
एक उपकरण जो एंड्रॉइड ऐप्स के पेंटेस्टिंग के सामान्य कार्यों को स्वचालित करता है। यह APKTool और Dex2Jar का उपयोग करता है।
v2.0.0
एक उपकरण जो Android ऐप्स के पेंटेस्टिंग के सामान्य कार्यों को स्वचालित करता है।
यह उपकरण वर्तमान में निम्नलिखित सुविधाएँ प्रदान करता है:
/data/app//data/dataआप अपने स्वयं के कस्टम कार्यप्रवाह को स्वचालित करने के लिए संचालन मोड को श्रृंखलाबद्ध कर सकते हैं।
उदाहरण:
humoud@komputer:~/Documents/dev/apkSneeze# python3 apkSneeze.py -adb_over_wifi -device_ip 192.168.1.114 -apk_dl -pkg_name com.dev.test.example -apk
===========================================================
___ ______ _ __ _____ _ _ _____ _____ ______ _____
/ _ \ | ___ \ | / / / ___| \ | || ___| ___|___ /| ___|
/ /_\ \| |_/ / |/ / \ `--.| \| || |__ | |__ / / | |__
| _ || __/| \ `--. \ . ` || __|| __| / / | __|
| | | || | | |\ \ /\__/ / |\ || |___| |___./ /___| |___
\_| |_/\_| \_| \_/ \____/\_| \_/\____/\____/\_____/\____/
v2.0.0
============================================================
Using Settings:
+> Process apk file: True
> Target apk file name: sneezed.apk
+> Setup ADB over WiFi: True
+> Download apk file: True
+> Download app data directory: False
>> Settings shared for adb setup and apk\data download:
>> ADBKey file location: /home/humoud/.android/adbkey
>> Test device IP address: 192.168.1.114
>> Test device port: 5555
>> Target package name: com.dev.test.example
Confirm? [y/n] y
Killing adb server
Listing attached devices
* daemon not running; starting now at tcp:5037
* daemon started successfully
> List of devices attached
> xxxxx device
Setting the device to listen on port 5555
> restarting in TCP mode port: 5555
Connecting to the device...
> connected to 192.168.1.114:5555
You can test if everything is working by seeing if you can get a shell: adb -s 192.168.1.114:5555 shell
<*> Copying APK file to /data/local/tmp/apkSneeze/base.apk (mobile device)...
<*> Downloading APK file to sneezed.apk...
<*> Download done, check sneezed.apk
<*> Deleting APK file from /data/local/tmp/apkSneeze/base.apk (mobile device)...
[0] Processing apk file...
[1] Decompiling the APK file using APKTOOL...
> I: Using Apktool 2.4.0-dirty on sneezed.apk
> I: Loading resource table...
> I: Decoding AndroidManifest.xml with resources...
> I: Loading resource table from file: /home/humoud/.local/share/apktool/framework/1.apk
> I: Regular manifest package...
> I: Decoding file-resources...
> I: Decoding values */* XMLs...
> I: Baksmaling classes.dex...
> I: Baksmaling classes2.dex...
> I: Baksmaling classes3.dex...
> I: Copying assets and libs...
> I: Copying unknown files...
> I: Copying original files...
[2] Converting APK file to JAR file using dex2jar...
dex2jar sneezed.apk -> ./sneezed-dex2jar.jar
[3] Searching for interesting strings(outputing to file interesting_strings_sneezed.txt)...
[3] >> Going through RegEx list...
[3] >> Going through strings list...
Hits: 20853
Done!
आवश्यकताएँ:
python3 -m pip install -r requirements.txt
नोट: यह उपकरण Kali Linux पर परीक्षित और विकसित किया गया है, इसमें apktool और dex2jar स्थापित हैं।
apk फ़ाइल को प्रोसेस करने के लिए (डीकंपाइल करें, Jar में बदलें, और दिलचस्प स्ट्रिंग्स के लिए स्कैन करें):
python3 apkSneeze.py -apk -apk_name test.apk
WiFi पर ADB सेट करने के लिए, उपकरण USB के माध्यम से जुड़ा होना चाहिए:
python3 apkSneeze.py -adb_over_wifi -device_ip 192.168.1.114
कस्टम पोर्ट सेट करें:
python3 apkSneeze.py -adb_over_wifi -device_ip 192.168.1.114 -device_port 10111
परीक्षण उपकरण से apk फ़ाइल डाउनलोड करने के लिए (रूट एक्सेस आवश्यक):
python3 apkSneeze.py -apk_dl -pkg_name com.dev.test -device_ip 192.168.1.114
यदि आप 5555 के अलावा कोई अन्य पोर्ट (कस्टम पोर्ट) उपयोग कर रहे हैं:
python3 apkSneeze.py -apk_dl -pkg_name com.dev.test -device_ip 192.168.1.114 -device_port 10111
परीक्षण उपकरण से ऐप का डेटा निर्देशिका (/data/data) डाउनलोड करने के लिए (रूट एक्सेस आवश्यक):
python3 apkSneeze.py -data_dir_dl -device_ip 192.168.1.114 -pkg_name com.test.target.app
आप संचालन मोड को श्रृंखलाबद्ध कर सकते हैं। उदा: wifi पर adb सेट करें, फिर एक apk फ़ाइल डाउनलोड करें, और अंत में डाउनलोड की गई apk फ़ाइल को प्रोसेस करें।
python3 apkSneeze.py -adb_over_wifi -device_ip 192.168.1.114 -apk_dl -pkg_name com.dev.test.example -apk
उपकरण निम्नलिखित पर डिफ़ॉल्ट होता है:
उपयुक्त पैरामीटर निर्दिष्ट करके इन सभी को बदला जा सकता है।
usage: apkSneeze.py [-h] [-apk] [-apk_name APK_NAME] [-apk_dl] [-data_dir_dl]
[-pkg_name PKG_NAME] [-device_ip DEVICE_IP]
[-device_port DEVICE_PORT] [-adbkey_file ADBKEY_FILE]
[-adb_over_wifi]
optional arguments:
-h, --help show this help message and exit
-apk Process an apk file.
-apk_name APK_NAME Name of the apk file to process.
-apk_dl Download apk file from device. Requires params:
pkg_name, device_ip, device_port, adbkey_file.
-data_dir_dl Download app data directory from device. Requires
params: pkg_name, device_ip, device_port, adbkey_file.
-pkg_name PKG_NAME Application Package Name (ex: com.dev.app). This is
required if you wish to download the apk file.
-device_ip DEVICE_IP IP Address of the testing device.
-device_port DEVICE_PORT
Port number the testing device is listening on.
-adbkey_file ADBKEY_FILE
Location of the adbkey file (ex:
/home/user/.android/adbkey).
-adb_over_wifi Setup adb over wifi automatically. You must provide
the IP address of the device and have it connected via
USB. You can set a custom port using param
device_port.
बिना पूर्व आपसी सहमति के लक्ष्यों पर हमला करने के लिए APKSneeze का उपयोग अवैध है। सभी लागू स्थानीय, राज्य और संघीय कानूनों का पालन करना अंतिम उपयोगकर्ता की जिम्मेदारी है। डेवलपर्स कोई दायित्व नहीं लेते हैं और इस प्रोग्राम के कारण होने वाले किसी भी दुरुपयोग या क्षति के लिए जिम्मेदार नहीं हैं।