Android pentesting - Galaxy S III Q&A, Help & Troubleshooting

Hi guys i work in IT security my job is mainly pentesting for those of you who do not no what that is its basically an ethical hacker and i am interested as to weather there are meny apps or framework to do this on android if you no of any please list them below thanks for your help everyone
Sent from my GT-I9300 using xda premium

Are you trying to pentest Android or use Android to pentest your customers?
You can run Backtrack on Android-powered devices but you may encounter problems with e.g. promiscous mode
Pentesting Android itself is a different target alltogether but tools catered for Network Man-in-the-middle, Java attacks or Linux attacks (Android being based on Linux and GNU tools) should help you out

I was thinking more of using Android as a pentesting platform as it would make my job a lot quicker if I could run certain attacks from my phone
Sent from my GT-I9300 using xda premium

Seems legit.
Sent from my GT-I9300 using Tapatalk 2

ole12 said:
Seems legit.
Sent from my GT-I9300 using Tapatalk 2
Click to expand...
Click to collapse
:laugh:

If I was going to lie I wouldn't even bother making up a story I would just say anybody no any pen testing apps but I thought I would explain what I do as some people maybe interested in the field but obviously my 4 year degree in network security and my numorus Microsoft and Cisco qualifications came from the university and college of make belive in fairy land maybe you should not be so quick to accuse people of being a lier
Sent from my GT-I9300 using xda premium

dSploit is a good framework so far...there's also zANTI which isn't free and basically has less options. For ARP-Spoofing there's droidsheep and SSLstrip as a standalone app. if you're rooted you can even change your mac adress via Mac Adress Ghost,
#edit: As d4fseeker said promiscous mode is almost non existant for the most wifi chipsets at this point so you won't get very far in regards to WiFi "pentesting"

Thanks for your help mate I have been testing dsploit which is very interesting and as for Zanti I think it's a bit of a con the way they make you pay for creds and I'm not that interested in arp spoofing or wifi cracking there a bit a mature and you don't get many requests for that sort of thing in my line of work lol
Sent from my GT-I9300 using xda premium

depending on what your line of work is you might want to take a a look at the mobile version of wireshark/ettercap for wireshark the app is simply called shark and to crudly read the pcap files there's shark reader. other than that i would prefer a netbook with the linux distribution of your choice over a smartphone any time, yeah it's nice that you are able to do some network mapping and a few kind of attacks etc. with your android but not much more than that not bad for an initial assessment if you want deeper analysis use your notebook/netbook

post

To be fair I was using the standard android keyboard without auto correct which was my own fault as I tend to type quite fast and not read it back and I'm in my mid 20s lol not 13 but no worry we all make mistakes mate
Sent from my GT-I9300 using xda premium

Well my job is more vulnerability assessment and then showing people how these can be exploited and explaining what damage can be done through this and then suddgesting ways of patching these systems up I was just thinking the way smart phones are getting so powerful it may be possible to have some of these programs on a phone although dsploit does have a vulnerability scanner built in
Sent from my GT-I9300 using xda premium

Android pentesting using Revenssis
terrorbite said:
Hi guys i work in IT security my job is mainly pentesting for those of you who do not no what that is its basically an ethical hacker and i am interested as to weather there are meny apps or framework to do this on android if you no of any please list them below thanks for your help everyone
Sent from my GT-I9300 using xda premium
Click to expand...
Click to collapse
Try Revenssis Penetration testing suite. No regrets whatsoever

Its outdated on my device, ease fix it

Related

Android anti virus?

Just out of interest is there an actual need for such applications as android is linux and I never install apps without reading their reviews first. So is there a point to these apps or are they just wanting you to drain your battery faster?
Sent from my GT-I9100 using XDA App
Sayo1337 said:
Just out of interest is there an actual need for such applications as android is linux and I never install apps without reading their reviews first. So is there a point to these apps or are they just wanting you to drain your battery faster?
Sent from my GT-I9100 using XDA App
Click to expand...
Click to collapse
I've not bothered with any, however recently started running Samsung Mobile Security, doesn't seem to affect battery and silently runs in the background. Available via Samsung Apps.
There is no point to antivirus apps on android, your best bet is to watch out what you install and always check the permissions something asks for, and if it seems to ask for stuff it shouldn't need, eg permissions to send sms's or call numbers on something like a wallpaper app don't install it.
Using popular/well rated apps from known devs/using your common sense is far better than these supposed anti virus apps.
Just what I thought to be honest with you guys. I just wanted to see other peoples opinion on it as I've been reading on some threads people have actually paid for avg pro etc and i just thought what's the point.
Sent from my GT-I9100 using XDA App
I have Kaspersky Internet Security software on my device.
You can get it free if you bank with Barclays UK. ( i don't bank with Barclays. . . lol )
Thank You
It's not worth it just for the antivirus part tbh. Market has inbuilt protection against known threats, which is all most AV software gives.
Maybe some people like the extras, like remote backup, wipe, tracker etc... But most of that is available free.
If you really must use AV, at least use lookout. Others just use the app name to decide if it's malicious (was tested by chainsdd who compiled hello world using a particular package name, then had it setting off avg...)
Do you have the link to chainsdd who compiled this list please
Thank you
Sayo1337 said:
Just out of interest is there an actual need for such applications as android is linux and I never install apps without reading their reviews first. So is there a point to these apps or are they just wanting you to drain your battery faster?
Sent from my GT-I9100 using XDA App
Click to expand...
Click to collapse
Use Lookout or ESET.
There has been an abundance of Malware apps posted on Market and more and more are slipping through and then been pulled later so its best to have something installed just incase.
Common sense is your best protection but its best to have a fall back.
NTOP said:
Do you have the link to chainsdd who compiled this list please
Click to expand...
Click to collapse
pulser_g2 didn't say ChainsDD compiled a list (re-read it), but he is referring to this
http://androidsu.com/2011/06/a-word-about-superuser-and-security/
Anti-virus software does only one thing *well*...And that is make money for the companies who push it.
oinkylicious thank you for the link and it is very useful to know that information
Thank you
Thanks for the great responses. I do have common sense but just don't like the fact that companies charge a considerable amount for it. But I have donated towards the titanium back up pro which is handy and worth it. Also thanks for the suggestions of anti virus apps
Sent from my GT-I9100 using XDA App
i have avast mobile security and its very good on the battery.. havent had any malware issues yet so dont know if it is any good
adit07 said:
i have avast mobile security and its very good on the battery.. havent had any malware issues yet so dont know if it is any good
Click to expand...
Click to collapse
I guess it is doing its job then if there is a threat... Lol
Sent from my GT-I9100 using XDA App

Anybody else hear about Ubuntu for Android?

This is probably old news but I just recently saw this on the Ubuntu website. Looks pretty freaking sweet! Still in development tho.
Sent from my ADR6350 using XDA
There's actually a phone made by Fujitsu that's similar in that it can be booted into the full desktop windows 7 32 bit by the switch of a button. The downside I see to it is that when you are running it the phones radio is turned off so you can't receive calls or texts also the phone UI is some proprietary Fujitsu software. Needless to say it looks pretty lame compared to Android but nevertheless it's still pretty awesome looking. Here's a few links if you guy's wanna check it out.
http://www.youtube.com/watch?v=6XckwJJPTyo&feature=related
http://www.ebay.com/itm/DOCOMO-FUJI...ultDomain_0&hash=item35bc0e465e#ht_3766wt_948
Yes, saw that too! Would be a great experience!
Can you share link to where you read it, I want to check it out..
Sent from my X8 using xda premium
stamatis16 said:
Can you share link to where you read it, I want to check it out..
Sent from my X8 using xda premium
Click to expand...
Click to collapse
Sure!
http://igify.com/?q=ubuntu+android
Sent from my SGH-T989 using xda premium
Would like to point out while Ubuntu are working on it, there are already a range of projects to get it running on your device (see my sig) my project is on of the more active projects, really the only big thing missing that they have working is native graphics (right now my project uses a vnc server within ubuntu to view gui within android).
Mine works on a whole host of devices (not just dual core like ubuntu project) and you can also install debian or backtrack if you wish.
We are in the process of adding more options to the app and making it far more user friendly (Although it is already pretty fool proof)
I love ubuntu on my pc. I would love it on my phone.
Sent from my LG-P350 using XDA
lawalty said:
Sure!
http://igify.com/?q=ubuntu+android
Sent from my SGH-T989 using xda premium
Click to expand...
Click to collapse
Funny..
Sent from my X8 using xda premium
looks sweet,waiting to be deployed
Im excited for the fact you can take you computer with you. simply dock it them WALLA you get a working desktop environment. i have reservations on it using Google docs though, i tried, but never can really use Google docs the way i use my other office programs, just doesn't have the flexibility.
But im excited! I've alread click their link on their page.
Also, with the advent of ICS tgeb JB they need to kick it into gear or how else they going to keep up with the upgrades?
Sent from my SGH-T989 using xda premium
If you can virtualize another distribution within it, you basically have Linux within Linux within Linux.
Linception.
http://www.ubuntu.com/devices
Sent from my DROID2 using XDA
http://www.ubuntu.com/devices/android
Sent from my DROID2 using XDA
Ya, Ubuntu is awesome. It is really good if you want to make a music/movie server for you HTPC
Saw this a few days ago and I'm astonished. Hope someone will get closer look at this. Then I'll change my Vision to something with 2cores immediately
Yeah, but i think it for high-end device..
Sent from my GT-S5570
i been using ubuntu on my laptop.. great OS must say but coming to a phone? wow
ItS been on the android market. As you probably already know have like 6free gigs.
Sent from my LG-P920 using xda premium

Point me in the right direction

i would like to start developing apps for android in the near future but im not sure what software i need and what language i have to learn to get started if anyone can help me with my inquiry it would be awesome im going to be working on Windows 7 any insight and information will be greatly appreciated
thanks
Sent from my GT-P7510 using xda premium
I'm on a phone now but you can get find the "How to build an android app" 4 part series on XDA. Do a search and it should turn up.
Sent from my GT-N7000 using Xparent ICS Tapatalk 2
much appreciated kind sir, i have a really cool idea not totally original but i'll see where it goes
Sent from my GT-P7510 using xda premium
Are you familiar with Java programming? You'll need Java development kit installed on your PC. I'm not sure if Eclipse IDE runs well on a window machine, but if you're familiar with Linux you can run Eclipse IDE on Ubuntu. You also will need Android SDK. This lets you write raw code and helps you get it working in the Android environment. There's more stuff, but that can be found at the thread referenced above or by Google'ing!
Sent from my MB865 using xda's premium carrier pigeon service
I am only familiar with some of the things mentioned from researching but I wasn't sure what was going to lead me to the right avenue, steady now I know what to download and focus more attention on now it's time to stick my head in a book as well as this forum any other information would be awesome thanks
Sent from my SGH-T989 using xda premium
Google, along with XDA will be your best resources. XDA probably more so, because you ask for help and members will do their best to answer you, as opposed to just reading links online that may be written in "Greek" as far as being understandable and easy to digest, with no real availability to get quick, useful, insightful info with.
Sent from my MB865 using xda's premium carrier pigeon service
thanks man your awesome much appreciated!
Sent from my GT-P7510 using xda premium
Also, I was at Barnes & Noble (not sure where you're from) bookstore and there's a section just for Android software development there. Also wouldn't hurt to look into the "Android Cookbook" as a resource literature. If you don't have access to a large bookstore such as B&N, the Android Cookbook website is here:
http://androidcookbook.com/home.seam
Sent from my MB865 using xda's premium carrier pigeon service
Roger that, there is a b&n right next to my school so inbetween classes I'll be there, also is it possible to run Linux on my PC while I still have windows 7?
Sent from my SGH-T989 using xda premium
Dasonec said:
Roger that, there is a b&n right next to my school so inbetween classes I'll be there, also is it possible to run Linux on my PC while I still have windows 7?
Sent from my SGH-T989 using xda premium
Click to expand...
Click to collapse
Absolutely! I'm running Ubuntu 12.04 as well as Win7 on my laptop. Ubuntu is free to download:
http://www.ubuntu.com/download
Also download the Wubi package installer:
http://www.google.com/url?sa=t&sour...p528Bg&usg=AFQjCNFFmxvY4HkumfqYoA0Nv24RfRPrrA
After downloading both, run the Wubi installer and it will load Ubuntu on your PC. You'll get the option upon restart as to which OS to boot -either Ubuntu or Windows.
Sent from my MB865 using xda premium
Oh that is just amazing! Once I get my replacement A/C adapter for my g73 laptop ima get cracking, in your opinion what do you think is easier to work on, custom roms/kernels or apps?
Sent from my SGH-T989 using xda premium
Depends on the experience with the programs needed to do each, I suppose. For starting out you might stick with building .apks or work some theming on an existing rom build, just to get familiar with things.
Sent from my MB865 using xda premium
That sounds like a plan I'm a student at an art institute so this can be alot of fun now I have some resources to help me out
Sent from my SGH-T989 using xda premium
Good deal, good luck, and have fun!
Sent from my MB865 using xda premium

Why you root the phones ?

Hi
I want to know what is your personally reason for root the phone?
I rooted my phone because want to try something new, i like changes, want to know something about rooting, want to install add away and call recorder from skvalex.
What about You ? Which apps do you use for rooted phones?
P.S
This thread can give me ideas or new way to use phone, new apps which i dont know, etc.
I do it because I can. And because I like the freedom root access allows.
Sent from my GT-I9300 using Tapatalk 2
I personally root to customise it.
Get rid of bloatware, get inverted Google apps.
To me stock is how samsung want it and root is how I want it.
Sent from my GT-I9000 using xda app-developers app
hsrars-d said:
I do it because I can. And because I like the freedom root access allows.
Sent from my GT-I9300 using Tapatalk 2
Click to expand...
Click to collapse
But what " freedom root access" mean? What do you have with it and what do you do ? That what i want to know because i want discover more then i know - even if i dont know
I rooted due to customization, few apps like titanium backup pro, cwm, reverse Tethering
I love to be controller of my gadget not some os
Android as-is offers a lot of customization, but rooting it unlocks a whole new level of customization and offers things never possible without root privileges.
How some people can enjoy the locked-down state of iOS is beyond me, or letting themselves be controlled by Apple in the first place.
It offer you more option to do with your phone.
Hope I help u
Sent from my GT-I9300 using xda app-developers app
-Greenify
-Stweaks (mostly modifying charging currents)
Sent from my GT-I9300 using xda premium
Custom ROMS. That's why I rooted and I like the terminal emulator better with SU access.
Nexus 4 CyanogenMod 10.1.0RC2
I rooted to use adaway and get rid of ads among other stuff
HannahNewton said:
im still learning what i can do with it, but so stoked to play with my new and improved phone! thanks Repairem.com
Click to expand...
Click to collapse
Thats why i created this thread. But want to make people more tralkative
htcsnap93 said:
-Greenify
-Stweaks (mostly modifying charging currents)
Sent from my GT-I9300 using xda premium
Click to expand...
Click to collapse
BIG THX for this app.
universal ssalfic
mine? Uh, It's like running a Windows on a PC with Admin right. Can I put it like that?
I want the 100% power of my phone and not either a locked smartphone or with limits....
Sent from my Galaxy Nexus using xda premium
Root comes stock with CM10.1, and one of the key reason for root would be for backup.
You can access all the different root directories to transfer files and sync it automatically in the night when you're sleeping!
Because I get lonely sometimes.
Sent from my GT-I9300 using xda premium
being able to have 100% control of something i paid lots of money for. i also like to be unique and original. Just like my cars..i have to modify and customize them
sent from where i'm at.
I do it for the custom ROMs and freedom to do whatever I please with the phone. I don't think twice before rooting my phones.
Sent from my SCH-I535 using Tapatalk 2
I came into rooting because I bought a Vodafone 360[i8320] which had linux mobile on it and great specs for that day. With that phone you could connect to the Vodafone 360 forum were you can buy apps(limo) for €5 and share your contacts and connect to 360 people.
Within +/- a year the 360 forum was dead. I found the H1 Droid forum were people weer busy porting Android on that phone. It had much benefits: custom roms flashing and making backups, adjusting the phone in every aspect; from keylayout to dpi to overclocking to kernel adjusting. Getting adds out of free apps and getting apps for free.
Nowadays I enjoy a G. Nexus which I immediately rooted after buying it.
Verstuurd van mijn Galaxy Nexus met Tapatalk
cuz my first android phone was a Lg P990, and without root and custom rom it was unusable.
Rooted
to use some of the apps and try diffrent ROM

iMessage on Android Anyone interested?

Hello everyone!!! I have currently been working on iMessage for Android. However the use of a Mac OSX computer is necessary or you can use a virtual machine. I need a android developer for the app, shell scriptors, and Xcode developers.
If you would like to help shoot me a PM and reply to the post.
If you are just interested post in the forum to show your support.
Right now I can currently send iMessage messages via terminal.
Curious....
Sent from my SCH-I545 using xda app-developers app
that would be cool
2nd, that it would be cool.
This would be great!!! especially if there was a way it could be integrated into the stock app kind of like how Cyanogen announced that google voice is being integrated into stock sms.
I'd be interested in this. Wish I could help ya out though! One day....one day...
Have everything required and I'm definitely interested. PM me! Love to help.
Sent from my SCH-I545 using xda app-developers app
very interested in this. I can't provide much more than emotional support but I've been waiting for something like this since imesage was announced. best of luck man!!!
Sent from my SCH-I545 using Tapatalk 4 Beta
This is very interesting indeed
Sent from my SCH-I545 using xda premium
Update:
I am currently able to receive them on the phone via email.
Can u elaborate on that? How exactly are you getting this to work? Is it like an app?
Sent from my SCH-I545 using xda premium
I have a Mac and iMessage on there and would love to help in testing if possible! Definitely interested!
Soldi3rxx said:
Can u elaborate on that? How exactly are you getting this to work? Is it like an app?
Sent from my SCH-I545 using xda premium
Click to expand...
Click to collapse
Sure, What it does is uses the iMessage.app program on a mac to send and recieve messages. the messages are then sent to the android phone and can be replied to in a normal style messaging app. It will also allow you to choose which email address you want to send it with.
So will the use need an iOS device to get this to work? If there any way of just getting the imessanger software on android n send like SMS style etc etc
Sent from my SCH-I545 using xda premium
I don't know if you have spoken to him already or not but I think it's worth sending a message to team cm or Steve kondik to see if there's anything they can do or possibly work this into cm.
Sent from my SCH-I545 using Tapatalk 4 Beta
dstreng said:
I don't know if you have spoken to him already or not but I think it's worth sending a message to team cm or Steve kondik to see if there's anything they can do or possibly work this into cm.
Sent from my SCH-I545 using Tapatalk 4 Beta
Click to expand...
Click to collapse
Its not going to be meant to be put into a preexisting messaging application. There are just too many settings that would have to be implemented. I am going to try and develop and app that will work with it and maybe a plugin that adds support for native messaging.
All you will need is Mac OSX no iPhone.
so the only way this will function is through mac osx? it wouldn't be possible to have a native android app that operates straight through the imesage servers?
Sent from my SCH-I545 using Tapatalk 4 Beta
dstreng said:
so the only way this will function is through mac osx? it wouldn't be possible to have a native android app that operates straight through the imesage servers?
Sent from my SCH-I545 using Tapatalk 4 Beta
Click to expand...
Click to collapse
I think a majority of the people who don't have iMessage don't have an MAC to use. The idea you proposed sound interesting because it gave us hope of by passing any apple product and still being able to talk to apple users!
Soldi3rxx said:
I think a majority of the people who don't have iMessage don't have an MAC to use. The idea you proposed sound interesting because it gave us hope of by passing any apple product and still being able to talk to apple users!
Click to expand...
Click to collapse
I disagree. Both my wife and I are android users and Mac users. We left windows 8 year ago and haven't looked back. The customization of Android is what we love and iOS sucks for full Google services integration (especially since both our jobs are dependent on Google services). However we do have imessage on our Macs, and have friends/family that use iOS. While an app that would work without the use of a Mac would be great, I'm highly interested in using it through my mac, or any other way it would work. I'm currently using VZW messenger app on the ipad so i can answer text messages when using that.

Categories

Resources