
Durcissement des appareils mobiles Android
Android Mobile Device Hardening écrit en python3.
Version Android, PObY-A (Privacy Owned by You - Android), avec analyses des malwares et des paramètres, disponible sur le Play Store et le code source se trouve ICI
AMDH a été créé pour aider à automatiser l'analyse des applications installées sur les appareils Android, détecter certains malwares connus et aussi protéger la vie privée.
$ git clone https://github.com/SecTheTech/AMDH.git; cd AMDH
$ python3 -m venv amdh
$ source amdh/bin/activate
(amdh) $ pip install -r requirement.txt
Note : Sous Windows, vous devez spécifier le chemin d'ADB ou modifier la variable "adb_windows_path" dans "config/main.py".
Attention : lors de l'utilisation de l'argument -l avec l'option d'application activée '-t e', les applications système seront listées. Désinstaller des applications système peut casser votre système Android. L'utilisation de 'disable' plutôt que 'uninstall' est recommandée pour les applications système.
$ python amdh.py -h
usage: amdh.py [-h] [-d DEVICES] [-sS] [-sA] [-H] [-a ADB_PATH] [-t {e,d,3,s}] [-D APKS_DUMP_FOLDER]
[-rar] [-R] [-l] [-P] [-S SNAPSHOT_DIR] [-cS SNAPSHOT_REPORT] [-rS SNAPSHOT_TO_RESTORE] [-o OUTPUT_DIR]
Android Mobile Device Hardening
optional arguments:
-h, --help show this help message and exit
-d DEVICES, --devices DEVICES
list of devices separated by comma or "ALL" for all connected devices
-sS Scan the system settings
-sA Scan the installed applications
-H Harden system settings /!\ Developer Options and ADB will be disabled /!\
-a ADB_PATH, --adb-path ADB_PATH
Path to ADB binary
-t {e,d,3,s} Type of applications:
e: enabled Apps
d: disabled Apps
3: Third party Apps
s: System Apps
-D APKS_DUMP_FOLDER, --dump-apks APKS_DUMP_FOLDER
Dump APKs from device to APKS_DUMP_FOLDER directory
-rar Remove admin receivers: Remove all admin receivers if the app is not a system App
Scan application option "-sA" is required
-R For each app revoke all dangerous permissions
Scan application option "-sA" is required
-l List numbered applications to disable, uninstall or analyze
-P List current users processes
-S SNAPSHOT_DIR, --snapshot SNAPSHOT_DIR
Snapshot the current state of the phone to a json file and backup applications into SNAPSHOT_DIR
-cS SNAPSHOT_REPORT, --cmp-snapshot SNAPSHOT_REPORT
Compare SNAPSHOT_REPORT with the current phone state
-rS SNAPSHOT_TO_RESTORE, --restore-snapshot SNAPSHOT_TO_RESTORE
Restore SNAPSHOT_TO_RESTORE
-o OUTPUT_DIR, --output-dir OUTPUT_DIR
Output directory for reports and logs. Default: out
Compare les autorisations accordées avec les autorisations décrites dans le fichier malware_perms.json. Le fichier contient trois nœuds :
Les autorisations exclusives aux malwares sont celles utilisées uniquement par les malwares. Les malwares analysés proviennent des dépôts :
La commande "aapt" a été utilisée pour extraire les autorisations. La deuxième partie consistait à extraire les autorisations des applications légitimes (environ 400 applications). Les autorisations exclusives aux malwares sont celles utilisées par les malwares et jamais apparues dans les applications légitimes analysées.