Top Banner
Mobile Android Apps: Pen-Test, Malware Tri Wanda Septian COMNETS Research Group. Fasilkom UNSRI
26

Mobile Android Apps

Feb 20, 2017

Download

Documents

Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Mobile Android Apps

Mobile Android Apps: Pen-Test, MalwareTri Wanda Septian

COMNETS Research Group. Fasilkom UNSRI

Page 2: Mobile Android Apps

Siapa saya ?

Silahkan "googling" !

Page 3: Mobile Android Apps

Android Mobile Phones

sumber gambar : https://9to5google.files.wordpress.com/2015/10/android-versions.jpg?quality=82&strip=all&w=1024

Page 4: Mobile Android Apps

sumber gambar : hhttps://www.android.com/static/2016/img/devices/phones/nexus-6p/transparent/nexus-6p-02_1x.pnghttps://www.android.com/static/2016/img/devices/phones/moto-x/transparent/moto-x-03_1x.png

Page 5: Mobile Android Apps

sumber gambar : http://www.aboveandroid.com/wp-content/uploads/2015/06/Android-smart-homes-2015.jpghttp://androidboxoffice.com/media/wysiwyg/25isvhw.jpg

Smart Device

Page 6: Mobile Android Apps

sumber : http://thenextweb.com/google/2017/01/18/google-reveals-how-it-flagged-25000-android-apps-for-malware/

Page 7: Mobile Android Apps

sumber : https://www.cnet.com/news/russian-android-malware-tracked-ukrainian-military-report/

Page 8: Mobile Android Apps

sumber : https://cdn.arstechnica.net/wp-content/uploads/2016/07/hummingbad-by-country-640x424.png

10 million Android phones infected by all-powerful auto-rooting apps

Page 9: Mobile Android Apps

sumber : https://cse.google.com/cse?q=android+malware&cx=partner-pub-7983783048239650%3A3179771210#gsc.tab=0&gsc.q=android%20malware&gsc.page=1

Page 10: Mobile Android Apps

sumber : https://www.cvedetails.com/vulnerability-list/vendor_id-1224/product_id-19997/Google-Android.html

Android CVE (Common Vulnerabilities and Exposures)

Page 11: Mobile Android Apps

sumber : mr.robot s2 eps 8

Page 12: Mobile Android Apps

Mobile Pen-Test

Page 13: Mobile Android Apps

Mobile Pen-Test

sumber : https://www.owasp.org/index.php/Mobile_Top_10_2016-Top_10

Page 14: Mobile Android Apps

Mobile Pen-Test

Pen-tester analysis :

static analysis : recompile, reversing, decrypt

dynamic : apps behavior, logs, db, updates, system

Page 15: Mobile Android Apps

Mobile Pen-Test

Page 16: Mobile Android Apps

Mobile Pen-Test

Page 17: Mobile Android Apps

Mobile Pen-Test

Page 18: Mobile Android Apps

Mobile Malware(with MSF)

Page 19: Mobile Android Apps

Mobile Malware (with MSF)• create Metasploit APK

• decompile metasploit APK, apktool

• decompile original apk,apktool

• copy smali directory from metasploit to smali folder in orgina apps

• inject and invokde Metasploit project

• recompile

• sign & verify

Page 20: Mobile Android Apps

Mobile Malware (with MSF)

Page 21: Mobile Android Apps

Mobile Malware (with MSF)

Page 22: Mobile Android Apps

Mobile Malware (with MSF)

Page 23: Mobile Android Apps

Mobile Malware (with MSF)

Page 24: Mobile Android Apps

Mobile Malware (with MSF)

• Remote Client

• DDoS Attack

• Zombie Client

• Steal data user

Page 25: Mobile Android Apps
Page 26: Mobile Android Apps

Terima Kasih