Aditya Gupta (@adi1391)
Aditya Gupta (@adi1391)
[email protected]
Certifications : http://securitytube-training.com
Pentester Academy : http://PentesterAcademy.com
Check the complete course
• http://securitytube-training.com/online-courses/android-
security-for-pentesters/index.html
• pentesteracademy.com
1. Insecure Logging
2. Hardcoding Issues
•/data/data/[package-name]/shared_prefs
• Check the xml file if you can find the sensitive information
•/data/data/[package-name]/databases
•/data/data/[package-name]/
•/mnt/sdcard
• Using Drozer :
run app.activity.info -a jakhar.aseem.diva
run app.activity.start --component jakhar.aseem.diva
jakhar.aseem.diva.APICreds2Activity --extra boolean chk_pin
false
• Left as a challenge :)
• securitytube-training.net
• pentesteracademy.com