
모바일 애플리케이션 테스팅 툴킷
Scrounger – 다른 사람에게서 빌리거나 기대어 사는 사람.
이 도구를 설명하는 데 이보다 더 적절한 말은 없습니다. 첫째, 이 도구는 이미 출판된 많은 다른 도구들에서 영감을 받았기 때문이고, 둘째, 모바일 애플리케이션의 취약점에 기대어 살아가기 때문입니다.
여러 모바일 애플리케이션 분석 도구들이 개발되었음에도 불구하고, 안드로이드와 iOS 모두에 사용할 수 있고 모든 모바일 애플리케이션 평가에 반드시 사용해야 하는 "표준"이라고 불릴 만한 도구는 없습니다.
Scrounger의 아이디어는 침투 테스터의 작업을 대신하는 것이 아니라, 모든 평가에서 수행해야 하는 지루한 작업을 실행하여 침투 테스터의 평가를 돕는 metasploit과 유사한 도구를 만드는 것입니다.
Scrounger가 제공하는 다른 도구에는 없는 주요 기능:
Scrounger는 다른 도구들에서 영감을 받았으며, 다음 개발자분들께 큰 감사를 드립니다:
면책 조항으로, Scrounger에 의해 식별된 모든 발견 사항은 항상 수동으로 재확인해야 합니다.
Android 또는 iOS 기기가 필요한 모듈을 사용할 때, Scrounger는 각각 Rooted 또는 Jailbroken 기기가 필요합니다.
Scrounger는 iOS 11 및 Android 8.1에서 작동하도록 테스트되었습니다.
Scrounger는 python 2.7 전용으로 빌드되었습니다.
git clone https://github.com/nettitude/scrounger.git cd scrounger bash setup.sh pip install -r requirements.txt python setup.py install
## 개발```
git pull https://github.com/nettitude/scrounger.git
cd scrounger
bash setup.sh
pip install -r requirements.txt
python setup.py develop
cd scrounger git pull python setup.py install --upgrade
## 필수 바이너리
### 안드로이드 모듈용
* java (<http://www.oracle.com/technetwork/java/javase/downloads/index.html>)
* jd-cli (<https://github.com/kwart/jd-cmd>)
* apktool (<https://ibotpeaches.github.io/Apktool/>)
* d2j-dex2jar (<https://github.com/pxb1988/dex2jar>)
* adb (<https://developer.android.com/studio/releases/platform-tools>)
* 기타 (선택 사항):
* avdmanager (<https://developer.android.com/studio/#downloads>)
### iOS 모듈용
* jtool (Linux) (<http://www.newosxbook.com/tools/jtool.html>)
* otool (MacOS) (<https://developer.apple.com/xcode/>)
* ldid (<https://github.com/daeken/ldid.git>)
* iproxy (패키지: libimobiledevice)
* lsusb (패키지: usbutils)
* unzip
### iOS 바이너리
* 번들 바이너리:
* dump_backup_flag
* dump_file_protection
* dump_keychain
* dump_log
* listapps
* Cydia Karen's 저장소 (https://cydia.angelxwind.net) (선택 사항):
* AppSync Unified (패키지: net.angelxwind.appsyncunified)
* appinst (패키지: com.linusyang.appinst)
* Cydia Shmoo419's 저장소 (https://shmoo419.github.io/) (선택 사항):
* uncrypt11 (패키지: com.shmoo.uncrypt11)
* gdb (패키지: gdb71050)
* Cydia Ichitaso's 저장소 (http://cydia.ichitaso.com/) (선택 사항):
* clutch (패키지: com.kjcracks.clutch2)
## 설치 스크립트
### Linux```
# install iproxy lsusb
sudo apt-get install libimobiledevice usbutils
# install jd-cli
if [ ! -x "$(which jd-cli)" ]; then
curl -L -o /tmp/jdcli.zip https://github.com/kwart/jd-cmd/releases/download/jd-cmd-0.9.2.Final/jd-cli-0.9.2-dist.zip
unzip /tmp/jdcli.zip /usr/local/share/jd-cli
ln -s /usr/local/share/jd-cli/jd-cli /usr/local/bin/jd-cli
ln -s /usr/local/share/jd-cli/jd-cli.jar /usr/local/bin/jd-cli.jar
rm -rf /tmp/jdcli.zip
fi
# install apktool
if [ ! -x "$(which apktool)" ]; then
mkdir /usr/local/share/apktool
curl -L -o /usr/local/share/apktool/apktool https://raw.githubusercontent.com/iBotPeaches/Apktool/master/scripts/osx/apktool
curl -L -o /usr/local/share/apktool/apktool.jar https://bitbucket.org/iBotPeaches/apktool/downloads/apktool_2.3.3.jar
chmod +x /usr/local/share/apktool /usr/local/share/apktool/apktool.jar
ln -s /usr/local/share/apktool /usr/local/bin/apktool
ln -s /usr/local/share/apktool.jar /usr/local/bin/apktool.jar
fi
# install dex2jar
if [ ! -x "$(which d2j-dex2jar)" ]; then
curl -L -o /tmp/d2j.zip https://github.com/pxb1988/dex2jar/files/1867564/dex-tools-2.1-SNAPSHOT.zip
unzip /tmp/d2j.zip -d /tmp/d2j
dirname=$(ls --color=none /tmp/d2j)
mv /tmp/d2j/$dirname /usr/local/share/d2j-dex2jar
ln -s /usr/local/share/d2j-dex2jar/d2j-dex2jar.sh /usr/local/bin/d2j-dex2jar.sh
ln -s /usr/local/share/d2j-dex2jar/d2j-apk-sign.sh /usr/local/bin/d2j-apk-sign.sh
rm -rf /tmp/d2j.zip
fi
if [ ! -x "$(which d2j-dex2jar)" ]; then
ln -s /usr/local/bin/d2j-dex2jar.sh /usr/local/bin/d2j-dex2jar
fi
# install adb
if [ ! -x "$(which adb)" ]; then
curl -L -o /tmp/platform-tools.zip https://dl.google.com/android/repository/platform-tools-latest-linux.zip
unzip /tmp/platform-tools.zip -d /tmp/pt
mv /tmp/pt/platform-tools /usr/local/share/
ln -s /usr/local/share/platform-tools/adb /usr/local/bin/adb
ln -s /usr/local/share/platform-tools/fastboot /usr/local/bin/fastboot
fi
# install ldid
if [ ! -x "$(which ldid)" ]; then
git clone https://github.com/daeken/ldid.git /tmp/ldid
cd /tmp/ldid
./make.sh
mv ldid /usr/local/bin/
cd /tmp
rm -rf /tmp/ldid
fi
# install jtool
if [ ! -x "$(which jtool)" ]; then
curl -L -o /tmp/jtool.tar http://www.newosxbook.com/tools/jtool.tar
mkdir /tmp/jtool
tar xvf /tmp/jtool.tar -C /tmp/jtool
mv /tmp/jtool/jtool.ELF64 /usr/local/bin/jtool
rm -rf /tmp/jtool.tar /tmp/jtool
fi
# install scrounger
git clone [email protected]:nettitude/scrounger.git
cd scrounger
pip install -r requirements.txt
python setup.py install
brew tap jlhonora/lsusb && brew install lsusb libimobiledevice ldid
if [ ! -x "$(which jd-cli)" ]; then curl -L -o /tmp/jdcli.zip https://github.com/kwart/jd-cmd/releases/download/jd-cmd-0.9.2.Final/jd-cli-0.9.2-dist.zip unzip /tmp/jdcli.zip /usr/local/share/jd-cli ln -s /usr/local/share/jd-cli/jd-cli /usr/local/bin/jd-cli ln -s /usr/local/share/jd-cli/jd-cli.jar /usr/local/bin/jd-cli.jar rm -rf /tmp/jdcli.zip fi
if [ ! -x "$(which apktool)" ]; then mkdir /usr/local/share/apktool curl -L -o /usr/local/share/apktool/apktool https://raw.githubusercontent.com/iBotPeaches/Apktool/master/scripts/osx/apktool curl -L -o /usr/local/share/apktool/apktool.jar https://bitbucket.org/iBotPeaches/apktool/downloads/apktool_2.3.3.jar chmod +x /usr/local/share/apktool /usr/local/share/apktool/apktool.jar ln -s /usr/local/share/apktool /usr/local/bin/apktool ln -s /usr/local/share/apktool.jar /usr/local/bin/apktool.jar fi
if [ ! -x "$(which d2j-dex2jar)" ]; then curl -L -o /tmp/d2j.zip https://github.com/pxb1988/dex2jar/files/1867564/dex-tools-2.1-SNAPSHOT.zip unzip /tmp/d2j.zip -d /tmp/d2j dirname=$(ls --color=none /tmp/d2j) mv /tmp/d2j/$dirname /usr/local/share/d2j-dex2jar ln -s /usr/local/share/d2j-dex2jar/d2j-dex2jar.sh /usr/local/bin/d2j-dex2jar.sh ln -s /usr/local/share/d2j-dex2jar/d2j-apk-sign.sh /usr/local/bin/d2j-apk-sign.sh rm -rf /tmp/d2j.zip fi
if [ ! -x "$(which d2j-dex2jar)" ]; then ln -s /usr/local/bin/d2j-dex2jar.sh /usr/local/bin/d2j-dex2jar fi
if [ ! -x "$(which adb)" ]; then curl -L -o /tmp/platform-tools.zip https://dl.google.com/android/repository/platform-tools-latest-darwin.zip unzip /tmp/platform-tools.zip -d /tmp/pt mv /tmp/pt/platform-tools /usr/local/share/ ln -s /usr/local/share/platform-tools/adb /usr/local/bin/adb ln -s /usr/local/share/platform-tools/fastboot /usr/local/bin/fastboot fi
xcode-select --install
git clone [email protected]:nettitude/scrounger.git cd scrounger pip install -r requirements.txt python setup.py install
## 사용자 정의 모듈 추가하기
애플리케이션을 설치하면 `~/.scrounger` 폴더가 생성됩니다.
`~/.scrounger` 안에는 기본 scrounger 모듈과 동일한 구조를 가진 `modules/custom` 폴더가 있습니다(예: `analysis/android/module_name`).
새 사용자 정의 모듈을 만들려면 원하는 모듈 이름으로 새 파일을 추가하기만 하면 다음에 scrounger를 실행할 때 포함됩니다.
### 예시
다음 모듈을 추가했습니다 (`~/.scrounger/modules/custom/misc/test.py`):```
from scrounger.core.module import BaseModule
class Module(BaseModule):
meta = {
"author": "RDC",
"description": """Just a Test module""",
"certainty": 100
}
options = [
{
"name": "output",
"description": "local output directory",
"required": False,
"default": None
},
]
def run(self):
print("This is a print from the custom module")
return {
"print": "This will be print by scrounger's console."
}
$ scrounger-console Starting Scrounger console...
scrounger > list custom/misc
Module Certainty Author Description
custom/misc/test 100% RDC Just a Test module
scrounger > use custom/misc/test
scrounger custom/misc/test > options
Global Options:
Name Value
---- -----
device
output /tmp/scrounger-app
Module Options (custom/misc/test):
Name Required Description Current Setting
---- -------- ----------- ---------------
output False local output directory /tmp/scrounger-app
scrounger custom/misc/test > run This is a print from the custom module [+] This will be print by scrounger's console.
scrounger custom/misc/test >
## 예제
### 모듈 목록 보기 / 검색```
$ scrounger-console
Starting Scrounger console...
> help
Documented commands (type help <topic>):
========================================
add_device devices list print results set unset
back help options quit run show use
> help list
Lists all available modules
> list ios
Module Certainty Author Description
------ --------- ------ -----------
analysis/ios/app_transport_security 90% RDC Checks if there are any Application Transport Security misconfigurations
analysis/ios/arc_support 90% RDC Checks if a binary was compiled with ARC support
analysis/ios/backups 90% RDC Checks the application's files have the backup flag on
analysis/ios/clipboard_access 75% RDC Checks if the application disables clipboard access
analysis/ios/debugger_detection 75% RDC Checks if the application detects debuggers
analysis/ios/excessive_permissions 90% RDC Checks if the application uses excessive permissions
analysis/ios/file_protection 90% RDC Checks the application's files specific protection flags
analysis/ios/full_analysis 100% RDC Runs all modules in analysis and writes a report into the output directory
analysis/ios/insecure_channels 50% RDC Checks if the application uses insecure channels
analysis/ios/insecure_function_calls 75% RDC Checks if the application uses insecure function calls
analysis/ios/jailbreak_detection 60% RDC Checks if the application implements jailbreak detection
analysis/ios/logs 60% RDC Checks if the application logs to syslog
analysis/ios/passcode_detection 60% RDC Checks if the application checks for passcode being set
analysis/ios/pie_support 100% RDC Checks if the application was compiled with PIE support
analysis/ios/prepared_statements 60% RDC Checks if the application uses sqlite calls and if so checks if it also uses prepared statements
analysis/ios/ssl_pinning 60% RDC Checks if the application implements SSL pinning
analysis/ios/stack_smashing 90% RDC Checks if a binary was compiled stack smashing protections
analysis/ios/third_party_keyboard 65% RDC Checks if an application checks of third party keyboards
analysis/ios/unencrypted_communications 80% RDC Checks if the application implements communicates over unencrypted channels
analysis/ios/unencrypted_keychain_data 70% RDC Checks if the application saves unencrypted data in the keychain
analysis/ios/weak_crypto 60% RDC Checks if the application uses weak crypto
analysis/ios/weak_random 50% RDC Checks if a binary uses weak random functions
analysis/ios/weak_ssl_ciphers 50% RDC Checks if a binary uses weak SSL ciphers
misc/ios/app/archs 100% RDC Gets the application's available architectures
misc/ios/app/data 100% RDC Gets the application's data from the remote device
misc/ios/app/entitlements 100% RDC Gets the application's entitlements
misc/ios/app/flags 100% RDC Gets the application's compilation flags
misc/ios/app/info 100% RDC Pulls the Info.plist info from the device
misc/ios/app/start 100% RDC Launches an application on the remote device
misc/ios/app/symbols 100% RDC Gets the application's symbols out of an installed application on the device
misc/ios/class_dump 100% RDC Dumps the classes out of a decrypted binary
misc/ios/decrypt_bin 100% RDC Decrypts and pulls a binary application
misc/ios/install_binaries 100% RDC Installs iOS binaries required to run some checks
misc/ios/keychain_dump 100% RDC Dumps contents from the connected device's keychain
misc/ios/local/app/archs 100% RDC Gets the application's available architectures
misc/ios/local/app/entitlements 100% RDC Gets the application's entitlements from a local binary and saves them to file
misc/ios/local/app/flags 100% RDC Gets the application's compilation flags using local tools. Will look for otool and jtool in the PATH.
misc/ios/local/app/info 100% RDC Pulls the Info.plist info from the unzipped IPA file and saves an XML file with it's contents to the output folder
misc/ios/local/app/symbols 100% RDC Gets the application's symbols out of an installed application on the device
misc/ios/local/class_dump 100% RDC Dumps the classes out of a decrypted binary
misc/ios/pull_ipa 100% RDC Pulls the IPA file from a remote device
misc/ios/unzip_ipa 100% RDC Unzips the IPA file into the output directory
$ scrounger-console Starting Scrounger console...
use misc/android/decompile_apk
misc/android/decompile_apk > options
Global Options:
Name Value
---- -----
device
output /tmp/scrounger-app
Module Options (misc/android/decompile_apk):
Name Required Description Current Setting
---- -------- ----------- ---------------
output True local output directory /tmp/scrounger-app
apk True local path to the APK file
misc/android/decompile_apk > set output scrounger-demo-output
misc/android/decompile_apk > set apk ./a.apk
misc/android/decompile_apk > options
Global Options:
Name Value
---- -----
device
output /tmp/scrounger-app
Module Options (misc/android/decompile_apk):
Name Required Description Current Setting
---- -------- ----------- ---------------
output True local output directory scrounger-demo-output
apk True local path to the APK file ./a.apk
misc/android/decompile_apk > run 2018-05-01 10:29:53 - decompile_apk : Creating decompilation directory 2018-05-01 10:29:53 - decompile_apk : Decompiling application 2018-05-01 10:29:59 - manifest : Checking for AndroidManifest.xml file 2018-05-01 10:29:59 - manifest : Creating manifest object [+] Application decompiled to scrounger-demo-output/com.eg.challengeapp.decompiled
### 다른 모듈의 결과 사용하기```
misc/android/decompile_apk > show results
Results:
Name Value
---- -----
com.eg.challengeapp_decompiled scrounger-demo-output/com.eg.challengeapp.decompiled
misc/android/decompile_apk > use analysis/android/permissions
analysis/android/permissions > options
Global Options:
Name Value
---- -----
device
output /tmp/scrounger-app
Module Options (analysis/android/permissions):
Name Required Description Current Setting
---- -------- ----------- ---------------
decompiled_apk True local folder containing the decompiled apk file
permissions True dangerous permissions to check for, seperated by ; android.permission.GET_TASKS;android.permission.BIND_DEVICE_ADMIN;android.permission.USE_CREDENTIALS;com.android.browser.permission.READ_HISTORY_BOOKMARKS;android.permission.PROCESS_OUTGOING_CA
analysis/android/permissions > print option permissions
Option Name: permissions
Value: android.permission.GET_TASKS;android.permission.BIND_DEVICE_ADMIN;android.permission.USE_CREDENTIALS;com.android.browser.permission.READ_HISTORY_BOOKMARKS;android.permission.PROCESS_OUTGOING_CALLS;android.permission.READ_LOGS;android.permission.READ_SMS;android.permission.READ_CALL_LOG;android.permission.RECORD_AUDIO;android.permission.MANAGE_ACCOUNTS;android.permission.RECEIVE_SMS;android.permission.RECEIVE_MMS;android.permission.WRITE_CONTACTS;android.permission.DISABLE_KEYGUARD;android.permission.WRITE_SETTINGS;android.permission.WRITE_SOCIAL_STREAM;android.permission.WAKE_LOCK
analysis/android/permissions > set decompiled_apk result:com.eg.challengeapp_decompiled
analysis/android/permissions > options
Global Options:
Name Value
---- -----
device
output /tmp/scrounger-app
Module Options (analysis/android/permissions):
Name Required Description Current Setting
---- -------- ----------- ---------------
decompiled_apk True local folder containing the decompiled apk file result:com.eg.challengeapp_decompiled
permissions True dangerous permissions to check for, seperated by ; android.permission.GET_TASKS;android.permission.BIND_DEVICE_ADMIN;android.permission.USE_CREDENTIALS;com.android.browser.permission.READ_HISTORY_BOOKMARKS;android.permission.PROCESS_OUTGOING_CA
analysis/android/permissions > run
2018-05-01 10:54:58 - manifest : Checking for AndroidManifest.xml file
2018-05-01 10:54:58 - manifest : Creating manifest object
2018-05-01 10:54:58 - permissions : Analysing application's manifest permissions
[+] Analysis result:
The Application Has Inadequate Permissions
Report: True
Details:
* android.permission.READ_SMS
$ scrounger-console Starting Scrounger console...
show devices
Added Devices:
Scrounger ID Device OS Identifier
------------ --------- ----------
add_device android ios
add_device android 00cd7e67ec57c127
show devices
Added Devices:
Scrounger ID Device OS Identifier
------------ --------- ----------
1 android 00cd7e67ec57c127
set global device 1
options
Global Options:
Name Value
---- -----
device 1
output /tmp/scrounger-app
use misc/list_apps
misc/list_apps > options
Global Options:
Name Value
---- -----
device 1
output /tmp/scrounger-app
Module Options (misc/list_apps):
Name Required Description Current Setting
---- -------- ----------- ---------------
output False local output directory /tmp/scrounger-app
device True the remote device 1
misc/list_apps > unset output
misc/list_apps > options
Global Options:
Name Value
---- -----
device 1
output /tmp/scrounger-app
Module Options (misc/list_apps):
Name Required Description Current Setting
---- -------- ----------- ---------------
output False local output directory
device True the remote device 1
misc/list_apps > run [+] Applications installed on 00cd7e67ec57c127:
com.android.sharedstoragebackup com.android.providers.partnerbookmarks com.google.android.apps.maps com.google.android.partnersetup de.codenauts.hockeyapp ...
### 명령줄 도움말```
$ scrounger --help
usage: scrounger [-h] [-m analysis/ios/module1;analysis/ios/module2]
[-a argument1=value1;argument1=value2;]
[-f /path/to/the/app.[apk|ipa]] [-d device_id] [-l] [-o]
[-p /path/to/full-analysis.json] [-V] [-D]
_____
/ ____|
| (___ ___ _ __ ___ _ _ _ __ __ _ ___ _ __
\___ \ / __| '__/ _ \| | | | '_ \ / _` |/ _ \ '__|
____) | (__| | | (_) | |_| | | | | (_| | __/ |
|_____/ \___|_| \___/ \__,_|_| |_|\__, |\___|_|
__/ |
|___/
optional arguments:
-h, --help show this help message and exit
-m analysis/ios/module1;analysis/ios/module2, --modules analysis/ios/module1;analysis/ios/module2
modules to be run - seperated by ; - will be run in order
-a argument1=value1;argument1=value2;, --arguments argument1=value1;argument1=value2;
arguments for the modules to be run
-f /path/to/the/app.[apk|ipa], --full-analysis /path/to/the/app.[apk|ipa]
runs a full analysis on the application
-d device_id, --device device_id
device to be used by the modules
-l, --list list available devices and modules
-o, --options prints the required options for the selected modules
-p /path/to/full-analysis.json, --print-results /path/to/full-analysis.json
prints the results of a full analysis json file
-V, --verbose prints more information when running the modules
-D, --debug prints more information when running scrounger
$ scrounger -o -m "misc/android/decompile_apk"
Module Options (misc.android.decompile_apk):
Name Required Description Default
---- -------- ----------- -------
output True local output directory None
apk True local path to the APK file None
$ scrounger -m "misc/android/decompile_apk" -a "apk=./a.apk;output=./cli-demo" Excuting Module 0 2018-05-01 11:17:42 - decompile_apk : Creating decompilation directory 2018-05-01 11:17:42 - decompile_apk : Decompiling application 2018-05-01 11:17:46 - manifest : Checking for AndroidManifest.xml file 2018-05-01 11:17:46 - manifest : Creating manifest object [+] Application decompiled to ./cli-demo/com.eg.challengeapp.decompiled
## TODO
* scrounger-console가 시작될 때마다 실행되는 init 파일 추가
* 문자열이 아닌 경우 세션 결과 저장 문제 수정