Android Security & Malware
43.4K subscribers
128 photos
20 videos
7 files
2.7K links
Mobile cybersecurity channel
Links: https://linktr.ee/mobilehacker
Contact: [email protected]
Download Telegram
This media is not supported in your browser
VIEW IN TELEGRAM
Exploiting embedded mitel phones for unauthenticated remote code execution
Achieving a fully unauthenticated RCE exploit as root in a Mitel IP phone. Several 0-days were discovered which chained together gives the privilege of completely owning the phone
https://baldur.dk/blog/embedded-mitel-exploitation.html
πŸ‘19❀2πŸ‘2
Monitor file system changes using fsmon
β–ͺ️supports Linux, iOS, OS X, Android
β–ͺ️identify when are binaries loaded (root)
β–ͺ️get dropped payloads (root)
β–ͺ️identify when are which files opened at app's runtime (db, txt, log, temp...) (non-root)
https://www.mobile-hacker.com/2024/06/24/monitoring-android-file-system-with-fsmon/
πŸ‘20❀2
Snowblind: A new Android malware abuses security feature to bypass security
Blog: https://promon.co/app-threat-reports/snowblind
Demo: https://youtu.be/zUqZQlQ0ZzQ?si=oZhSdfR1w_SlNjSA
πŸ‘21❀4πŸ€“1
BADUnboxing: Automated Android unpacker
It works by locating and decompiling code inside the APK that is relevant to the unpacking process. Once Bad Unboxing detects packing, it automatically generates a new Java application based on the decompiled code
https://github.com/LaurieWired/BadUnboxing
πŸ”₯21πŸ‘5πŸ‘3πŸ₯±2❀1🀑1
BlueToolkit - automated Bluetooth vulnerability testing framework
βœ…Can test 43 exploits
βœ…Runs on rooted Android, which makes it a portable Bluetooth vulnerability scanner
βœ…It already helped to find 64 new vulnerabilities in 22 products
https://www.mobile-hacker.com/2024/07/02/uncover-bluetooth-vulnerabilities-with-bluetoolkit/
πŸ‘32πŸ‘4
[For beginners] Introduction to Android Pentesting
https://owlhacku.com/introduction-to-android-pentesting/
πŸ†26πŸ‘7πŸ₯±4❀3πŸ₯΄2πŸ€ͺ2πŸ”₯1