Android Application Pentesting - Mystikcon 2020

Поділитися
Вставка
  • Опубліковано 23 січ 2025

КОМЕНТАРІ • 74

  • @WiseFoxSecurity
    @WiseFoxSecurity  4 роки тому +62

    Please let me know if you are interested in Android App Pentesting series in the comment section below. Please like the video and subscribe to my channel if you are interested in Android App Pentesting series. Please share this video with others if you found this talk useful. Thanks

    • @prathmeshgidde5095
      @prathmeshgidde5095 3 роки тому +1

      Why your not uploading videos

    • @alexosunga5527
      @alexosunga5527 3 роки тому +1

      I'm a junior pentester and I'm interested in the android app pentest.

    • @itsme7570
      @itsme7570 2 роки тому +1

      Keep them coming brother!!!

    • @itsme7570
      @itsme7570 2 роки тому

      Links provided to GitHub repos where they at?

    • @0x_hacks
      @0x_hacks 11 місяців тому

      Yes please make more details video related to andriod apps vulnerabilities and submitted these reports

  • @domaincontroller
    @domaincontroller 2 роки тому +33

    04:00 APK 05:38 manifest 06:37 classes.dex 07:12 res 07:43 META-INF 09:19 demo, unzip 10:55 apk decompilation, jadx, static analysis, mobsf 14:05 apktool 17:22 MOBSF, docker container, drag n drop, false positive 21:20 hardcoded credentials 23:26 classes.dex, jd-gui, jar file 26:12 Activities 28:17 implicit intent 30:05 broadcast receivers 31:35 services 32:10 content provider 33:41 dynamic analysis 34:56 frida, drozer, RMS, objection 35:55 frida, ssl pinning, aws keys on the fly, genymotion 38:38 frida set up 40:00 dynamic analysis 43:10 all running processes, packages

  • @scarytruths01
    @scarytruths01 Рік тому

    This is excellent... im in the middle of a bug bounty that requires some android pentesting knowledge. The video really helped.

  • @pratapkhandulwan9319
    @pratapkhandulwan9319 3 роки тому +5

    Such a great quality of content provided in this session. Thank you for uploading it, and hoping for upcoming videos on mobile penetraion testing with more deeper approaches and concepts.👍

  • @zmoraubecka9906
    @zmoraubecka9906 3 роки тому +2

    Amazing video! I have been performing web/infra pentesting for a while and just started my journey with the mobile testing. This video sorted out the methodology I should start with in a great way. Thanks bro and keep creating such videos!

  • @tksec-1
    @tksec-1 3 роки тому +4

    Thanks a lot for this amazing talk! You’re great at breaking down key concepts in a beginner friendly way.

  • @petitloukoum0
    @petitloukoum0 Рік тому

    this is really the video I was looking for, thank you very much.
    I saw that you were not very active anymore but thanks for teaching me all this.

  • @anthonytuff8783
    @anthonytuff8783 3 роки тому +1

    The video was of good quality..I'm testing an android app, at least now I know where to get started. Upload more videos for Static analysis. This one was helpful

  • @zeorjvistr6245
    @zeorjvistr6245 2 роки тому +2

    best video for me, When can we expect the series for it + You are a great teacher 👍

  • @foxgameplay5449
    @foxgameplay5449 3 роки тому

    in some apps ssl bypassed failed to get request so what we can do more ?

  • @thecapletsecurity7316
    @thecapletsecurity7316 2 роки тому

    Can you please tell me how can i download any application apk if want to perform the pentesting on that apk.

  • @krishnasoni4427
    @krishnasoni4427 3 роки тому +5

    Sir it's really helpful plzz posts more video's ❤️ .i am from India

  • @Marco1_1
    @Marco1_1 Рік тому

    i don't now how to say thank you man pls we need more videos in Statics Analysis

  • @AshleyEhSMR
    @AshleyEhSMR Рік тому +1

    I had adb on my android device, and it went completely over my head to use it on the linux. I was trying to tunnel my tcp traffic, which is a not nearly as fluid as that. 😅 I feel so silly - thank you for the reminder & useful information 🙌✨

    • @WiseFoxSecurity
      @WiseFoxSecurity  Рік тому +1

      Haha yes the ADB way is easier. I have tried TCP tunneling in the past but never got used to it for some reasons haha

    • @AshleyEhSMR
      @AshleyEhSMR Рік тому

      @@WiseFoxSecurity ADB doesn’t require you to make so many configurations and changes to your network to get the outcome of which you’re looking compared to TCP tunneling. I’m sure there’s benefits to it that I’m too ignorant to understand, at this point, that I’m missing out on, but ADB is a brilliant option.
      Not sure if you’ve used it, and would be curious on your opinion of NordVPN Meshnet?

  • @testtesting1030
    @testtesting1030 2 роки тому

    Where are the APK you mentioned to download for practice?

  • @funkymonk2254
    @funkymonk2254 3 роки тому

    Thank You so much!! I appreciate such an easy to understand and informative introduction to app pentesting.

  • @zafirjeeawody8628
    @zafirjeeawody8628 3 роки тому

    what check should we implement to prevent the password hack ?

  • @wardellcastles
    @wardellcastles Рік тому

    MOBSF Rules! Love that now there's a Docker image.

    • @Reacher6207
      @Reacher6207 Рік тому

      It's ok but it produces lots of False positives.

  • @tazimulsohag2200
    @tazimulsohag2200 3 роки тому +1

    yes we are highly interested to learn new things from you

  • @paularvie9473
    @paularvie9473 2 роки тому +1

    does this work on app built with reactNative?

  • @Exendes
    @Exendes 2 роки тому

    Possible to change the code and recompile the apk? I want to bypass an sms verification

  • @dayumnson9769
    @dayumnson9769 4 роки тому +4

    wow this was a great talk, thanks a lot!

    • @WiseFoxSecurity
      @WiseFoxSecurity  4 роки тому +1

      Thanks a lot for the feedback. Glad you found the video useful ☺️

  • @viveknair4709
    @viveknair4709 3 роки тому

    Is there videos based on android application's vulnerabitily analysis using common tools..

  • @jiayaoou8254
    @jiayaoou8254 3 роки тому

    how to use bria from burpsuite

  • @learningtime9861
    @learningtime9861 5 місяців тому

    Thanks buddy for setting up so nicely.

  • @hggghg98
    @hggghg98 2 роки тому

    The best video in my week
    Thanks alot 😘

  • @viveknair4709
    @viveknair4709 3 роки тому

    Sir, do you have any lectures privilege escalation vulnerabilities or can you please
    mention any relevant sources for those that can research into

  • @moss460
    @moss460 3 роки тому

    can you pls tell me where I can find all links of your "some useful links" slide?

  • @Hybrid_Netowrks
    @Hybrid_Netowrks 2 роки тому

    Awesome and Thank you so much from Pakistan. Amazing quality content

  • @hackingtips1072
    @hackingtips1072 3 роки тому

    what is the IOS simulator for windows? like genymotion

    • @MoreYaseen
      @MoreYaseen 2 роки тому

      not possible... only for mac

  • @python1tz229
    @python1tz229 3 роки тому

    thank you so much, this video has opened my way to android pentesting

    • @WiseFoxSecurity
      @WiseFoxSecurity  3 роки тому +1

      Wow this comment made my day. I am so glad that you found this video useful. I'll upload more videos soon. Happy holidays everyone!!

    • @python1tz229
      @python1tz229 3 роки тому +1

      @@WiseFoxSecurity Real useful, android pentesting was always mysterious to me, after this, then my plan for 2022 is to go for android pen testing, I have already subscribed to your channel and whoever asks me about android hacking I will recommend your channel, keep up great video. thank you for your free knowledge, waiting for more

  • @nikoshalk
    @nikoshalk 3 роки тому +1

    very nice introductory video!

  • @ratnalaabhinav6182
    @ratnalaabhinav6182 2 роки тому

    plz make a video on mob sf installation on kali Linux and windows

  • @wolfrevokcats7890
    @wolfrevokcats7890 2 роки тому

    54:58 Approach
    Install app in emulator such as
    Static analysis, hardcoded key/secrets using tools such as mobsf
    Dynamic analysis,
    Use Frida

  • @yoshi5113
    @yoshi5113 3 роки тому

    can you share all links in the useful link section?

  • @akhlaquecybersecurity
    @akhlaquecybersecurity 2 роки тому

    Awesome road maps for implementation

  • @hashmattabibi6370
    @hashmattabibi6370 3 роки тому +1

    Wow, Thanks a lot.

  • @mayankgiri7853
    @mayankgiri7853 3 роки тому

    Sir please make full video in PIVAA practical..

  • @Lfomod1Dubstep
    @Lfomod1Dubstep 3 роки тому

    Very well done! Thank you for sharing :)

  • @hectorm9764
    @hectorm9764 3 роки тому

    Buenas, alguien me puede recomendar por favor un buen curso o certificación de mobile hacking para aplicaciones ios y android?, gracias!!!

  • @RealOrji
    @RealOrji 5 місяців тому

    Interested.

  • @emmanuelsadiq2165
    @emmanuelsadiq2165 3 роки тому +1

    Thanks for this tutorial

  • @AkashJhaDDN
    @AkashJhaDDN 3 роки тому +1

    Thankyou sir

  • @silverman2263
    @silverman2263 3 роки тому

    Super video sir

  • @Basudarammm
    @Basudarammm 2 роки тому

    Nice job

  • @silverman2263
    @silverman2263 3 роки тому

    Plz make more videos for android app model

  • @abbasa68a39
    @abbasa68a39 Рік тому

    hi thanks for your best tutorial just teach more on real application like application that have dexguard and we can't read they code

  • @kumarniloy1798
    @kumarniloy1798 3 роки тому

    Best books for android penetration without android hackers handbook and mobile application hacker's handbook both are outdated

  • @BugHunter-im3iu
    @BugHunter-im3iu 11 місяців тому

    Make so many videos for this 👩‍💻

  • @akhlaquecybersecurity
    @akhlaquecybersecurity 2 роки тому

    Please go ahead

  • @raghul1208
    @raghul1208 3 роки тому

    nice!!

  • @lookback6314
    @lookback6314 2 роки тому

    thanks!

  • @achrafelhardi8055
    @achrafelhardi8055 3 роки тому

    Somone hack cambly for me? ❤️❤️

  • @ca7986
    @ca7986 3 роки тому

    👌