done! Patched file: ./application.apk 500 ``` 501 502 * [51j0/Android-CertKiller](https://github.com/51j0/Android-CertKiller) - An automation script to bypass SSL/Certificate pinning in Android 503 504 ```powershell 505 python main.py -w #(Wizard mode) 506 python main.py -p 'root/Desktop/base.apk' #(Manual mode) 507 ``` 508 509 * [frida/frida](https://github.com/frida/frida) - Universal SSL Pinning Bypass 510 511 ```javascript 512 $ adb devices 513 $ adb root 514 $ adb shell 515 $ phone:/# ./frida-server 516 517 // https://codeshare.frida.re/@pcipolloni/universal-android-ssl-pinning-bypass-with-frida/ 518 $ frida -U --codeshare pcipolloni/universal-android-ssl-pinning-bypass-with-frida -f com.example.pinned 519 520 $ frida -U -f org.package.name -l universal-ssl-check-bypass.js --no-pause 521 Java.perform(function() { 522 var array_list = Java.use("java.util.ArrayList"); 523 var ApiClient = Java.use('com.android.org.conscrypt.TrustManagerImpl'); 524 ApiClient.checkTrustedRecursive.implementation = function(a1,a2,a3,a4,a5,a6) { 525 var k = array_list.$new(); 526 return k; 527 } 528 },0); 529 ``` 530 531 * [m0bilesecurity/RMS-Runtime-Mobile-Security](https://github.com/m0bilesecurity/RMS-Runtime-Mobile-Security) - Certificate Pinning bypass script (all + okhttpv3) 532 * [federicodotta/Brida](https://github.com/federicodotta/Brida) - The new bridge between Burp Suite and Frida 533 534 ## Root Detection Bypass 535 536 Common root detection techniques: 537 538 * Su binaries: `su`/`busybox` 539 * Known Root Files/Paths : `Superuser.apk` 540 * Root Management Apps: `Magisk`, `SuperSU` 541 * RW paths: `/system`, `/data` directories 542 * System Properties 543 544 Common bypass: 545 546 * [fridantiroot](https://codeshare.frida.re/@dzonerzy/fridantiroot/) - `frida --codeshare dzonerzy/fridantiroot -f YOUR_BINARY` 547 * [xamarin-antiroot](https://codeshare.frida.re/@Gand3lf/xamarin-antiroot/) - `frida --codeshare Gand3lf/xamarin-antiroot -f YOUR_BINARY` 548 * [multiple-root-detection-bypass/](https://codeshare.frida.re/@KishorBal/multiple-root-detection-bypass/) - `frida --codeshare KishorBal/multiple-root-detection-bypass -f YOUR_BINARY` 549 550 ## Android Debug Bridge 551 552 Android Debug Bridge (ADB) is a versatile command-line tool that enables communication between a computer and an Android device. It facilitates tasks like installing apps, debugging, accessing the device's shell, and transferring files, making it essential for developers and power users in Android development and troubleshooting. 553 554 ### USB Debugging 555 556 * Open the **Settings** app. 557 * Select **System**. 558 * Scroll to the bottom and select **About phone**. 559 * Scroll to the bottom and tap **Build number** 7 times. 560 * Return to the previous screen to find **Developer options** near the bottom. 561 * Scroll down and enable **USB debugging**. 562 563 ```ps1 564 ./platform-tools/adb connect IP:PORT 565 ./platform-tools/adb shell 566 ``` 567 568 ### Wireless Debugging 569 570 * Open the **Settings** app. 571 * Select **System**. 572 * Scroll to the bottom and select **About phone**. 573 * Scroll to the bottom and tap **Build number** 7 times. 574 * Return to the previous screen to find **Developer options** near the bottom. 575 * Scroll down and enable **Wifi debugging**. 576 * Click on **Wifi debugging** to access the settings 577 578 One more step, you need to pair the devices using a code. 579 580 ```ps1 581 ./platform-tools/adb pair IP:PORT CODE 582 ./platform-tools/adb connect IP:PORT 583 ./platform-tools/adb shell 584 ``` 585 586 | Command | Description | 587 | ----------------------------------------- | ----------------------------------------- | 588 | `adb devices` | List devices | 589 | `adb connect <IP>:<PORT>` | Connect to a remote device | 590 | `adb install app.apk` | Install application | 591 | `adb uninstall app.apk` | Uninstall application | 592 | `adb root` | Restarting adbd as root | 593 | `adb shell pm list packages` | List packages | 594 | `adb shell pm list packages -3` | Show third party packages | 595 | `adb shell pm list packages -f` | Show packages and associated files | 596 | `adb shell pm clear com.test.abc` | Delete all data associated with a package | 597 | `adb pull <remote> <local>` | Download file | 598 | `adb push <local> <remote>` | Upload file | 599 | `adb shell screenrecord /sdcard/demo.mp4` | Record video of the screen | 600 | `adb shell am start -n com.test.abc` | Start an activity | 601 | `adb shell am startservice` | Start a service | 602 | `adb shell am broadcast` | Send a broadcast | 603 | `adb logcat *:D` | Show log with Debug level | 604 | `adb logcat -c` | Clears the entire log | 605 606 ## Android Virtual Device 607 608 An Android Virtual Device (AVD) is an emulator configuration that mimics a physical Android device. It allows developers to test and run Android apps in a simulated environment with specific hardware profiles, screen sizes, and Android versions, facilitating app testing without needing actual devices. 609 610 ```ps1 611 emulator -avd Pixel_8_API_34 -writable-system 612 ``` 613 614 | Command | Description | 615 | ----------------------------- | --------------------------------- | 616 | `-tcpdump /path/dumpfile.cap` | Capture all the traffic in a file | 617 | `-dns-server X.X.X.X` | Set DNS servers | 618 | `-http-proxy X.X.X.X:8080` | Set HTTP proxy | 619 | `-port 5556` | Set the ADB TCP port number | 620 621 ## Unlock Bootloader 622 623 **Requirements**: 624 625 * Enable `Settings` > `Developer Options` > `OEM unlocking` 626 * Enable `Settings` > `Developer Options` > `USB Debugging` 627 628 Unlock the bootloader will wipe the userdata partition. On some device these methods will require a key to successfully unlock the bootloader. 629 630 * Method 1 631 632 ```ps1 633 adb reboot bootloader 634 fastboot oem unlock 635 ``` 636 637 * Method 2 638 639 ```ps1 640 adb reboot bootloader 641 fastboot flashing unlock 642 ``` 643 644 * Methods based on the chip 645 * For Qualcomm devices, you can use EDL (Emergency Download Mode) 646 * For MediaTek devices, BROM (Boot ROM) mode 647 * For Unisoc devices, Research Download Mode. 648 649 ## Android XML 650 651 * [androguard/axml](https://github.com/androguard/axml) - Android binary XML parser in Python 652 * [xgouchet/AXML](https://github.com/xgouchet/AXML) - Android binary XML file parser 653 * [MadSquirrels/pyaxml](https://gitlab.com/MadSquirrels/mobile/pyaxml) - Library to parse and modify AXML files 654 655 ```py 656 pip install pyaxml 657 658 # To print Manifest in XML form 659 pyaxml-rs axml2xml -i AndroidManifest.xml 660 661 # To print resources.arsc in XML form 662 pyaxml-rs arsc2xml -i resources.arsc 663 664 # To convert XML to AXML 665 pyaxml-rs xml2axml -i AndroidManifest.xml -o AndroidManifest.axml 666 ``` 667 668 ## References 669 670 * [A beginners guide to using Frida to bypass root detection. - DianaOpanga - November 27, 2023](https://medium.com/@dianaopanga/a-beginners-guide-to-using-frida-to-bypass-root-detection-16af76b989ac) 671 * [Android App Reverse Engineering 101 - @maddiestone](https://www.ragingrock.com/AndroidAppRE/) 672 * [Android app vulnerability classes - Google Play Protect](https://static.googleusercontent.com/media/www.google.com/fr//about/appsecurity/play-rewards/Android_app_vulnerability_classes.pdf) 673 * [Apkpatcher - Workshop on application patching - Benoît FORGETTE (MadSquirrels) - June 27, 2026](https://ci-yow.com/workshop-slide/slides.html) 674 * [Appium documentation](https://appium.io/docs/en/latest/) 675 * [Configuring Android Emulator with Burp Suite - Jarrod @Jrod_R87 - January 8, 2025](https://owlhacku.com/configuring-android-emulator-with-burp-suite/) 676 * [Configuring Burp Suite with Android Emulators - Aashish Tamang - June 6, 2022](https://blog.yarsalabs.com/setting-up-burp-for-android-application-testing/) 677 * [Configuring Burp Suite With Android Nougat - ropnop - January 18, 2018](https://blog.ropnop.com/configuring-burp-suite-with-android-nougat) 678 * [Configuring Frida with BurpSuite and Genymotion to bypass Android SSL Pinning - arben - September 4, 2020](https://spenkk.github.io/bugbounty/Configuring-Frida-with-Burp-and-GenyMotion-to-bypass-SSL-Pinning/) 679 * [How to root an Android device for analysis and vulnerability assessment - Joe Lovett - August 23, 2024](https://www.pentestpartners.com/security-blog/how-to-root-an-android-device-for-analysis-and-vulnerability-assessment/) 680 * [Intercepting OkHttp at Runtime With Frida - A Practical Guide - Szymon Drosdzol - January 22, 2026](https://blog.doyensec.com/2026/01/22/frida-instrumentation.html) 681 * [Introduction to Android Pentesting - Jarrod - July 8, 2024](https://owlhacku.com/introduction-to-android-pentesting/) 682 * [Mobile Systems and Smartphone Security - @reyammer](https://mobisec.reyammer.io) 683 * [Rooting an Android Emulator for Mobile Security Testing - 8ksecresearch - April 17, 2025](https://8ksec.io/rooting-an-android-emulator-for-mobile-security-testing/)