Android Pentesting - Android Architecture + Static Analysis with apktool + gf + jadx - Pt. 01

Поделиться
HTML-код
  • Опубликовано: 21 авг 2024
  • In this video we would start with android pentesting :
    - Basics of Android Architecture
    Security Features in Android
    - APK Structures
    Installing apktool & jadx-gui
    Understanding folder structure & files
    Finding secrets in apps
    - Exploiting a real world app
    Searching for secrets
    AndroidManifest.xml
    Strings.xml
    Raw resources
    Using gf to search for secrets
    Validating these secrets
    ▬▬▬▬▬▬ 🔗 Links ▬▬▬▬▬▬
    manifestsecuri...
    hackerone.com/...
    ▬▬▬▬▬▬ 🔗 Other Links ▬▬▬▬▬▬
    🔥Stay Up-To-Date with latest in CyberSecurity and Bug Bounty Tips 🔥
    omnisec.app/
    💸 $100 Digital Ocean referral link :💸
    m.do.co/c/5e8e...
    Google FeedBack Form : forms.gle/rA9o...
    Discord : / discord
    Subreddit : / hackingsimplified
    Telegram : t.me/hackingsi...
    Hope it was worth your time.
    Stay tuned.
    Thank you everyone :)
    ▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬
    Disclaimer :
    These materials are for educational and research purposes only.
    Do not attempt to violate the law with anything contained here. If this is your intention, then LEAVE NOW! The creator of this video, nor anyone else affiliated in any way, is going to accept responsibility for your actions.
    ------------------------------------------------------------------------------------------------------------------------
    #hacking #HackingSimplified #StartHacking #beTheHACR #websecurity #howtohack #hack #howtobeahacker #hackingCourse #bugBounty #bug #bounty #hacker #freeHacking #freecourse
    hacking ,HackingSimplified, Hacking Simplified, Start Hacking ,Be The HACR, web security, how to be a hacker, free hacking, free hacking course, web security,hacking Course,bug Bounty,hacker,bug bounty,cyber security,bug bounty hunting

Комментарии • 74

  • @HackingSimplifiedAS
    @HackingSimplifiedAS  3 года назад +7

    If you like the content, make sure to like and subscribe. Share this to reach as many folks as possible :)

    • @nishanthm6563
      @nishanthm6563 Год назад

      bro am using kali linux gf command is not working bro

  • @chasejensen88
    @chasejensen88 3 года назад +3

    You and your smile will be a legend my friend. You've made some awesome tools and content, for real I'm pretty surprised you haven't blown up yet. Keep it up, they're coming

  • @Ramu_Sriram
    @Ramu_Sriram Месяц назад

    Thank you bro, learned something.

  • @anuvindtiwari8229
    @anuvindtiwari8229 2 года назад +1

    Your videos are really informative.Thanks alot man for making such informative video.Keep it up .☺️👍

  • @kAh00t
    @kAh00t 3 года назад

    Really useful video, added the gf tool to my tooling! Keep them up

  • @sampritdas783
    @sampritdas783 3 года назад +1

    Nice video waiting for more videos on andro pentest 😁

    • @HackingSimplifiedAS
      @HackingSimplifiedAS  3 года назад +1

      Thanks mate. If you like the content, consider sharing it :D

    • @sampritdas783
      @sampritdas783 3 года назад

      @@HackingSimplifiedAS sure 😁

  • @HarshalChauhan_
    @HarshalChauhan_ 3 года назад

    Very well explained. your videos are always awesome.

  • @grahamparr4451
    @grahamparr4451 6 месяцев назад

    This is really good vid ,thanks man

  • @sagarpatra2748
    @sagarpatra2748 3 года назад

    Very good content. Hoping for more android pen testing contents.

    • @HackingSimplifiedAS
      @HackingSimplifiedAS  3 года назад +1

      Thanks mate. If you like the content, consider sharing it :D

  • @mr_t0mat042
    @mr_t0mat042 3 года назад

    Really appreciate your work, keep going👍

  • @divyangchauhan9592
    @divyangchauhan9592 2 года назад

    Your content is very helpful!!! I have one suggestion please don't background music!! sometimes it's distracting...

  • @hackersratremoteaccesstroj4238
    @hackersratremoteaccesstroj4238 3 года назад

    Evergreen content

  • @dhrudeeppatel3098
    @dhrudeeppatel3098 3 года назад

    very good approach man...

  • @domaincontroller
    @domaincontroller 2 года назад

    02:30 Android architecture 07:20 sandbox 07:37 APK file structure

  • @pethe7
    @pethe7 3 года назад

    Thank you. It helped me a lot.

  • @ghtkdfake1274
    @ghtkdfake1274 3 года назад

    Hey, This is the video one needs to start with Android Pentesting. I have setup everything on Windows. Can you please create an installation guide for gf tool on Windows. Will be great help.

  • @ANKITPATEL-ju7ro
    @ANKITPATEL-ju7ro 3 года назад

    Thanx for the awsome content!

    • @HackingSimplifiedAS
      @HackingSimplifiedAS  3 года назад

      Thanks mate. If you like the content, consider sharing it :D

  • @asadakhlaq1298
    @asadakhlaq1298 2 года назад

    Thanks for your help ☺️

  • @karanthakkar04
    @karanthakkar04 3 года назад +1

    I cannot find the apk that you used in the video. Can you please upload a copy and share the link if you have so that I can follow?
    Edit: I found it on apksum and it is only website that has versions from 2019.

  • @ammartanweer3388
    @ammartanweer3388 3 года назад +2

    You are making great content man if need any help ping us really great material

  • @maroghal2071
    @maroghal2071 2 года назад +1

    Hey, thank you for the video its very helpful.
    Is there any good Static Analysis tool? And how accurate are they?

    • @HackingSimplifiedAS
      @HackingSimplifiedAS  2 года назад

      MobSF is good. You can try that.

    • @maroghal2071
      @maroghal2071 2 года назад

      @@HackingSimplifiedAS Thank you for answering, do you have any good resources where I can learn more about static analysis.

  • @shazone4141
    @shazone4141 3 года назад

    Waiting for second part and my question is what you've shown on gui starting of video decompilation is same in the last of video with apktool with storing file in that directory right. We can perform same thing on terminal with gf pattern search.

  • @anuragpathak2848
    @anuragpathak2848 3 года назад

    @Hacking Simplified is this io. fabric.ApiKey can be consider as sensitive API key

  • @amanrai8054
    @amanrai8054 3 года назад

    Good Topic

    • @HackingSimplifiedAS
      @HackingSimplifiedAS  3 года назад

      Thanks mate. If you like the content, consider sharing it :D

  • @goodboy8833
    @goodboy8833 3 года назад

    I can say this will be a goto resource for learning android pt. Good content make part 2 buddy.

  • @saikiranlingadally1036
    @saikiranlingadally1036 3 года назад

    🔥👍

  • @sabyasachisahoo8975
    @sabyasachisahoo8975 3 года назад +1

    what about if a applicaton made up Reactnactive or flutter

  • @TWINYT08
    @TWINYT08 3 года назад +1

    Heyy Can U make videos on finding bugs in Java Script

  • @user-hs4hx9dw2b
    @user-hs4hx9dw2b 2 года назад

    please dynamic analysis with drozer, frida, etc

  • @sauravshukla8351
    @sauravshukla8351 3 года назад

    Nyc Video great explanation Buddy Thanks for such great content. Just wanted to know which Linux distribution you are using....

    • @HackingSimplifiedAS
      @HackingSimplifiedAS  3 года назад +1

      Ubuntu, recently on manjaro. I try different things. But mostly it's Ubuntu.

  • @umeshb8210
    @umeshb8210 3 года назад

    Waiting for pt 2

    • @umeshb8210
      @umeshb8210 3 года назад +1

      Bro can u make a video on wat n all to look for in a android pentest

  • @gajendrantheepiha3851
    @gajendrantheepiha3851 2 года назад

    Omnisec link for security updates is not working . Please

  • @torsec6048
    @torsec6048 3 года назад

    your content is ows0me i lik3 it

    • @HackingSimplifiedAS
      @HackingSimplifiedAS  3 года назад

      Thanks mate. If you like the content, consider sharing it :D

  • @0ximtiaz
    @0ximtiaz 3 года назад

    next

  • @neerajverma9226
    @neerajverma9226 2 года назад

    How to decompile JNI based files in android app?

  • @optionroots
    @optionroots Год назад

    hi, can you plz tell me how to increase heap size error when i open any apk into jadx

  • @surajvishwakarma9441
    @surajvishwakarma9441 3 года назад

    Awesome video.... Can you let me know if there is any automated dast tool for mobile app

    • @HackingSimplifiedAS
      @HackingSimplifiedAS  3 года назад

      You can see mobsf , it has dast as well.

    • @surajvishwakarma9441
      @surajvishwakarma9441 3 года назад

      Are there any commercial tool? Also is there any difference between web application dast and mobile application dast?

  • @shopflicker
    @shopflicker 3 года назад

    we need android pentesting with burpsuite.plzzzzzzzzzzz

  • @TanmayBhattacharjee-gj3vb
    @TanmayBhattacharjee-gj3vb 3 года назад

    omnisec app is not working.

  • @0ximtiaz
    @0ximtiaz 3 года назад

    next....

  • @helloworld-dh4pk
    @helloworld-dh4pk 3 года назад

    if u really want to explain then why r u disturbing with background music...

  • @ashutoshraval3255
    @ashutoshraval3255 3 года назад

    Aree bhai jara hindi me bolo to india ke kuch log smaja paay

  • @shivam_vk
    @shivam_vk 3 года назад

    Plz make video in hindi 😑😑

    • @yrks1109
      @yrks1109 3 года назад +3

      There's a reason he uses english, because more audience can understand the content .

    • @shivam_vk
      @shivam_vk 3 года назад

      @@yrks1109 yes bro you are right 👌😁

  • @glostar_Rx
    @glostar_Rx Год назад

    Done Hack th3