
Explore Android architecture from the Linux kernel through the hardware abstraction layer to libraries, Android runtime with ahead-of-time compilation and garbage collection, and the application framework with key managers.
Explore the fundamentals of android applications, including Java, the Android SDK, packaging into a package and archive, resources and assets, and the roles of activities, services, and permissions.
Explore Android Debug Bridge (ADB) and how it enables a development machine to communicate with Android devices through setup, connections, shell access, and basic ADB commands.
· Download Android SDK from : http://developer.android.com/sdk/index.html.
Download the latest version of apktool from : http://ibotpeaches.github.io/Apktool/.
Download latest version of dex2jar from : https://bitbucket.org/pxb1988/dex2jar/downloads
Download Link : https://developer.android.com/studio
Set up the Genymotion emulator and Android Studio, install the SDK and tools, configure VirtualBox, download and start a compatible Android device for bug bounty testing.
Burp proxy acts as a man-in-the-middle to intercept and modify requests and responses between an app and its server, with a Firefox setup using 127.0.0.1.
Learn to use burp interceptor by configuring proxy listeners, routing mobile traffic through a local proxy, installing the burp certificate, and recording and editing http requests and responses.
Burp intruder for brute-force testing by selecting parameters, adding payloads, and positioning payloads to test multiple inputs, using sniper and cluster bomb modes.
Configure the Android emulator or device to intercept traffic with Burp by setting the correct port number, IP address, and listening on the appropriate interfaces.
Install the Burp CA certificate on an Android emulator or device to intercept traffic, navigate downloads, adjust security settings, and resolve certificate installation issues.
Learn to use Burp professional by obtaining a free license and setting up Burp Suite Pro, including JDK download, firewall and antivirus adjustments, and offline activation.
Explore the divine Android application, an intentionally vulnerable app for penetration testing. Download the official source, compile with Android Studio, install on device or emulator, and begin the challenges.
Install and configure the insecure bank lab version 2 for testing, setting up the server and client app on an android emulator, and validate credentials via server logs.
Explore how Drozer coordinates client, host, and emulator to test Android apps, using console modules to inspect packages, attack surfaces, and content providers.
Explore the OWASP top 10 mobile vulnerabilities and learn practical hunting for improper platform usage in Android, focusing on platform features, permissions, and secure server-side controls.
Identify insecure logging vulnerabilities in an Android app by examining log files for plaintext credentials, and learn how a single code line converts input to plaintext, exposing sensitive data.
Identify insecure data storage as a top vulnerability when devices are lost or stolen, risking credentials, banking details, and PII; enforce encrypted cookies, secure in-device storage, and minimize data logging.
This lecture examines insecure data storage in an Android app, identifying vulnerable code and showing how credentials are stored in shared preferences in plain text, exposing a vulnerability.
Examine insecure data storage in the rebate app, showing credentials stored as strings in a local database and exposed in the my user table with plaintext secrets.
Investigate insecure data storage by tracing how credentials are saved to a temporary plaintext file and exposed in storage.
Investigate insecure data storage by storing credentials in an external storage file. Learn how missing storage permissions allow access to sensitive data on an SD card.
Explore insecure mobile app communication risks, including man-in-the-middle attacks on local networks, and learn to enforce secure connections via certificate validation and proper handshake.
Learn to identify and prevent insecure authentication in mobile apps, including bypass attacks, token-based device verification, and avoiding local storage of credentials, to stop unauthorized access.
Expose how input validation issues enable sql injection, revealing vulnerability to unauthorized access and exposing user data such as passwords and credit card numbers, with log analysis guiding discovery.
Explore how insufficient cryptography on mobile devices exposes encrypted data to attackers and enables unauthorized retrieval from mobile databases.
Examine weak cryptographic vulnerabilities in Android apps by analyzing encryption methods, aliases, and how credentials and encrypted passwords are stored in shared preferences.
Identify insecure authorization flaws that allow bypassing authentication and accessing admin functions. Learn how server-side validation, proper permissions, and back-end data controls prevent unauthorized access.
Explore how honesty and different problem shape Android bug bounty and practical penetration testing. People say they seem to get past that problem.
Learn how buffer overflows from untrusted inputs trigger remote code execution and denial of service, and how strict input validation and memory bounds prevent such vulnerabilities in mobile apps.
Identify hard coded credentials by decompiling the app, inspect the hard coding activity, and reproduce the access granted condition by matching the input to the hardcoded string.
Identify and extract hardcoded values from Android apps by inspecting the source code, locating the vendor key, and understanding how to approach applications via code analysis.
Examine input validation issues in the diva application by sending oversized input that overflows a 20-element buffer, causing a crash and exposing a denial of service risk on the server.
Explore how code tampering enables modded Android apps from third-party stores to alter resources, inject malicious scripts, and unlock unauthorized features, risking user data and security.
Learn practical techniques to bypass Android protection checks by analyzing app code, modifying and rebuilding an APK, signing and deploying to an emulator for security testing.
Explore reverse engineering techniques to analyze apps and uncover obfuscation strategies. Examine how hardcoded data paths and backend database access can expose data and affect security.
Identify and exploit hardcoded values by inspecting the app's source code, locate the vendor key inside the c file, and understand how to retrieve hardcoded credentials.
Explore extraneous functionality in mobile apps, uncover hidden back-end features, and prevent unauthorized access by auditing configurations, debug modes, and log statements before production.
---------- M10 : Extraneous Functionality ----------------
The Insecure Bank v2 apk file has a customer login page
This is the customer login page
We will try to find out any hidden admin login pages left behind by the Developers.
Step 1 : We will decompile the .apk file using "apktool" [Command : java -jar d InsecureBankv2.apk]
Step 2 : Navigate to the folder ~/apktool/InsecureBankv2/res/values and open the file "strings.xml" for editing.
Step 3 : We find a flag “is_admin”. [Our piece of interest]
Step 4 : We will change the flag from 'no' to 'yes' and save the "Strings.xml" file.
Step 5 : We will now recompile the application.
[ Command :java -jar apktool.jar b InsecureBankv2 -o InsecureBankv2.apk]
Step 6 : Copy the InsecureBankv2.apk file generated above into the “dist” folder of "SignApk" and enter the below command to sign the apk file
[Command : java -jar sign.jar InsecureBankv2.apk]
Step 7 : A new sign apk file called InsecureBankv2.s.apk is generated in the same “dist” folder.
Step 8 : Install the new InsecureBankv2.s.apk onto the emulator.
We can now see the "Create user" option which directs the user to the User Creation Module which should have been accessed only by the admins.
Note : Shift + R-Click for Open Powershell here
Test Android apps on an emulator by downloading from a test app site, choosing latest or previous versions, then install and practice testing on a virtual device.
Demonstrate how ssl pinning prevents interception by validating server certificates against embedded client certificates, explain public key pinning with hashed keys, and outline bypass approaches for modern apps.
Learn to set up SSL pinning bypass on Android by using exposed installer and SSL unpinning tools to intercept traffic with a proxy on a rooted emulator.
Locate websites with active bug bounty programs and responsible disclosure policies to test web and Android applications, and assess program scope and application availability.
Learn by reviewing proof-of-concept reports from successful penetration testers, exploring asset and POC reports to understand bug hunting techniques and android app vulnerabilities.
Practice testing Android apps on vulnerable apps to master testing approaches, identify endpoints you must test, and start a bug bounty career; modules reveal tools and automated testing techniques.
Learn to Hack Android Apps with Practical & Hands-on Lessons on Bug Bounty Hunting in this Masterclass
[ DISCOUNT CODE: "HACKOCT" for flat @ 499/- INR / $6.55 USD ]
OFFER : Get Free Licence to BURPSUITE PROFESSIONAL with this course
This is the most comprehensive Course to begin your Bug Bounty career in Android PenTesting.
Most Penetration testers target Web Applications for finding Bugs but most of them do not test the Android Apps which are a goldmine of vulnerabilities. This course will take you from the basics of Android Architecture to the advanced level of hunting vulnerabilities in the apps. No other course may provide with such a structured lesson and there are numerous Practical lesson with hands on hacking real and Live Android Applications.
Practicals for finding vulnerabilities are important and this course provides a lot of hands-on practical lessons to clear the concept of each vulnerability. You will explore the concepts of the most frequently found Vulnerabilities with addition to other vulnerabilities found in Android Mobile Applications and methods to exploit those vulnerabilities as well as how to suggest a Patch for these Vulnerabilities. You will also learn how to approach the scope of an Android Application to PenTest and find Attack Surfaces and finally Bag yourself a hefty Bounty amount from the Bug Bounty Programs.