Android Pentesting

Resources
Tools
Static Analysis

Pull APK From Google Playstore


Android Mainifest.xml

Decompiled APK
Find Hardcoded Strings


Exported Activity

Enumerating AWS Storage Bucket

Enumerating Firebase Databases

Dynamic Analysis
Disable SSL Pinning
Patching Apk using Objection
Manual Patching

Signing The APK


Insecure Logging
Drozer usage
Port Forward
Connect Drozer
Show App Info
Show Activity Info
Show Content Provider
Check Vulnerable Injection in Content Provider
Show Broadcast Receiver


Run Acitivity Directly
ADB
Insecure Login Mechanism
Tool to extract that backup file
Checking Log
Last updated