daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

android-applications.md (27164B)


      1 ---
      2 title: "Android Application"
      3 section: "Methodology"
      4 sectionSlug: "methodology"
      5 sourcePath: "docs/methodology/android-applications.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/methodology/android-applications.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Android Application
     12 
     13 ## Lab
     14 
     15 * [payatu/diva-android](https://github.com/payatu/diva-android) - Damn Insecure and vulnerable App for Android
     16 * [HTB VIP - Pinned](https://app.hackthebox.com/challenges/282) - Hack The Box challenge
     17 * [HTB VIP - Manager](https://app.hackthebox.com/challenges/283) - Hack The Box challenge
     18 
     19 ## Extract APK
     20 
     21 ### ADB Method
     22 
     23 Connect to ADB shell and list/download packages.
     24 You might need to enable `Developer mode` and `Debugging` in order to connect with `adb`
     25 
     26 ```powershell
     27 adb shell pm list packages
     28 adb shell pm path com.example.someapp
     29 adb pull /data/app/com.example.someapp-2.apk
     30 ```
     31 
     32 ### Stores
     33 
     34 Warning: Downloading APK files from unofficial stores can compromise your device's security. These sources often host malware and malicious software. Always use trusted and official app stores for downloads.
     35 
     36 * [Google Play](https://play.google.com/store/apps) - Official Store
     37 * [Apkpure.fr](https://apkpure.fr/fr/) - Alternative to Google Play
     38 * [Apkpure.co](https://apkpure.co) - Alternative to Google Play
     39 * [Aptoide](https://fr.aptoide.com/) - Alternative to Google Play
     40 * [Aurora Store](https://f-droid.org/fr/packages/com.aurora.store/) - Alternative to Google Play
     41 
     42 Download APK from Google Play using a 3rd Party:
     43 
     44 * [apkcombo.com](https://apkcombo.com/downloader/)
     45 * [apps.evozi.com](https://apps.evozi.com/apk-downloader/)
     46 
     47 ## Static Analysis
     48 
     49 ### Extract Contents From APK
     50 
     51 Search for strings `flag`,`secret`, the default string file is `Resources/resources.arsc/res/values/strings.xml`.
     52 
     53 ```powershell
     54 apktool d application.apk
     55 ```
     56 
     57 ### Decompile Data as Java Code
     58 
     59 * Rename `application.apk` to `application.zip`: `mv application.apk application.zip`
     60 * Extract `classes.dex`: `unzip application.zip`
     61 * Use `dex2jar` to obtain a jar file: `/usr/bin/d2j-dex2jar classes.dex`
     62 * Use `jadx` using full CPU: `jadx classes.dex -j $(grep -c ^processor /proc/cpuinfo) -d Downloads/app/ > /dev/null`
     63 
     64     ```powershell
     65     jadx-gui
     66     --deobf # remove obfuscation by AndroGuard
     67     -e      # generate a gradle project for Android Studio (easy to find function)
     68     ```
     69 
     70 To reverse `.odex` you need to provide the `/system/framework/arm`, fortunately since we have the firmware we have it.
     71 
     72 ```powershell
     73 java -jar baksmali-2.3.4.jar x application.odex -d k107-mb-8.1/system/framework/arm -o application
     74 apktool d application.apk 
     75 apktool b rebuild_folder -o rebuilt.apk
     76 ```
     77 
     78 ### Decompile Native Code
     79 
     80 Native library are represented as `.so` files.
     81 These libraries by default are included in the APK at the file path `/lib/<cpu>/lib<name>.so` or `/assets/<custom_name>`.
     82 
     83 Use `IDA`, `Radare2/Cutter` or `Ghidra` to reverse them.
     84 
     85 | CPU Native           | Library Path               |
     86 | -------------------- | -------------------------- |
     87 | "generic" 32-bit ARM | lib/armeabi/libcalc.so     |
     88 | x86                  | lib/x86/libcalc.so         |
     89 | x64                  | lib/x86_64/libcalc.so      |
     90 | ARMv7                | lib/armeabi-v7a/libcalc.so |
     91 | ARM64                | lib/arm64-v8a/libcalc.so   |
     92 
     93 :warning: The shared object file (`.so`) doesn't need to be embedded in the app.
     94 
     95 ### Mobile Security Framework Static
     96 
     97 > Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.
     98 
     99 * [MobSF - Documentation](https://mobsf.github.io/docs/#/)
    100 * [MobSF - Github](https://github.com/MobSF/Mobile-Security-Framework-MobSF)
    101 * [MobSF - Live Demo](https://mobsf.live/)
    102 
    103 Run [MobSF/Mobile-Security-Framework-MobSF](https://github.com/MobSF/Mobile-Security-Framework-MobSF)
    104 
    105 * Latest version from DockerHub
    106 
    107     ```powershell
    108     docker run -it --name mobsf -p 8000:8000 opensecurity/mobile-security-framework-mobsf:latest
    109     ```
    110 
    111 * Enable persistence on the Docker container
    112 
    113     ```powershell
    114     docker run -it --rm --name mobsf -p 8000:8000 -v <your_local_dir>:/root/.MobSF opensecurity/mobile-security-framework-mobsf:latest
    115     ```
    116 
    117 ### Online Assets
    118 
    119 :warning: Uploading APKs to uncontrolled websites risks data leaks, malware, intellectual property theft, and privacy violations. Use trusted platforms only to ensure the security and integrity of your app.
    120 
    121 * [appetize.io](https://appetize.io/) - Instantly run mobile apps in your browser
    122 * [mobsf.live](https://mobsf.live/) - Demo version of MobSF
    123 * [hybrid-analysis.com](https://www.hybrid-analysis.com/sample/573df0b1cb5ffc0a25306be5ec83483ed1b2acdba37dd93223b9f14f42b2fdea?environmentId=200) - Sandbox analysis of APK files
    124 
    125 ### React Native and Hermes
    126 
    127 Identify React Native app with `index.android.bundle` inside the `assets` folder
    128 
    129 ```ps1
    130 Hermes: pip install hbctool
    131 ╰─$ hbctool disasm index.android.bundle indexasm
    132 [*] Disassemble 'index.android.bundle' to 'indexasm' path
    133 [*] Hermes Bytecode [ Source Hash: 4013cb75f7e16d4474f5cf258edc45ee16585560, HBC Version: 74 ]
    134 [*] Done
    135 ```
    136 
    137 ### Flutter
    138 
    139 Indentify Flutter use in the `MANIFEST.MF` and search for `libflutter.so`.
    140 
    141 * [worawit/blutter](https://github.com/worawit/blutter) - Flutter Mobile Application Reverse Engineering Tool
    142 
    143     ```ps1
    144     blutter jadx/resources/lib/arm64-v8a/ ./blutter_output
    145     ```
    146 
    147 ## APK Patching
    148 
    149 * [MadSquirrels/apkpatcher](https://gitlab.com/MadSquirrels/mobile/apkpatcher)
    150 
    151 ```ps1
    152 docker run --rm -v .:/pwd -it madsquirrels/apkpatcher -a base.apk
    153 
    154 # Java dependencies
    155 apt install -y default-jre
    156 
    157 # sdktools dependendies installation
    158 wget https://dl.google.com/android/repository/commandlinetools-linux-6200805_latest.zip
    159 mkdir /usr/lib/android-sdk
    160 cd /usr/lib/android-sdk
    161 unzip commandlinetools-linux-6200805_latest.zip
    162 mkdir cmdline-tools
    163 mv tools/ cmdline-tools/
    164 echo 'export ANDROID_SDK_ROOT=/usr/lib/android-sdk' >> ~/.bashrc
    165 
    166 # installation of platform-tools
    167 sdkmanager "platform-tools" "platforms;android-36" "build-tools;36.0.0" "emulator"
    168 
    169 # install apkpatcher
    170 pip install apkpatcher
    171 ```
    172 
    173 ### Sign and Package APK
    174 
    175 * [iBotPeaches/apktool](https://github.com/iBotPeaches/Apktool) + `jarsigner`
    176 
    177     ```powershell
    178     apktool b ./application.apk
    179     keytool -genkey -v -keystore application.keystore -alias application -keyalg RSA -keysize 2048 -validity 10000
    180     jarsigner -verbose -sigalg SHA1withRSA -digestalg SHA1 -keystore application.keystore application.apk application
    181     zipalign -v 4 application.apk application-signed.apk
    182     ```
    183 
    184 * [iBotPeaches/apktool](https://github.com/iBotPeaches/Apktool) + `signapk`
    185 
    186     ```powershell
    187     apktool b app-release
    188     ./signapk app-release/dist/app-release.apk
    189     ```
    190 
    191 * [patrickfav/uber-apk-signer](https://github.com/patrickfav/uber-apk-signer) (Linux only)
    192 
    193     ```powershell
    194     java -jar uber-apk-signer.jar --apks /path/to/apks
    195     ```
    196 
    197 * [APK Toolkit v1.3](https://xdaforums.com/t/tool-apk-toolkit-v1-3-windows.4572881/) (Windows only)
    198 
    199 ### Unpack Resources
    200 
    201 ```ps1
    202 apkpatcher -a <apk> --only-unpack dir
    203 apkpatcher -a <new_apk> --only-repack dir
    204 ```
    205 
    206 ### Inject Proxy Certificate
    207 
    208 Accept user certificate
    209 
    210 ```ps1
    211 apkpatcher -a <apk> -e
    212 ```
    213 
    214 Add a custom certificate
    215 
    216 ```ps1
    217 apkpatcher -a <apk> -c burp.der
    218 ```
    219 
    220 ### Add Permissions
    221 
    222 ```ps1
    223 apkpatcher -a <apk> --add-permissions <my_permission>
    224 ```
    225 
    226 ### Debug Mode
    227 
    228 Inject the `android:debuggable` option into an application `AndroidManifest.xml`, allowing users to debug applications even when they are in release mode.
    229 
    230 ```ps1
    231 apkpatcher -a <apk>  --enable-debug
    232 ```
    233 
    234 Set the application to be the debug target.
    235 
    236 ```ps1
    237 adb shell am set-debug-app --persistent
    238 ```
    239 
    240 Start the application’s activity in debug mode.
    241 
    242 ```ps1
    243 adb shell am start -D -a android.intent.action.MAIN -n <package>/<Activity>
    244 ```
    245 
    246 Then use `gdbserver` for Native Code or Java Debugger like `jdb`.
    247 
    248 ```ps1
    249 adb forward tcp:12345 jdwp:$(adb shell pidof <package> )
    250 jdb -attach localhost:12345
    251 ```
    252 
    253 ## Dynamic Analysis
    254 
    255 Dynamic analysis for Android malware involves executing and monitoring an app in a controlled environment to observe its behavior. This technique detects malicious activities like data exfiltration, unauthorized access, and system modifications. Additionally, it aids in reverse engineering app features, revealing hidden functionalities and potential vulnerabilities for better threat mitigation.
    256 
    257 ### Burp Suite
    258 
    259 * Proxy > Listen to all interfaces
    260 * Import/Export CA certificate
    261 * `adb push burp.der /sdcard/burp.crt`
    262 * Open the Settings on the device and search "Install Cert"
    263 * Click Install certificates from SD card
    264 * Configure the AVD to use the proxy
    265 
    266 ```ps1
    267 # Convert Burp certificate for Android
    268 openssl x509 -inform DER -in burp.der -out burp.pem
    269 openssl x509 -inform PEM -subject_hash_old -in burp.pem |head -1
    270 mv burp.pem <hash output>.0
    271 
    272 # Push the certificate in the AVD
    273 emulator -list-avds
    274 emulator -avd Pentesting_Device -writable-system
    275 adb root
    276 adb remount
    277 adb push <hash>.0 /sdcard/
    278 
    279 # Change the permissions
    280 adb shell
    281 mv /sdcard/<hash>.0 /system/etc/security/cacerts/
    282 chmod 644 /system/etc/security/cacerts/<hash>.0
    283 chown root:root /system/etc/security/cacerts/<hash>.0
    284 ```
    285 
    286 ### Frida
    287 
    288 * [Frida - Documentation](https://frida.re/docs/android)
    289 * [Frida - Github](https://github.com/frida/frida/)
    290 
    291 Download [frida/frida](https://github.com/frida/frida/releases) from releases.
    292 
    293 ```ps1
    294 pip install frida-tools
    295 unxz frida-server.xz
    296 adb root # might be required
    297 adb push frida-server /data/local/tmp/
    298 adb shell "chmod 755 /data/local/tmp/frida-server"
    299 adb shell "/data/local/tmp/frida-server &"
    300 ```
    301 
    302 Inject frida inside the APK.
    303 
    304 ```ps1
    305 $ pip install frida-tools
    306 $ frida --version
    307 16.7.13
    308 
    309 $ apkpatcher -a <apk> --download_frida_version <version>
    310 $ apkpatcher -a <apk> --download_frida_version 16.7.13
    311 ```
    312 
    313 Interesting Frida scripts:
    314 
    315 * [Universal Android SSL Pinning Bypass with Frida](https://codeshare.frida.re/@pcipolloni/universal-android-ssl-pinning-bypass-with-frida/) -  `frida --codeshare pcipolloni/universal-android-ssl-pinning-bypass-with-frida -f YOUR_BINARY`
    316 * [frida-multiple-unpinning](https://codeshare.frida.re/@akabe1/frida-multiple-unpinning/) - `frida --codeshare akabe1/frida-multiple-unpinning -f YOUR_BINARY`
    317 * [aesinfo](https://codeshare.frida.re/@dzonerzy/aesinfo/) - `frida --codeshare dzonerzy/aesinfo -f YOUR_BINARY`
    318 * [fridantiroot](https://codeshare.frida.re/@dzonerzy/fridantiroot/) - `frida --codeshare dzonerzy/fridantiroot -f YOUR_BINARY`
    319 * [anti-frida-bypass](https://codeshare.frida.re/@enovella/anti-frida-bypass/) - `frida --codeshare enovella/anti-frida-bypass -f YOUR_BINARY`
    320 * [xamarin-antiroot](https://codeshare.frida.re/@Gand3lf/xamarin-antiroot/) - `frida --codeshare Gand3lf/xamarin-antiroot -f YOUR_BINARY`
    321 * [Intercept Android APK Crypto Operations](https://codeshare.frida.re/@fadeevab/intercept-android-apk-crypto-operations/) - `frida --codeshare fadeevab/intercept-android-apk-crypto-operations -f YOUR_BINARY`
    322 * [Android Location Spoofing](https://codeshare.frida.re/@dzervas/android-location-spoofing/) - `frida --codeshare dzervas/android-location-spoofing -f YOUR_BINARY`
    323 * [java-crypto-viewer](https://codeshare.frida.re/@Serhatcck/java-crypto-viewer/) - `frida --codeshare Serhatcck/java-crypto-viewer -f YOUR_BINARY`
    324 
    325 ### Runtime Mobile Security
    326 
    327 > Runtime Mobile Security (RMS) 📱🔥 - is a powerful web interface that helps you to manipulate Android and iOS Apps at Runtime
    328 
    329 * [RMS - Github](https://github.com/m0bilesecurity/RMS-Runtime-Mobile-Security)
    330 
    331 **Requirements**:
    332 
    333 * `adb`
    334 * `frida`: server up and running on the target device
    335 
    336 In case of issue with your favorite Browser, please use Google Chrome (fully supported).
    337 
    338 * Install RMS
    339 
    340     ```powershell
    341     npm install -g rms-runtime-mobile-security
    342     ```
    343 
    344 * Make sure `frida-server` is up and running on the target device.
    345 * Launch RMS: `rms`
    346 * Open your browser at `http://127.0.0.1:5491/`
    347 * Attach to the app, find name with `adb shell pm list package | grep NAME`
    348 
    349 ### Genymotion
    350 
    351 Genymotion is a robust Android emulator designed for developers, offering fast and reliable virtual devices for app testing. It features GPS, battery, and network simulation, enabling comprehensive testing and development
    352 
    353 * [Genymotion](https://www.genymotion.com/)
    354 * [Genymotion Desktop](https://www.genymotion.com/product-desktop/)
    355 * [Genymotion Device Image](https://www.genymotion.com/product-device-image/)
    356 * [Genymotion SaaS](https://www.genymotion.com/product-cloud/)
    357 
    358 ### Android SDK emulator
    359 
    360 Android Virtual Device (AVD) without Google Play Store.
    361 
    362 * Download the files for an API 25 build
    363 
    364     ```powershell
    365     sdkmanager "system-images;android-25;google_apis;x86_64"
    366     ```
    367 
    368 * Create a device based on what we downloaded previously
    369 
    370     ```powershell
    371     avdmanager create avd x86_64_api_25 -k "system-images;android-25;google_apis;x86_64"
    372     ```
    373 
    374 * Run the emulator
    375 
    376     ```powershell
    377     emulator @x86_64_api_25
    378 
    379     emulator -list-avds
    380     emulator -avd <non_production_avd_name> -writable-system -no-snapshot
    381     emulator -avd Pixel_XL_API_31 -writable-system -http-proxy 127.0.0.1:8080
    382     ```
    383 
    384 * Install the APK
    385 
    386     ```powershell
    387     adb install ./challenge.apk
    388     ```
    389 
    390 * Start the App
    391 
    392     ```powershell
    393     adb shell monkey -p com.scottyab.rootbeer.sample 1
    394     ```
    395 
    396 ### Mobile Security Framework Dynamic
    397 
    398 :warning: Dynamic Analysis will not work if you use MobSF docker container or setup MobSF inside a Virtual Machine.
    399 
    400 **Requirements**:
    401 
    402 * Genymotion (Supports x86_64 architecture Android 4.1 - 11.0, upto API 30)
    403     * Android 5.0 - 11.0 - uses Frida and works out of the box with zero configuration or setup.
    404     * Android 4.1 - 4.4 - uses Xposed Framework and requires MobSFy
    405 * Genymotion Cloud
    406     * [Amazon Marketplace - TCP 5555](https://aws.amazon.com/marketplace/seller-profile?id=933724b4-d35f-4266-905e-e52e4792bc45)
    407     * [Azure Marketplace - TCP 5555](https://azuremarketplace.microsoft.com/en-us/marketplace/apps/genymobile.genymotion-cloud)
    408 * Android Studio Emulator (only Android images upto API 28 are supported)
    409     * AVD without Google Play Store
    410 
    411 Dynamic Analysis from MobSF grants you the following features:
    412 
    413 * Web API Viewer
    414 * Frida API Monitor
    415 
    416 ### Appium
    417 
    418 Appium is an open-source project and ecosystem of related software, designed to facilitate UI automation of many app platforms, including mobile (iOS, Android, Tizen), browser (Chrome, Firefox, Safari), desktop (macOS, Windows), TV (Roku, tvOS, Android TV, Samsung), and more!
    419 
    420 * Install appium: `npm install -g appium`
    421 * Install and validate the `uiautomator2` driver
    422 
    423     ```ps1
    424     export JAVA_HOME=/usr/lib/jvm/default-java
    425     export ANDROID_HOME=/home/user/Android/Sdk/
    426     wget https://github.com/google/bundletool/releases/download/1.17.1/bundletool-all-1.17.1.jar
    427     sudo mv bundletool-all-1.17.1.jar /usr/local/bin
    428     appium driver install uiautomator2
    429     appium driver doctor uiautomator2
    430     ```
    431 
    432 * Start the server on the default host (0.0.0.0) and port (4723): `appium server`
    433 * Install the Appium Python client: `pip install Appium-Python-Client`
    434 * Use the [appium/appium-inspector](https://github.com/appium/appium-inspector) with the following capability
    435 
    436     ```json
    437     {
    438     "platformName": "Android",
    439     "appium:automationName": "UiAutomator2"
    440     }
    441     ```
    442 
    443 Examples:
    444 
    445 * [quickstarts/py/test.py](https://github.com/appium/appium/blob/master/packages/appium/sample-code/quickstarts/py/test.py)
    446 * [quickstarts/js/test.js](https://github.com/appium/appium/blob/master/packages/appium/sample-code/quickstarts/js/test.js)
    447 * [quickstarts/js/test.rb](https://github.com/appium/appium/blob/master/packages/appium/sample-code/quickstarts/rb/test.rb)
    448 
    449 ### Flutter
    450 
    451 Repackage a Flutter Android application to allow Burp Suite proxy interception.
    452 
    453 * [ptswarm/reFlutter](https://github.com/ptswarm/reFlutter) - Flutter Reverse Engineering Framework
    454 
    455     ```ps1
    456     pip3 install reflutter
    457     reflutter application.apk
    458     ```
    459 
    460 * Sign the apk with [patrickfav/uber-apk-signer](https://github.com/patrickfav/uber-apk-signer/releases/tag/v1.2.1)
    461 
    462     ```ps1
    463     java -jar ./uber-apk-signer-1.3.0.jar --apks release.apk
    464     java -jar ./uber-apk-signer.jar --allowResign -a release.RE.apk
    465     ```
    466 
    467 An alternative way to do it is using a rooted Android device with `zygisk-reflutter`.
    468 
    469 * [yohanes/zygisk-reflutter](https://github.com/yohanes/zygisk-reflutter) - Zygisk-based reFlutter (Rooted Android with Magisk installed and Zygisk Enabled)
    470 
    471     ```ps1
    472     adb push  zygiskreflutter_1.0.zip /sdcard/
    473     adb shell su -c magisk --install-module /sdcard/zygiskreflutter_1.0.zip
    474     adb reboot
    475     ```
    476 
    477 ## SSL Pinning Bypass
    478 
    479 SSL certificate pinning in an APK involves embedding a server's public key or certificate directly into the app. This ensures the app only trusts specific certificates, preventing man-in-the-middle attacks by rejecting any certificates not matching the pinned ones, even if they are otherwise valid.
    480 
    481 :warning: Android 9.0 is changing the defaults for Network Security Configuration to block all cleartext traffic.
    482 
    483 * [shroudedcode/apk-mitm](https://github.com/shroudedcode/apk-mitm) - A CLI application that automatically prepares Android APK files for HTTPS inspection
    484 
    485     ```powershell
    486     $ npx apk-mitm application.apk
    487     npx: 139 installé(s) en 12.206s
    488     ╭ apk-mitm v0.6.1
    489     ├ apktool v2.4.1
    490     ╰ uber-apk-signer v1.1.0
    491     Using temporary directory:
    492     /tmp/87d3a4921ddf86cde634205480f89e90
    493     ✔ Decoding APK file
    494     ✔ Modifying app manifest
    495     ✔ Modifying network security config
    496     ✔ Disabling certificate pinning
    497     ✔ Encoding patched APK file
    498     ✔ Signing patched APK file
    499     Done!  Patched file: ./application.apk
    500     ```
    501 
    502 * [51j0/Android-CertKiller](https://github.com/51j0/Android-CertKiller) - An automation script to bypass SSL/Certificate pinning in Android
    503 
    504     ```powershell
    505     python main.py -w #(Wizard mode)
    506     python main.py -p 'root/Desktop/base.apk' #(Manual mode)
    507     ```
    508 
    509 * [frida/frida](https://github.com/frida/frida) - Universal SSL Pinning Bypass
    510 
    511     ```javascript
    512     $ adb devices
    513     $ adb root
    514     $ adb shell
    515     $ phone:/# ./frida-server
    516 
    517     // https://codeshare.frida.re/@pcipolloni/universal-android-ssl-pinning-bypass-with-frida/
    518     $ frida -U --codeshare pcipolloni/universal-android-ssl-pinning-bypass-with-frida -f com.example.pinned
    519 
    520     $ frida -U -f org.package.name -l universal-ssl-check-bypass.js --no-pause
    521     Java.perform(function() {                
    522         var array_list = Java.use("java.util.ArrayList");
    523         var ApiClient = Java.use('com.android.org.conscrypt.TrustManagerImpl');
    524         ApiClient.checkTrustedRecursive.implementation = function(a1,a2,a3,a4,a5,a6) {
    525             var k = array_list.$new(); 
    526             return k;
    527         }
    528     },0);
    529     ```
    530 
    531 * [m0bilesecurity/RMS-Runtime-Mobile-Security](https://github.com/m0bilesecurity/RMS-Runtime-Mobile-Security) - Certificate Pinning bypass script (all + okhttpv3)
    532 * [federicodotta/Brida](https://github.com/federicodotta/Brida) - The new bridge between Burp Suite and Frida
    533 
    534 ## Root Detection Bypass
    535 
    536 Common root detection techniques:
    537 
    538 * Su binaries: `su`/`busybox`
    539 * Known Root Files/Paths : `Superuser.apk`
    540 * Root Management Apps: `Magisk`, `SuperSU`
    541 * RW paths:  `/system`, `/data` directories
    542 * System Properties
    543 
    544 Common bypass:
    545 
    546 * [fridantiroot](https://codeshare.frida.re/@dzonerzy/fridantiroot/) - `frida --codeshare dzonerzy/fridantiroot -f YOUR_BINARY`
    547 * [xamarin-antiroot](https://codeshare.frida.re/@Gand3lf/xamarin-antiroot/) - `frida --codeshare Gand3lf/xamarin-antiroot -f YOUR_BINARY`
    548 * [multiple-root-detection-bypass/](https://codeshare.frida.re/@KishorBal/multiple-root-detection-bypass/) - `frida --codeshare KishorBal/multiple-root-detection-bypass -f YOUR_BINARY`
    549 
    550 ## Android Debug Bridge
    551 
    552 Android Debug Bridge (ADB) is a versatile command-line tool that enables communication between a computer and an Android device. It facilitates tasks like installing apps, debugging, accessing the device's shell, and transferring files, making it essential for developers and power users in Android development and troubleshooting.
    553 
    554 ### USB Debugging
    555 
    556 * Open the **Settings** app.
    557 * Select **System**.
    558 * Scroll to the bottom and select **About phone**.
    559 * Scroll to the bottom and tap **Build number** 7 times.
    560 * Return to the previous screen to find **Developer options** near the bottom.
    561 * Scroll down and enable **USB debugging**.
    562 
    563 ```ps1
    564 ./platform-tools/adb connect IP:PORT
    565 ./platform-tools/adb shell
    566 ```
    567 
    568 ### Wireless Debugging
    569 
    570 * Open the **Settings** app.
    571 * Select **System**.
    572 * Scroll to the bottom and select **About phone**.
    573 * Scroll to the bottom and tap **Build number** 7 times.
    574 * Return to the previous screen to find **Developer options** near the bottom.
    575 * Scroll down and enable **Wifi debugging**.
    576 * Click on **Wifi debugging** to access the settings
    577 
    578 One more step, you need to pair the devices using a code.
    579 
    580 ```ps1
    581 ./platform-tools/adb pair IP:PORT CODE
    582 ./platform-tools/adb connect IP:PORT
    583 ./platform-tools/adb shell
    584 ```
    585 
    586 | Command                                   | Description                               |
    587 | ----------------------------------------- | ----------------------------------------- |
    588 | `adb devices`                             | List devices                              |
    589 | `adb connect <IP>:<PORT>`                 | Connect to a remote device                |
    590 | `adb install app.apk`                     | Install application                       |
    591 | `adb uninstall app.apk`                   | Uninstall application                     |
    592 | `adb root`                                | Restarting adbd as root                   |
    593 | `adb shell pm list packages`              | List packages                             |
    594 | `adb shell pm list packages -3`           | Show third party packages                 |
    595 | `adb shell pm list packages -f`           | Show packages and associated files        |
    596 | `adb shell pm clear com.test.abc`         | Delete all data associated with a package |
    597 | `adb pull <remote> <local>`               | Download file                             |
    598 | `adb push <local> <remote>`               | Upload file                               |
    599 | `adb shell screenrecord /sdcard/demo.mp4` | Record video of the screen                |
    600 | `adb shell am start -n com.test.abc`      | Start an activity                         |
    601 | `adb shell am startservice`               | Start a service                           |
    602 | `adb shell am broadcast`                  | Send a broadcast                          |
    603 | `adb logcat *:D`                          | Show log with Debug level                 |
    604 | `adb logcat -c`                           | Clears the entire log                     |
    605 
    606 ## Android Virtual Device
    607 
    608 An Android Virtual Device (AVD) is an emulator configuration that mimics a physical Android device. It allows developers to test and run Android apps in a simulated environment with specific hardware profiles, screen sizes, and Android versions, facilitating app testing without needing actual devices.
    609 
    610 ```ps1
    611 emulator -avd Pixel_8_API_34 -writable-system
    612 ```
    613 
    614 | Command                       | Description                       |
    615 | ----------------------------- | --------------------------------- |
    616 | `-tcpdump /path/dumpfile.cap` | Capture all the traffic in a file |
    617 | `-dns-server X.X.X.X`         | Set DNS servers                   |
    618 | `-http-proxy X.X.X.X:8080`    | Set HTTP proxy                    |
    619 | `-port 5556`                  | Set the ADB TCP port number       |
    620 
    621 ## Unlock Bootloader
    622 
    623 **Requirements**:
    624 
    625 * Enable `Settings` > `Developer Options` > `OEM unlocking`
    626 * Enable `Settings` > `Developer Options` > `USB Debugging`
    627 
    628 Unlock the bootloader will wipe the userdata partition. On some device these methods will require a key to successfully unlock the bootloader.
    629 
    630 * Method 1
    631 
    632     ```ps1
    633     adb reboot bootloader
    634     fastboot oem unlock
    635     ```
    636 
    637 * Method 2
    638 
    639     ```ps1
    640     adb reboot bootloader
    641     fastboot flashing unlock
    642     ```
    643 
    644 * Methods based on the chip
    645     * For Qualcomm devices, you can use EDL (Emergency Download Mode)
    646     * For MediaTek devices, BROM (Boot ROM) mode
    647     * For Unisoc devices, Research Download Mode.
    648 
    649 ## Android XML
    650 
    651 * [androguard/axml](https://github.com/androguard/axml) - Android binary XML parser in Python
    652 * [xgouchet/AXML](https://github.com/xgouchet/AXML) - Android binary XML file parser
    653 * [MadSquirrels/pyaxml](https://gitlab.com/MadSquirrels/mobile/pyaxml) - Library to parse and modify AXML files
    654 
    655 ```py
    656 pip install pyaxml
    657 
    658 # To print Manifest in XML form
    659 pyaxml-rs axml2xml -i AndroidManifest.xml
    660 
    661 # To print resources.arsc in XML form
    662 pyaxml-rs arsc2xml -i resources.arsc
    663 
    664 # To convert XML to AXML
    665 pyaxml-rs xml2axml -i AndroidManifest.xml -o AndroidManifest.axml
    666 ```
    667 
    668 ## References
    669 
    670 * [A beginners guide to using Frida to bypass root detection. - DianaOpanga - November 27, 2023](https://medium.com/@dianaopanga/a-beginners-guide-to-using-frida-to-bypass-root-detection-16af76b989ac)
    671 * [Android App Reverse Engineering 101 - @maddiestone](https://www.ragingrock.com/AndroidAppRE/)
    672 * [Android app vulnerability classes - Google Play Protect](https://static.googleusercontent.com/media/www.google.com/fr//about/appsecurity/play-rewards/Android_app_vulnerability_classes.pdf)
    673 * [Apkpatcher - Workshop on application patching - Benoît FORGETTE (MadSquirrels) - June 27, 2026](https://ci-yow.com/workshop-slide/slides.html)
    674 * [Appium documentation](https://appium.io/docs/en/latest/)
    675 * [Configuring Android Emulator with Burp Suite - Jarrod @Jrod_R87 - January 8, 2025](https://owlhacku.com/configuring-android-emulator-with-burp-suite/)
    676 * [Configuring Burp Suite with Android Emulators - Aashish Tamang - June 6, 2022](https://blog.yarsalabs.com/setting-up-burp-for-android-application-testing/)
    677 * [Configuring Burp Suite With Android Nougat - ropnop - January 18, 2018](https://blog.ropnop.com/configuring-burp-suite-with-android-nougat)
    678 * [Configuring Frida with BurpSuite and Genymotion to bypass Android SSL Pinning - arben - September 4, 2020](https://spenkk.github.io/bugbounty/Configuring-Frida-with-Burp-and-GenyMotion-to-bypass-SSL-Pinning/)
    679 * [How to root an Android device for analysis and vulnerability assessment - Joe Lovett - August 23, 2024](https://www.pentestpartners.com/security-blog/how-to-root-an-android-device-for-analysis-and-vulnerability-assessment/)
    680 * [Intercepting OkHttp at Runtime With Frida - A Practical Guide - Szymon Drosdzol - January 22, 2026](https://blog.doyensec.com/2026/01/22/frida-instrumentation.html)
    681 * [Introduction to Android Pentesting - Jarrod - July 8, 2024](https://owlhacku.com/introduction-to-android-pentesting/)
    682 * [Mobile Systems and Smartphone Security - @reyammer](https://mobisec.reyammer.io)
    683 * [Rooting an Android Emulator for Mobile Security Testing - 8ksecresearch - April 17, 2025](https://8ksec.io/rooting-an-android-emulator-for-mobile-security-testing/)