Drozer

ΠŸΡ€ΠΎ написаниС ΠΏΠ»Π°Π³ΠΈΠ½ΠΎΠ² ΠΏΠΎΠ΄ Π΄Ρ€ΠΎΠ·Π΅Ρ€

Бсылки ΠΏΠΎΠ»Π΅Π·Π½Ρ‹Π΅ - https://blog.attify.com/creating-your-own-drozer-module-for-android-application-testing/ - http://th3-incognito-guy.blogspot.com/2014/09/drozer-security-attack-framework-for.html - https://yashagarwal.in/posts/2018/05/writing-drozer-modules/ - https://github.com/mwrlabs/drozer/wiki/Advanced-patterns - https://github.com/mwrlabs/drozer/wiki/Using-mixins - https://github.com/mwrlabs/drozer/wiki/Using-Reflection - https://github.com/mwrlabs/drozer/wiki/Writing-a-Module - https://github.com/mwrlabs/drozer/wiki/Formulating-intents Modules: https://github.com/mwrlabs/drozer-modules https://github.com/snoopysecurity/Public/blob/master/blog%20archive/2015-10-23-six-things-you-didnt-know-Drozer-could-do.md

Intro

Drozer https://labs.mwrinfosecurity.com/tools/drozer/ https://labs.mwrinfosecurity.com/assets/BlogFiles/mwri-drozer-user-guide-2015-03-23.pdf

ΠšΡ€Π°Ρ‚ΠΊΠΈΠ΅ ΠΏΡ€ΠΈΠΌΠ΅Ρ€Ρ‹ использования: 1. Запуск: adb forward tcp:31415 tcp:31415 run agent on phone drozer console connect 2. ΠœΠΎΠ΄ΡƒΠ»ΠΈ: Бписок доступных ΠΌΠΎΠ΄ΡƒΠ»Π΅ΠΉ: list [search query] Бписок ΠΏΡ€ΠΈΠ»ΠΎΠΆΠ΅Π½ΠΈΠΉ: run app.package.list [-f <search>] Π˜Π½Ρ„ΠΎΡ€ΠΌΠ°Ρ†ΠΈΡ ΠΎ ΠΏΡ€ΠΈΠ»ΠΎΠΆΠ΅Π½ΠΈΠΈ: run app.package.info -a com.test.app Бтатистика ΠΏΠΎ Activity, Receivers, ContentProvider, Services: run app.package.attacksurface com.test.app Бписок Π·Π°ΠΏΡƒΡ‰Π΅Π½Π½Ρ‹Ρ… Activity: run app.activity.info -a com.test.app

ΠœΠΎΠ΄ΡƒΠ»ΡŒ scanner - сканируСт ΠΊΠΎΠΌΠΏΠΎΠ½Π΅Π½Ρ‚Ρ‹ ΠΏΡ€ΠΈΠ»ΠΎΠΆΠ΅Π½ΠΈΠ΅ Π½Π° уязвимости

Поиск custom schema: run scanner.activity.browsable -a com.test.app

Π‘ΠΈΠ»Π΄ Π΄Ρ€ΠΎΠ·Π΅Ρ€Π° с Π½Π΅ΠΎΠ±Ρ…ΠΎΠ΄ΠΈΠΌΡ‹ΠΌΠΈ ΠΏΡ€Π°Π²Π°ΠΌΠΈ: drozer agent build --permission android.PyPermission

Last updated

Was this helpful?