Lab Setup
Lab Setup
https://t.me/CyberBankSa
Android Userland Fuzzing and Exploitation
Lab Setup Guide
Lab Setup Outline
• Lesson 1: Slack Channel Setup
• Lesson 2: Install Vbox and Vbox Addition Package
• Lesson 3: Import Ubuntu/Fuzzing VM
• Lesson 4: Installing Android Studio
• Lesson 5: Installing NDK
• Lesson 6: Import ”Vulnerable Project” in Android Studio
• Lesson 7: Download and run ARM Android VM
• Lesson 8: Connect to phone from Ubuntu VM
• Lesson 9: Corellium Lab Setup
Lesson 1: Slack Channel Setup
• Use the Invite link to join the AFE slack channel
• https://join.slack.com/t/afe-blackhat/shared_invite/zt-sdgejmeb-
u00JdotXANepB~4GFH~4lw
Lesson 1: Slack Channel Setup
• Join the AFE channel either with your Gmail, Apple, or another email
account
Lesson 1: Slack Channel Setup
• Once you have joined the slack channel group, you can find multiple channels
on the left panel.
• https://www.virtualbox.org/wiki/Downloads
• https://developer.android.com/studio
• Click next
Lesson 7: Download and run ARM Android VM
• Select the correct image
▫ Nougat
▫ API Level 25
▫ Armabi-v7a
▫ Android 7.1.1
• Click “Download”
• Click next after download
Lesson 7: Download and run ARM Android VM
• Running the VM is easy, click the play button in
the ribbon
• https://sourceforge.net/projects/unix-
utils/files/socat/1.7.3.2/socat-1.7.3.2-1-
i686.zip/download
NOTE: This step is only required if you use Windows as your base machine!
Lesson 8: ADB connection forward for Windows
NOTE: This step is only required if you use Windows as your base machine!
Lesson 8: ADB connection forward
• Open you VirtualBox VM
• In the Ubuntu VM open a terminal
• Connect to you host adb from the VM by
typing the following command
• https://drive.google.com/file/d/19QLHCRnMh
16AnJcmM_iYQW87xIgh9bPa/view?usp=shari
ng
• Go to /data/local/tmp
• There we have our gdbserver
• Make it executable with chmod
• “chmod +x gdbserver”
https://afe.enterprise.corellium.com/login