
एंड्रॉइड मोबाइल डिवाइस हार्डनिंग
एंड्रॉइड मोबाइल डिवाइस हार्डनिंग, python3 में लिखा गया।
एंड्रॉइड संस्करण, PObY-A (Privacy Owned by You - Android), मैलवेयर और सेटिंग्स स्कैन के साथ, Play Store पर उपलब्ध है और स्रोत कोड यहाँ पाया जा सकता है
AMDH को Android उपकरणों पर स्थापित अनुप्रयोगों की स्कैनिंग को स्वचालित करने, कुछ ज्ञात मैलवेयर का पता लगाने और गोपनीयता की रक्षा करने में मदद के लिए बनाया गया था।
$ git clone https://github.com/SecTheTech/AMDH.git; cd AMDH
$ python3 -m venv amdh
$ source amdh/bin/activate
(amdh) $ pip install -r requirement.txt
नोट: विंडोज के लिए आपको ADB पथ निर्दिष्ट करना होगा या "config/main.py" में चर "adb_windows_path" संपादित करना होगा।
चेतावनी: -l तर्क का उपयोग करते समय सक्षम अनुप्रयोग '-t e' के साथ, सिस्टम ऐप सूचीबद्ध होंगे। सिस्टम ऐप को अनइंस्टॉल करने से आपका Android सिस्टम टूट सकता है। सिस्टम ऐप के लिए 'अनइंस्टॉल' के बजाय 'अक्षम' का उपयोग अनुशंसित है।
$ python amdh.py -h
usage: amdh.py [-h] [-d DEVICES] [-sS] [-sA] [-H] [-a ADB_PATH] [-t {e,d,3,s}] [-D APKS_DUMP_FOLDER]
[-rar] [-R] [-l] [-P] [-S SNAPSHOT_DIR] [-cS SNAPSHOT_REPORT] [-rS SNAPSHOT_TO_RESTORE] [-o OUTPUT_DIR]
Android Mobile Device Hardening
optional arguments:
-h, --help show this help message and exit
-d DEVICES, --devices DEVICES
list of devices separated by comma or "ALL" for all connected devices
-sS Scan the system settings
-sA Scan the installed applications
-H Harden system settings /!\ Developer Options and ADB will be disabled /!\
-a ADB_PATH, --adb-path ADB_PATH
Path to ADB binary
-t {e,d,3,s} Type of applications:
e: enabled Apps
d: disabled Apps
3: Third party Apps
s: System Apps
-D APKS_DUMP_FOLDER, --dump-apks APKS_DUMP_FOLDER
Dump APKs from device to APKS_DUMP_FOLDER directory
-rar Remove admin receivers: Remove all admin receivers if the app is not a system App
Scan application option "-sA" is required
-R For each app revoke all dangerous permissions
Scan application option "-sA" is required
-l List numbered applications to disable, uninstall or analyze
-P List current users processes
-S SNAPSHOT_DIR, --snapshot SNAPSHOT_DIR
Snapshot the current state of the phone to a json file and backup applications into SNAPSHOT_DIR
-cS SNAPSHOT_REPORT, --cmp-snapshot SNAPSHOT_REPORT
Compare SNAPSHOT_REPORT with the current phone state
-rS SNAPSHOT_TO_RESTORE, --restore-snapshot SNAPSHOT_TO_RESTORE
Restore SNAPSHOT_TO_RESTORE
-o OUTPUT_DIR, --output-dir OUTPUT_DIR
Output directory for reports and logs. Default: out
दी गई अनुमतियों की तुलना फ़ाइल malware_perms.json में वर्णित अनुमतियों से करें। फ़ाइल में तीन नोड हैं:
केवल मैलवेयर अनुमतियाँ वे हैं जो केवल मैलवेयर द्वारा उपयोग की जाती हैं। विश्लेषित मैलवेयर निम्नलिखित रिपॉजिटरी से हैं:
कमांड "aapt" का उपयोग अनुमतियाँ डंप करने के लिए किया गया था। दूसरा भाग वैध ऐप्स (लगभग 400 ऐप) की अनुमतियाँ डंप करना था। केवल मैलवेयर अनुमतियाँ वे अनुमतियाँ हैं जो मैलवेयर द्वारा उपयोग की जाती हैं और विश्लेषित वैध अनुप्रयोगों में कभी प्रकट नहीं होती हैं।
सभी अनुमतियाँ मैलवेयर और वैध अनुप्रयोगों दोनों द्वारा उपयोग की जाती हैं। मान प्रतिशत हैं कि वैध ऐप्स की तुलना में मैलवेयर ने इन अनुमतियों का कितना उपयोग किया।
स्नैपशॉट सिस्टम स्थिति की निगरानी और फोन डेटा का बैकअप लेने में मदद कर सकता है: