写在前面的话:推荐一些初学者使用的android渗透测试工具,android渗透测试工具集中了很多的方法,使使用的便携性,效率都大大提高,对于希望涉足这个领域的朋友,可以通过使用和了解这些工具建立初步的认知。
0x00 逆向工程和静态分析类
Oat2dex:主要用途就是将.oat文件转成.dex文件
如何反编译Android 5.0 framework-CSDN.NET
![图片[1]-Android Penetration Testing Tools Overview for Beginners](https://www.77169.net/wp-content/uploads/2016/09/58de41f671ad0b36c8d541c058e853fd_b.png)
使用android-apktool来逆向(反编译)APK包方法介绍_Android_脚本之家
![图片[2]-Android Penetration Testing Tools Overview for Beginners](https://www.77169.net/wp-content/uploads/2016/09/57ba34309a3849f157cd9caa481dbca2_b.png)
http://www.oschina.net/p/qarkhttp://www.oschina.net/p/qark
![图片[3]-Android Penetration Testing Tools Overview for Beginners](https://www.77169.net/wp-content/uploads/2016/09/4d1c8166dc4169be0449c27aabbcb26b_b.png)
![图片[4]-Android Penetration Testing Tools Overview for Beginners](https://www.77169.net/wp-content/uploads/2016/09/8a75fd17613b7bc095d52945111cce89_b.png)
GitHub – AndroBugs/AndroBugs_Framework: AndroBugs Framework is an efficient Android vulnerability scanner that helps developers or hackers find potential security vulnerabilities in Android applications. No need to install on Windows.
![图片[5]-Android Penetration Testing Tools Overview for Beginners](https://www.77169.net/wp-content/uploads/2016/09/d07f7db5dd4aff7cbfdb8c8c43bbb267_b.png)
Xposed Framework:可以在未刷机或者是更改任何android应用程序包的情况下更改系统配置。
Xposed Framework Modules
![图片[6]-Android Penetration Testing Tools Overview for Beginners](https://www.77169.net/wp-content/uploads/2016/09/359effab84d0fa5b4644f14bbd18499d_b.png)
安卓Hacking Part 11:使用Introspy进行黑盒测试
![图片[7]-Android Penetration Testing Tools Overview for Beginners](https://www.77169.net/wp-content/uploads/2016/09/64ca6b8b18956b6b9d0548c093710730_b.png)
Drozer – Android APP安全评估工具(附测试案例)
![图片[8]-Android Penetration Testing Tools Overview for Beginners](https://www.77169.net/wp-content/uploads/2016/09/96f6941848352dd44cb758dac2c299d8_b.png)
Mallory:可以监听和修改应用设备的网络流量,实施中间人攻击。
TCPdump:网络抓包的命令行工具。
![图片[9]-Android Penetration Testing Tools Overview for Beginners](https://www.77169.net/wp-content/uploads/2016/09/54bd9913509fd5be9207b27313c136de_b.png)
![图片[10]-Android Penetration Testing Tools Overview for Beginners](https://www.77169.net/wp-content/uploads/2016/09/4853a00eb8d92ef7aa61e6fb247a7558_b.png)
0x03 安全库类
proguard;免费的Java类文件压缩、优化、混淆以及校验工具。
![图片[11]-Android Penetration Testing Tools Overview for Beginners](https://www.77169.net/wp-content/uploads/2016/09/5ae532aecb5901ceaebfc392f814e409_b.png)
![图片[12]-Android Penetration Testing Tools Overview for Beginners](https://www.77169.net/wp-content/uploads/2016/09/28a12d0cde85de32df6a3833f0cfff24_b.png)
![图片[13]-Android Penetration Testing Tools Overview for Beginners](https://www.77169.net/wp-content/uploads/2016/09/db1ef5c6daaff9728868f7d4c0bb8c00_b.png)
GitHub – scottyab/secure-preferences: Android Shared preference wrapper than encrypts the values of Shared Preferences. It’s not bullet proof security but rather a quick win for incrementally making your android app more secure.
![图片[14]-Android Penetration Testing Tools Overview for Beginners](https://www.77169.net/wp-content/uploads/2016/09/6a2965d279aa152fb4a2b778c39c65c8_b.png)
Santoku:一款操作系统,可以脱离虚拟机作为单独的操作系统进行运行,进行逆向工程和静态分析。
![图片[15]-Android Penetration Testing Tools Overview for Beginners](https://www.77169.net/wp-content/uploads/2016/09/3e8c212cd934bce11fb80bc96ea23434_b.png)
![图片[16]-Android Penetration Testing Tools Overview for Beginners](https://www.77169.net/wp-content/uploads/2016/09/34323ae0543f9108aee4191544fa8bf1_b.png)
GitHub – sh4hin/Androl4b: A Virtual Machine For Assessing Android applications, Reverse Engineering and Malware Analysis
![图片[17]-Android Penetration Testing Tools Overview for Beginners](https://www.77169.net/wp-content/uploads/2016/09/205de73a7ddfaff494baeb0b305ee803_b.png)
Appie – Android Pentesting Portable Integrated Environment
![图片[18]-Android Penetration Testing Tools Overview for Beginners](https://www.77169.net/wp-content/uploads/2016/09/dd49808904b7a4ac1df3fc0f1ce79db9_b.png)
Rootcoak Plus:可以绕过已知常见的root识别机制。
GitHub – devadvance/rootcloakplus
![图片[19]-Android Penetration Testing Tools Overview for Beginners](https://www.77169.net/wp-content/uploads/2016/09/85765af2cbac6090e5d3c51be70dba41_b.png)
android-SSL-TruskKiller:能绕过大部分应用程序的SSL证书绑定的黑盒测试工具。
GitHub – iSECPartners/Android-SSL-TrustKiller: Bypass SSL certificate pinning for most applications
![图片[20]-Android Penetration Testing Tools Overview for Beginners](https://www.77169.net/wp-content/uploads/2016/09/c9d158c86b940935bf30120d8fe92f41_b.png)
![图片[21]-Android Penetration Testing Tools Overview for Beginners](https://www.77169.net/wp-content/uploads/2016/09/df9a9393f7ab4deb418726efd8168a10_b.png)
Network Spoofer:更侧重渗透而不是破解
![图片[22]-Android Penetration Testing Tools Overview for Beginners](https://www.77169.net/wp-content/uploads/2016/09/926ea6f777176e08647be299b8e27554_b.png)
端口扫描
漏洞发现
对路由器扫描
伪造数据包
会话控制(需要MSF RPC 连接)
中间人攻击
密码破解
有能力可以攻占路由器
bettercap – A complete, modular, portable and easily extensible MITM framework.
![图片[23]-Android Penetration Testing Tools Overview for Beginners](https://www.77169.net/wp-content/uploads/2016/09/399a98530b7d8007cb210069744251ff_b.png)
网络诊断,复杂的审计和渗透测试
中间人攻击和包探嗅
非常有好的界面
namap端口扫描,探测出操作系统
密码分析
zANTI – Mobile Security Risk Assessment
![图片[24]-Android Penetration Testing Tools Overview for Beginners](https://www.77169.net/wp-content/uploads/2016/09/0b40c3779046602d35e1f9b7b5336b98_b.png)











暂无评论内容