Android App Hacking – Black Belt Edition


Android App Hacking – Black Belt Edition
Android App Hacking – Black Belt Edition
Published 7/2022
MP4 | Video: h264, 1280×720 | Audio: AAC, 44.1 KHz

Becoming the lead expert in android app security

What you’ll learn
Deep understanding of the android app structure
How to exploit Activities, BroadcastReceiver and ContentProvider (SQL injection & Path Traversal)
Bypassing Rooting Detection (SMALI and FRIDA)
Bypassing Certificate Pinning (SMALI and FRIDA)
Performing a man-in-the-middle attack
Analyzing-/ Manipulating the network traffic of a mobile app
Creating call- and flow graphs to reverse engineer strong obfuscated apps
Manipulating Java and C/C++ methods (FRIDA & SMALI)
Reading- / Writing SMALI code
Injecting own (custom) code into existing applications
Deep understanding of the android permission model
Modifying games (infinite lives, high score, invisble, invincible) – Writing a trainer
Analzying bluetooth low energy connections
Dealing with different encryption types (e.g. AES)
Ethical and legal principles
Requirements
Android knowledge is not required (This course teaches everything)
Laptiop / PC
Description
Overview

Section 1: Installation and Setup

Lecture 1 Setup – Theory

Lecture 2 Installation (System & Android Studio)

Lecture 3 Emulator – Installation

Lecture 4 Emulator – Usage (Secret Features)

Lecture 5 Androidx86 Virtual Machine – Setup

Lecture 6 Developer Options

Lecture 7 Developer Options – Secrets ( Game Hacking )

Lecture 8 Developer Options – Bluetooth Low Energy Hacking

Lecture 9 Bluetooth Low Energy – Furby App Hacking

Lecture 10 Android Debug Bridge – Theory

Lecture 11 Android Debug Bridge (ADB) – HandsOn (White – Belt)

Section 2: App Structure

Lecture 12 Filestructure of an APK

Lecture 13 Dalvik / Dex

Lecture 14 Classes.dex

Lecture 15 Decompiling – Preperation

Lecture 16 Decompiling – HandsOn

Lecture 17 AndroidManifest.xml

Lecture 18 App – Permissions

Lecture 19 Activities

Lecture 20 Activities – Hacking

Lecture 21 Activity – Bonus (Bypassing Login – Own Application)

Lecture 22 Intents

Lecture 23 Intents – Examples

Lecture 24 BroadcastReceiver

Lecture 25 BroadcastReceiver – Hacking (Alarm App)

Lecture 26 BroadcastReceiver – Hacking via own App

Lecture 27 Services

Lecture 28 ContentProvider

Lecture 29 ContentProvider – SQL Injection

Lecture 30 ContentProvider – Database Attacks (SQLi – Permission / Bypass)

Lecture 31 ContentProvider – PathTraversal Attack

Lecture 32 Application Signing

Lecture 33 Application Signing – Deep Dive

Lecture 34 BlueBox Master Key Vulnerability (Signing)

Section 3: Reverse Engineering Android Apps

Lecture 35 Dex2Jar

Lecture 36 Jadx-Gui

Lecture 37 Jadx-Gui HandsOn

Lecture 38 Secret Super Weapon

Lecture 39 Reversing Apps

Lecture 40 Creating a CallGraph (CG)

Lecture 41 Creating a FlowGraph (FG)

Lecture 42 Challenge – Intro

Lecture 43 Challenge – Hacking Activities

Lecture 44 Challenge – Hacking Content Provider

Lecture 45 Challenge – Hacking BroadCast Receiver

Lecture 46 Challenge – Password (Decryption)

Section 4: Smali

Lecture 47 Recap

Lecture 48 Smali – Introduction

Lecture 49 Smali – Patching

Lecture 50 Challenge – Solution

Lecture 51 Registers

Lecture 52 Types

Lecture 53 P0 – Register

Lecture 54 Dalvik Opcodes

Lecture 55 Smali File Structure

Lecture 56 Practice – Smali

Lecture 57 Practice – Solution

Lecture 58 Orange Belt – Intro

Lecture 59 Orange Belt – Solution

Lecture 60 IF – Intro

Lecture 61 IF / ELSE / GOTO

Lecture 62 IF / ELSE / GOTO – Code Analysis

Lecture 63 IF / ELSE / GOTO – Blocks

Lecture 64 IF / ELSE / GOTO – Practice

Lecture 65 Smali Patching – Flipping the logic

Lecture 66 Smali Patching – Deleting Code

Lecture 67 Smali Patching – Jump Instructions

Lecture 68 Rooting Detection – Intro

Lecture 69 Rooting Detection (bypass) – Solution

Lecture 70 Rooting Detection – Solution2 (Bonus)

Lecture 71 Smali – Objects and Methods

Lecture 72 Smali – Static Methods

Lecture 73 Smali – Hello World (Yes, this late)

Lecture 74 Printing out secrets – System.out (Written in Smali)

Lecture 75 Patching XOR encryption

Lecture 76 One challenge to recap all – Intro

Lecture 80 One challenge to recap all – Solution

Lecture 81 Blue Belt – Challenge (Intro)

Lecture 82 Blue Belt – Challenge (Hint)

Lecture 83 Blue Belt – Challenge (Solution)

Section 5: Man in the Middle

Lecture 84 Adress Resolution Protocol (ARP)

Lecture 85 MitM – Setup

Lecture 86 Intercepting – Theory

Lecture 87 BurpSuite – Setup

Lecture 88 Reset the Setup

Lecture 89 HTTPS – Technical View

Lecture 90 Installing a Certificate

Lecture 91 MitM Setup – Virtual Machine (VM)

Lecture 92 Certificate Pinning – Theory

Lecture 93 Certificate Pinning – OpenSSL (Bonus)

Lecture 94 Certificate Pinning – Patching Fingerprint

Lecture 95 Certificate Pinning – Patching Certificate

Lecture 96 Certificate Pinning – Objection (Bypass)

Section 6: FRIDA

Lecture 97 Introduction

Lecture 98 Install

Lecture 99 Hooking – Theory

Lecture 100 Dize Game – HandsOn

Lecture 101 Dize App – Analysis

Lecture 102 Dize App – Observing Parameters

Lecture 103 Dize App – Modifying Parameters

Lecture 104 Function Overloading

Lecture 105 Timing (Hooking)

Lecture 106 Challenge – Rooting Detection (bypass)

Lecture 107 Challenge – Rooting Detection (solution)

Lecture 108 Actively calling a method

Lecture 109 Instance Methods

Lecture 110 Working with Instances

Lecture 111 HandsOn

Lecture 112 HandsOn – Solution

Lecture 113 Instance as a parameter

Lecture 114 Existing instance as a parameter

Lecture 115 Challenge – Create multiple player shots

Lecture 116 Challenge – Mulitple player shots (solution)

Lecture 117 Constructor hooking

Lecture 118 Manipulating UI Thread

Lecture 119 Writing a trainer

Lecture 120 Hooking the Native Development Kit (NDK)

Lecture 121 NDK hooking – Easy Way

Lecture 122 NDK hooking – Hard way

Lecture 123 NDK hooking – timing

Lecture 124 hooking ndk

Lecture 125 Reversing C – function in ghidra (Bonus)

Lecture 126 Hooking C – function in frida (Bonus)

Security Analyst / Ethical Hacker,Android app developer,Bug Bounty Hunter,Everyone who likes to manipulate android apps / games 🙂

Importantissimo!

Per NON SBAGLIARE link e finire su qualche possibile clone, approfittare di offerte esclusive personalizzate per il nostro sito, e se gradisce questo articolo ed il nostro lavoro, la preghiamo di supportarci rinnovando o sottoscrivendo un Account Premium su FILESTORE cliccando sul link qui sotto:

FileStore

Share This Post!

Torna in cima