
モバイルアプリケーションテストツールキット
Scrounger - 他人から借りたり、他人に頼って生きる人。
このツールにこれ以上ふさわしい説明はありません。その理由は主に2つあります。第一に、このツールは既に公開されている多くの他のツールからインスピレーションを得ているからです。第二に、モバイルアプリケーションの脆弱性に寄生しているからです。
他のモバイルアプリケーション分析ツールがいくつか開発されていますが、AndroidとiOSの両方で使用でき、すべてのモバイルアプリケーション評価で「標準」として使用すべきと言えるツールは1つもありません。
Scroungerの背後にあるアイデアは、ペネトレーションテスターの作業を代わりに行うのではなく、すべての評価で実行する必要のある日常的なタスクを実行することでテスターの評価を支援する、Metasploitのようなツールを作ることです。
Scroungerが提供する他のツールにはない主な機能:
Scroungerは他のツールからインスピレーションを受けています。以下の開発者に多大な感謝を捧げます:
免責事項として、Scroungerによって特定されたすべての発見事項は、常に手動で再確認する必要があります。
AndroidまたはiOSデバイスを必要とするモジュールを使用する場合、ScroungerはそれぞれRoot化またはJailbreakされたデバイスが必要です。
ScroungerはiOS 11とAndroid 8.1で動作することが確認されています。
Scroungerはpython 2.7専用に構築されています。
git clone https://github.com/nettitude/scrounger.git cd scrounger bash setup.sh pip install -r requirements.txt python setup.py install
## 開発```
git pull https://github.com/nettitude/scrounger.git
cd scrounger
bash setup.sh
pip install -r requirements.txt
python setup.py develop
cd scrounger git pull python setup.py install --upgrade
## 必要なバイナリ
### Androidモジュール用
* java (<http://www.oracle.com/technetwork/java/javase/downloads/index.html>)
* jd-cli (<https://github.com/kwart/jd-cmd>)
* apktool (<https://ibotpeaches.github.io/Apktool/>)
* d2j-dex2jar (<https://github.com/pxb1988/dex2jar>)
* adb (<https://developer.android.com/studio/releases/platform-tools>)
* その他 (オプション):
* avdmanager (<https://developer.android.com/studio/#downloads>)
### iOSモジュール用
* jtool (Linux) (<http://www.newosxbook.com/tools/jtool.html>)
* otool (MacOS) (<https://developer.apple.com/xcode/>)
* ldid (<https://github.com/daeken/ldid.git>)
* iproxy (パッケージ: libimobiledevice)
* lsusb (パッケージ: usbutils)
* unzip
### iOSバイナリ
* バンドルされたバイナリ:
* dump_backup_flag
* dump_file_protection
* dump_keychain
* dump_log
* listapps
* Cydia Karenのリポジトリ (https://cydia.angelxwind.net) (オプション):
* AppSync Unified (パッケージ: net.angelxwind.appsyncunified)
* appinst (パッケージ: com.linusyang.appinst)
* Cydia Shmoo419のリポジトリ (https://shmoo419.github.io/) (オプション):
* uncrypt11 (パッケージ: com.shmoo.uncrypt11)
* gdb (パッケージ: gdb71050)
* Cydia Ichitasoのリポジトリ (http://cydia.ichitaso.com/) (オプション):
* clutch (パッケージ: com.kjcracks.clutch2)
## インストールスクリプト
### Linux```
# install iproxy lsusb
sudo apt-get install libimobiledevice usbutils
# install jd-cli
if [ ! -x "$(which jd-cli)" ]; then
curl -L -o /tmp/jdcli.zip https://github.com/kwart/jd-cmd/releases/download/jd-cmd-0.9.2.Final/jd-cli-0.9.2-dist.zip
unzip /tmp/jdcli.zip /usr/local/share/jd-cli
ln -s /usr/local/share/jd-cli/jd-cli /usr/local/bin/jd-cli
ln -s /usr/local/share/jd-cli/jd-cli.jar /usr/local/bin/jd-cli.jar
rm -rf /tmp/jdcli.zip
fi
# install apktool
if [ ! -x "$(which apktool)" ]; then
mkdir /usr/local/share/apktool
curl -L -o /usr/local/share/apktool/apktool https://raw.githubusercontent.com/iBotPeaches/Apktool/master/scripts/osx/apktool
curl -L -o /usr/local/share/apktool/apktool.jar https://bitbucket.org/iBotPeaches/apktool/downloads/apktool_2.3.3.jar
chmod +x /usr/local/share/apktool /usr/local/share/apktool/apktool.jar
ln -s /usr/local/share/apktool /usr/local/bin/apktool
ln -s /usr/local/share/apktool.jar /usr/local/bin/apktool.jar
fi
# install dex2jar
if [ ! -x "$(which d2j-dex2jar)" ]; then
curl -L -o /tmp/d2j.zip https://github.com/pxb1988/dex2jar/files/1867564/dex-tools-2.1-SNAPSHOT.zip
unzip /tmp/d2j.zip -d /tmp/d2j
dirname=$(ls --color=none /tmp/d2j)
mv /tmp/d2j/$dirname /usr/local/share/d2j-dex2jar
ln -s /usr/local/share/d2j-dex2jar/d2j-dex2jar.sh /usr/local/bin/d2j-dex2jar.sh
ln -s /usr/local/share/d2j-dex2jar/d2j-apk-sign.sh /usr/local/bin/d2j-apk-sign.sh
rm -rf /tmp/d2j.zip
fi
if [ ! -x "$(which d2j-dex2jar)" ]; then
ln -s /usr/local/bin/d2j-dex2jar.sh /usr/local/bin/d2j-dex2jar
fi
# install adb
if [ ! -x "$(which adb)" ]; then
curl -L -o /tmp/platform-tools.zip https://dl.google.com/android/repository/platform-tools-latest-linux.zip
unzip /tmp/platform-tools.zip -d /tmp/pt
mv /tmp/pt/platform-tools /usr/local/share/
ln -s /usr/local/share/platform-tools/adb /usr/local/bin/adb
ln -s /usr/local/share/platform-tools/fastboot /usr/local/bin/fastboot
fi
# install ldid
if [ ! -x "$(which ldid)" ]; then
git clone https://github.com/daeken/ldid.git /tmp/ldid
cd /tmp/ldid
./make.sh
mv ldid /usr/local/bin/
cd /tmp
rm -rf /tmp/ldid
fi
# install jtool
if [ ! -x "$(which jtool)" ]; then
curl -L -o /tmp/jtool.tar http://www.newosxbook.com/tools/jtool.tar
mkdir /tmp/jtool
tar xvf /tmp/jtool.tar -C /tmp/jtool
mv /tmp/jtool/jtool.ELF64 /usr/local/bin/jtool
rm -rf /tmp/jtool.tar /tmp/jtool
fi
# install scrounger
git clone [email protected]:nettitude/scrounger.git
cd scrounger
pip install -r requirements.txt
python setup.py install
brew tap jlhonora/lsusb && brew install lsusb libimobiledevice ldid
if [ ! -x "$(which jd-cli)" ]; then curl -L -o /tmp/jdcli.zip https://github.com/kwart/jd-cmd/releases/download/jd-cmd-0.9.2.Final/jd-cli-0.9.2-dist.zip unzip /tmp/jdcli.zip /usr/local/share/jd-cli ln -s /usr/local/share/jd-cli/jd-cli /usr/local/bin/jd-cli ln -s /usr/local/share/jd-cli/jd-cli.jar /usr/local/bin/jd-cli.jar rm -rf /tmp/jdcli.zip fi
if [ ! -x "$(which apktool)" ]; then mkdir /usr/local/share/apktool curl -L -o /usr/local/share/apktool/apktool https://raw.githubusercontent.com/iBotPeaches/Apktool/master/scripts/osx/apktool curl -L -o /usr/local/share/apktool/apktool.jar https://bitbucket.org/iBotPeaches/apktool/downloads/apktool_2.3.3.jar chmod +x /usr/local/share/apktool /usr/local/share/apktool/apktool.jar ln -s /usr/local/share/apktool /usr/local/bin/apktool ln -s /usr/local/share/apktool.jar /usr/local/bin/apktool.jar fi
if [ ! -x "$(which d2j-dex2jar)" ]; then curl -L -o /tmp/d2j.zip https://github.com/pxb1988/dex2jar/files/1867564/dex-tools-2.1-SNAPSHOT.zip unzip /tmp/d2j.zip -d /tmp/d2j dirname=$(ls --color=none /tmp/d2j) mv /tmp/d2j/$dirname /usr/local/share/d2j-dex2jar ln -s /usr/local/share/d2j-dex2jar/d2j-dex2jar.sh /usr/local/bin/d2j-dex2jar.sh ln -s /usr/local/share/d2j-dex2jar/d2j-apk-sign.sh /usr/local/bin/d2j-apk-sign.sh rm -rf /tmp/d2j.zip fi
if [ ! -x "$(which d2j-dex2jar)" ]; then ln -s /usr/local/bin/d2j-dex2jar.sh /usr/local/bin/d2j-dex2jar fi
if [ ! -x "$(which adb)" ]; then curl -L -o /tmp/platform-tools.zip https://dl.google.com/android/repository/platform-tools-latest-darwin.zip unzip /tmp/platform-tools.zip -d /tmp/pt mv /tmp/pt/platform-tools /usr/local/share/ ln -s /usr/local/share/platform-tools/adb /usr/local/bin/adb ln -s /usr/local/share/platform-tools/fastboot /usr/local/bin/fastboot fi
xcode-select --install
git clone [email protected]:nettitude/scrounger.git cd scrounger pip install -r requirements.txt python setup.py install
## カスタムモジュールの追加
アプリケーションをインストールすると、`~/.scrounger` フォルダが作成されます。
`~/.scrounger` の中に、デフォルトの scrounger モジュールと同じ構造を持つ `modules/custom` というフォルダが作成されます(例:`analysis/android/module_name`)。