Drozer

ΠŸΡ€ΠΎ написаниС ΠΏΠ»Π°Π³ΠΈΠ½ΠΎΠ² ΠΏΠΎΠ΄ Π΄Ρ€ΠΎΠ·Π΅Ρ€

Бсылки ΠΏΠΎΠ»Π΅Π·Π½Ρ‹Π΅ - https://blog.attify.com/creating-your-own-drozer-module-for-android-application-testing/arrow-up-right - http://th3-incognito-guy.blogspot.com/2014/09/drozer-security-attack-framework-for.htmlarrow-up-right - https://yashagarwal.in/posts/2018/05/writing-drozer-modules/arrow-up-right - https://github.com/mwrlabs/drozer/wiki/Advanced-patternsarrow-up-right - https://github.com/mwrlabs/drozer/wiki/Using-mixinsarrow-up-right - https://github.com/mwrlabs/drozer/wiki/Using-Reflectionarrow-up-right - https://github.com/mwrlabs/drozer/wiki/Writing-a-Modulearrow-up-right - https://github.com/mwrlabs/drozer/wiki/Formulating-intentsarrow-up-right Modules: https://github.com/mwrlabs/drozer-modulesarrow-up-right https://github.com/snoopysecurity/Public/blob/master/blog%20archive/2015-10-23-six-things-you-didnt-know-Drozer-could-do.mdarrow-up-right

Intro

Drozer https://labs.mwrinfosecurity.com/tools/drozer/arrow-up-right https://labs.mwrinfosecurity.com/assets/BlogFiles/mwri-drozer-user-guide-2015-03-23.pdfarrow-up-right

ΠšΡ€Π°Ρ‚ΠΊΠΈΠ΅ ΠΏΡ€ΠΈΠΌΠ΅Ρ€Ρ‹ использования: 1. Запуск: adb forward tcp:31415 tcp:31415 run agent on phone drozer console connect 2. ΠœΠΎΠ΄ΡƒΠ»ΠΈ: Бписок доступных ΠΌΠΎΠ΄ΡƒΠ»Π΅ΠΉ: list [search query] Бписок ΠΏΡ€ΠΈΠ»ΠΎΠΆΠ΅Π½ΠΈΠΉ: run app.package.list [-f <search>] Π˜Π½Ρ„ΠΎΡ€ΠΌΠ°Ρ†ΠΈΡ ΠΎ ΠΏΡ€ΠΈΠ»ΠΎΠΆΠ΅Π½ΠΈΠΈ: run app.package.infoarrow-up-right -a com.test.app Бтатистика ΠΏΠΎ Activity, Receivers, ContentProvider, Services: run app.package.attacksurface com.test.app Бписок Π·Π°ΠΏΡƒΡ‰Π΅Π½Π½Ρ‹Ρ… Activity: run app.activity.infoarrow-up-right -a com.test.app

ΠœΠΎΠ΄ΡƒΠ»ΡŒ scanner - сканируСт ΠΊΠΎΠΌΠΏΠΎΠ½Π΅Π½Ρ‚Ρ‹ ΠΏΡ€ΠΈΠ»ΠΎΠΆΠ΅Π½ΠΈΠ΅ Π½Π° уязвимости

Поиск custom schema: run scanner.activity.browsable -a com.test.app

Π‘ΠΈΠ»Π΄ Π΄Ρ€ΠΎΠ·Π΅Ρ€Π° с Π½Π΅ΠΎΠ±Ρ…ΠΎΠ΄ΠΈΠΌΡ‹ΠΌΠΈ ΠΏΡ€Π°Π²Π°ΠΌΠΈ: drozer agent build --permission android.PyPermission

Last updated