Android Pentesting
The Android Package with the file extension apk is the file format used by the Android operating system, and a number of other Android-based operating systems for distribution and installation of mobi
APK Analyzing Flow
1. Extract APK File to DEX File
You can retrieve "classes.dex".
Now you can observe files. For React Native, it may contain the sensitive information in the bundle file.
2. Convert DEX to JAR
You can retrieve JAR file.
3. Observation
JD-GUI is a JAVA decompiler tool. It reveals class in the JAR file. Open JD-GUI.
Static Analysis
An open-source mobile threat intelligence platform.
MobSF (Mobile Security Framework) is an automated all-in-one mobile application pentesting, malware analysis framework capable of static and dynamic analysis.
Dynamic Analysis
If you pentest on virtual devices, you need to install some emulator as below.
Android Backup (.ab)
Extract
SSL Pinning Bypass
No content yet.
Last updated