Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacyΒ© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Android-rce-analizi β€” Android CVE-2024-0044, 43093, 23706 zafiyet analizi ve PoC lab ortamΔ± | Kitploit
Tools/GitHubGitHub/bfurkanyildiz/android-rce-analizi
Android SecurityVulnerability AnalysisExploitationCTFPenetration TestingDevSecOpsLearning & EducationRed TeamingIncident ResponseLog AnalysisLabs & Practice
2143 months agoNot yet reviewed

Most Popular

View all β†’

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools β†’
Share
GitHub
bfurkanyildiz/android-rce-analizi

Android-rce-analizi

Android CVE-2024-0044, 43093, 23706 zafiyet analizi ve PoC lab ortamΔ±

View Repository
Δ°stinye University

CVE Research and PoC Laboratory β€” Android Security Analysis

GitHub Language Status Course CI/CD Test


πŸ‘¨β€πŸ« Advisor Information

Name and SurnameKeyvan Arasteh
GitHub@keyvanarasteh
E-mail[email protected]
LinkedInkeyvanarasteh
Web Siteqline.tech

πŸ‘€ Student Information

Name and SurnameBaha Furkan YΔ±ldΔ±z
Student No2520****1009

πŸ“š Course Information

Course NamePenetration Testing
Course CodeBGT006
Credit3 ECTS
PrerequisitesNetwork Fundamentals, Linux CLI
Semester2025-2026 Spring

πŸš€ Project Summary and Scope

This project was developed as the final assignment for the Penetration Testing (BGT006) course of the Information Security Technology program at Δ°stinye University. Within the scope of the project, 3 different current vulnerabilities affecting the Android ecosystem (CVE-2024-0044, CVE-2024-43093, CVE-2024-23706) were examined in depth, an isolated lab environment was set up, and analyzed using a cyber detective methodology.

🎯 Problem Solved and Project Objective

Traditional Android security analyses usually consist only of theoretical documentation or static images. This project solves the following fundamental problems by combining the attack and defense cycle with working code:

  • Live Analysis of Vulnerabilities: Captures live traces of critical privilege escalation (LPE) vulnerabilities such as CVE-2024-0044 in the Android log layer (logcat).
  • Red Team & Blue Team Correlation: Presents a complete attack-defense PoC (Proof of Concept) by connecting the red team exploitation tool (exploit_sim.py) end-to-end with the blue team log monitoring detector (detector.py).
  • Productized Security Outputs: Converts detected alarms into real-time JSON/CSV reports compliant with SIEM standards and feeds them into a centralized dashboard.

⚑ Single-Command PoC (Attack-Detection Simulation)

Single-command PoC launchers (run_poc.bat / run_poc.sh) have been added so that a user who clones the project can run it and see the output within seconds. These scripts simulate the red team's exploitation steps and cause the blue team detector to generate alarms and write to the reports/detection_results.json file. For detailed execution steps, please refer to the Installation and Execution section.

πŸ“Š Summary Table of Analyzed Vulnerabilities

CVE CodeVulnerability TypeCVSSv3 ScoreAffected ComponentAttack Vector
CVE-2024-0044Run-as UID Bypass (LPE & RCE)8.8 (High)Android System ServerLocal (ADB / Malicious App)
CVE-2024-43093SQLite & DocumentProvider Bypass7.8 (High)Android SQLite LibraryLocal (Media/File Access)
CVE-2024-23706Package Manager Bypass7.8 (High)Android Package ManagerLocal (App Installation)

πŸ”Œ Midterm Module (NetVanguard) Integration

The endpoint log analysis agent src/detector.py developed within the project scope has been integrated into the NetVanguard central anomaly monitoring and alarm panel implemented as the midterm project. Critical vulnerability signatures generated on the emulator are transmitted over the network to the NetVanguard backend engine, simulating a centralized monitoring (SIEM) architecture.

πŸ•΅οΈ Log Analysis Agent (src/detector.py) Working Architecture

The vulnerability detection agent (src/detector.py) is a lightweight endpoint log monitoring engine designed to detect exploitation activities performed on an Android device.

Core Features and Operating Modes:

  1. Flexible Log Input (3 Different Modes):
    • Live ADB Logcat Stream: Connects directly to the emulator with the adb connect command to monitor device logs live.
    • Pipeline / Stdin Mode: Can be piped with other CLI tools via the adb logcat | python src/detector.py architecture.
    • File Tail (Tail -f): Dynamically monitors previously saved log files (.log) line by line.
    • Fallback (Manual Input): If ADB or log file is not installed on the system, filters manually entered log lines for testing purposes (Live simulation module).
  2. Rule-Based Signature Matching:
    • Fed from the DETECTION_KEYWORDS variable in the .env file.
    • Generates [DANGER - ALARM] instantly on the terminal and in logs when it captures critical exploitation signatures such as Android Runtime crashes (SIGSEGV), package installation errors (SIGABRT), and crashing security applications (Process has died).

πŸ› οΈ Technologies Used

TechnologyPurpose of Use
Python 3.xDetection engine, attack simulation
Android SDK / ADBEmulator management, device communication
DockerIsolated lab environment containerization
FlaskWeb monitoring panel
LogcatAndroid system log analysis

πŸ“‚ Project Directory Structure

Download Tool