
Non-decompiling iOS/Android app vulnerability scanner (DC25 demo lab, CB17)
trueseeing is a fast, accurate and resillient vulnerability scanner for iOS/Android apps. We operate on the Dalvik VM level for Android -- i.e. we don't care if the target app is obfuscated or not.
Currently we can:
NOTE:
We provide containers so you can use right away as follows; now this is also the recommended way, and the only way if you are on Windows, to run:
$ docker run --rm -v $(pwd):/out -v ts2:/cache ghcr.io/alterakey/trueseeing
If you want to run statelessly you omit mounting volume onto /cache (not recommended for day-to-day use though; also see #254):
$ docker run --rm -v $(pwd):/out ghcr.io/alterakey/trueseeing
Alternatively, you can install our package with uv as follows. Especially the uv tool install form of installation might be useful for extensions (see below), as it grants them the greatest freedom. Just remember you need a JRE and Android SDK (optionally; to mess with devices):
$ uvx trueseeing
$ uv tool install trueseeing
$ trueseeing
Of course you can always use the good old pip if you must:
$ pip install trueseeing
You can interactively scan/analyze/patch/etc. apps -- making it the ideal choice for manual analysis:
$ trueseeing target.apk
[+] trueseeing x.y.z
ts[target.apk]> ?
...
ts[target.apk]> i # show generic information
...
ts[target.apk]> pf AndroidManifest.xml # show manifest file
...
ts[target.apk]> a # analyze resources too
...
ts[target.apk]> /s something # search text
...
ts[target.apk]> as # scan
...
[+] done, found 6403 issues (174.94 sec.)
ts[target.apk]> gh report.html
We accept an inline command (-c) or script file (-i) to run before giving you prompt, as well as quitting right away instead of prompting (-q; we don't require a tty in this mode!).
You can use the features to conduct a batch scan, as follows e.g. to dump findings right onto the stderr:
$ trueseeing -eqc 'as' target.apk
To generate a report file in HTML format:
$ trueseeing -eqc 'as;gh report.html' target.apk
To generate a report file in JSON format:
$ trueseeing -eqc 'as;gj report.json' target.apk
To get report generated in stdout, omit filename from final g* command:
$ trueseeing -eqc 'as;gh' target.apk > report.html
$ trueseeing -eqc 'as;gj' target.apk > report.json
Traditionally, you can scan apps with the following command line to get findings listed in stderr:
$ trueseeing --scan target.apk
To generate a report in HTML format:
$ trueseeing --scan --scan-output report.html target.apk
$ trueseeing --scan --scan-report=html --scan-output report.html target.apk
To generate a report in JSON format:
$ trueseeing --scan --scan-report=json --scan-output report.json target.apk
To get report generated in stdout, specify '-' as filename:
$ trueseeing --scan --scan-output - target.apk > report.html
$ trueseeing --scan --scan-report=html --scan-output - target.apk > report.html
$ trueseeing --scan --scan-report=json --scan-output - target.apk > report.json
You can write your own commands and signatures as extensions. Extensions are placed under /ext (containers) or ~/.trueseeing2/extensions/ (uv/pip) . Alternatively you can distribute your extensions as wheels. We provide type information so you can not only type-check your extensions with zuban but also get a decent assist from IDEs. See the details section for details.
You can build it as follows:
$ docker build -t trueseeing https://github.com/alterakey/trueseeing.git#main
To build wheels you can do with flit, as follows:
$ flit build
To hack it, you need to create a proper build environment. With uv you could just do:
$ git clone https://github.com/alterakey/trueseeing.git wc
$ uv sync --locked --dev
$ (... hack ...)
$ uv run trueseeing ... # to run
$ uv run zuban check trueseeing && uv run ruff trueseeing # to validate
Success: no issues found in XX source files
$ uv run flit build # to build (wheel)
$ docker build -t trueseeing . # to build (container)
With pip, to create one, firstly set up a venv, install flit and validating toolchains (zuban and ruff) in there, and have flit pull dependencies. In short, do something like this:
$ git clone https://github.com/alterakey/trueseeing.git wc
$ python3 -m venv wc/.venv
$ source wc/.venv/bin/activate
(.venv) $ pip install flit zuban ruff
(.venv) $ flit install --deps=develop -s
(.venv) $ (... hack ...)
(.venv) $ trueseeing ... # to run
(.venv) $ zuban check trueseeing && ruff check trueseeing # to validate
Success: no issues found in XX source files
(.venv) $ flit build # to build (wheel)
(.venv) $ docker build -t trueseeing . # to build (container)
Currently we can detect the following class of vulnerabilities, largely ones covered in OWASP Mobile Top 10 - 2016:
Improper Platform Usage (M1)
Insecure Data (M2)
Insecure Commnications (M3)
Insufficient Cryptography (M5)
Client Code Quality Issues (M7)
Code Tampering (M8)
Reverse Engineering (M9)