Skip to main content

android-mobile-security-sandbox-jamboree

JAMBOREE Android security testing framework integrating Magisk, Burp Suite, Objection, and Frida for comprehensive mobile app penetration testing

Ir para a instalação

Informações da origem

Repositório
reason-machines/security-skills
Última atividade na origem
30 de junho de 2026 às 14:57
Idioma detectado do SKILL.md
inglês
Estrelas
12
Forks
1

Opções de instalação

Por padrão, está selecionado o prompt que primeiro revisa a origem. Você pode mudar para um comando direto ou baixar uma cópia local.

Revise os arquivos de origem

Leia o SKILL.md e os arquivos complementares exibidos pelo SkillsMP antes de decidir se vai instalar.

Exibindo SKILL.md

SKILL.md
Instruções da origem · Visualização somente leitura
name
android-mobile-security-sandbox-jamboree
description
JAMBOREE Android security testing framework integrating Magisk, Burp Suite, Objection, and Frida for comprehensive mobile app penetration testing
triggers
["set up android security testing environment","configure jamboree framework for mobile pentesting","integrate burp suite with android emulator","bypass ssl pinning on android app","use objection to hook android methods","set up magisk for rooted testing environment","intercept android app traffic with burp","automate frida scripts for android analysis"]
# Android Mobile Security Sandbox JAMBOREE > Skill by [ara.so](https://ara.so) — Security Skills collection ## Overview JAMBOREE (Java Android Magisk Burp Objection Root Emulator Easy) is a unified Android security testing framework that orchestrates multiple tools into a cohesive pentesting environment. It automates the integration of: - **Magisk modules** for systemless root and module management - **Burp Suite proxy** for traffic interception and certificate handling - **Objection/Frida** for runtime instrumentation and hooking - **Rooted Android emulators** optimized for security testing This framework eliminates fragmented workflows by providing pre-configured components that work together seamlessly for Android application security assessment. ## Installation ### Prerequisites Ensure the following are installed: ```bash # Java Development Kit 11+ java -version # Android SDK with platform tools which adb # Python 3.8+ for Objection python3 --version # Frida tools pip3 install frida-tools objection ``` ### Framework Setup ```bash # Clone the repository git clone https://github.com/hero-mike/Android-Mobile-Security-Sandbox-Testing.git cd Android-Mobile-Security-Sandbox-Testing # Run the orchestration script chmod +x orchestration/deploy.sh ./orchestration/deploy.sh # Verify installation ./orchestration/validate.sh ``` The deployment script will: 1. Validate dependencies 2. Configure Android emulator with Magisk 3. Install Burp Suite CA certificates 4. Deploy Objection scripts and Frida gadgets 5. Set up proxy routing ## Core Components ### 1. Magisk Module Management ```bash # Install Magisk modules adb push modules/magisk/systemless/universal-safetynet-fix.zip /sdcard/ adb shell su -c "magisk --install-module /sdcard/universal-safetynet-fix.zip" # List installed modules adb shell su -c "ls /data/adb/modules" # Enable/disable module adb shell su -c "touch /data/adb/modules/module-name/disable" adb reboot # Remove module adb shell su -c "rm -rf /data/adb/modules/module-name" ``` **Custom Module Installation:** ```bash # Deploy custom init.d script adb push configurations/android/custom-init.sh /data/adb/service.d/ adb shell su -c "chmod 755 /data/adb/service.d/custom-init.sh" ``` ### 2. Burp Suite Integration **Certificate Installation:** ```bash # Export Burp CA certificate (DER format) # In Burp: Proxy → Options → Import/Export CA certificate # Convert to PEM and get hash openssl x509 -inform DER -in burp-ca.der -out burp-ca.pem CERT_HASH=$(openssl x509 -inform PEM -subject_hash_old -in burp-ca.pem | head -1) # Install as system certificate adb root adb remount adb push burp-ca.pem /system/etc/security/cacerts/${CERT_HASH}.0 adb shell chmod 644 /system/etc/security/cacerts/${CERT_HASH}.0 adb reboot ``` **Proxy Configuration:** ```bash # Set system-wide proxy adb shell settings put global http_proxy <HOST_IP>:8080 # Or use the provided configuration script ./orchestration/deployers/burp-proxy-setup.sh --host 192.168.1.100 --port 8080 # Verify proxy settings adb shell settings get global http_proxy # Clear proxy adb shell settings put global http_proxy :0 ``` **VPN-based Interception:** ```bash # Install proxy VPN app adb install modules/burp/proxy-vpn.apk # Configure VPN tunnel adb shell am start -n com.proxyvpn/.MainActivity \ --es PROXY_HOST "192.168.1.100" \ --ei PROXY_PORT 8080 ``` ### 3. Objection Runtime Instrumentation **Basic Objection Usage:** ```bash # List running apps frida-ps -Ua # Attach to running app objection -g com.example.target explore # Spawn app with Objection objection -g com.example.target run ``` **SSL Pinning Bypass:** ```bash # Inside Objection REPL android sslpinning disable # Or using custom script objection -g com.example.target explore \ -s "android sslpinning disable" \ -s "jobs list" ``` **Common Objection Commands:** ```javascript // List activities android hooking list activities // List classes android hooking list classes // Search for methods android hooking search methods decrypt // Hook specific method android hooking watch class_method com.example.Crypto.decrypt --dump-args --dump-return // Bypass root detection android root disable // List shared preferences android file shared-preferences list // Read specific preference android file shared-preferences read com.example.target.prefs user_token // SQLite operations android sqlite list android sqlite query /data/data/com.example.target/databases/main.db "SELECT * FROM users" // Dump memory memory dump all /tmp/memory-dump.bin // Export class definitions android hooking dump class com.example.target.MainActivity ``` **Custom Frida Scripts:** Create `hooks/ssl-bypass.js`: ```javascript Java.perform(function() { console.log("[*] SSL Pinning Bypass Active"); // Hook OkHttp3 Certificate Pinner var CertificatePinner = Java.use("okhttp3.CertificatePinner"); CertificatePinner.check.overload('java.lang.String', 'java.util.List').implementation = function() { console.log("[+] Bypassed OkHttp3 Certificate Pinner"); }; // Hook TrustManagerImpl var TrustManagerImpl = Java.use("com.android.org.conscrypt.TrustManagerImpl"); TrustManagerImpl.verifyChain.implementation = function(untrustedChain, trustAnchorChain, host, clientAuth, ocspData, tlsSctData) { console.log("[+] Bypassed TrustManagerImpl verification for: " + host); return untrustedChain; }; // Hook SSLContext var SSLContext = Java.use("javax.net.ssl.SSLContext"); SSLContext.init.overload('[Ljavax.net.ssl.KeyManager;', '[Ljavax.net.ssl.TrustManager;', 'java.security.SecureRandom').implementation = function(keyManager, trustManager, secureRandom) { console.log("[+] SSLContext.init() called, accepting all certificates"); this.init.overload('[Ljavax.net.ssl.KeyManager;', '[Ljavax.net.ssl.TrustManager;', 'java.security.SecureRandom').call(this, keyManager, null, secureRandom); }; }); ``` Load custom script: ```bash # Using Frida directly frida -U -l hooks/ssl-bypass.js -f com.example.target # Using Objection with custom script objection -g com.example.target explore --startup-script hooks/ssl-bypass.js ``` **Method Hooking Template:** ```javascript Java.perform(function() { var TargetClass = Java.use("com.example.target.Crypto"); // Hook encryption method TargetClass.encrypt.implementation = function(plaintext, key) { console.log("[*] Encrypt called"); console.log("[*] Plaintext: " + plaintext); console.log("[*] Key: " + key); var result = this.encrypt(plaintext, key); console.log("[*] Encrypted result: " + result); return result; }; // Hook with multiple overloads TargetClass.processData.overload('java.lang.String').implementation = function(data) { console.log("[*] processData(String) called with: " + data); return this.processData(data); }; TargetClass.processData.overload('[B').implementation = function(data) { console.log("[*] processData(byte[]) called"); return this.processData(data); }; }); ``` ### 4. Emulator Configuration **Create Rooted AVD:** ```bash # Using provided configuration ./orchestration/deployers/create-rooted-avd.sh \ --name jamboree-test \ --api 30 \ --arch x86_64 # Manual AVD creation avdmanager create avd \ -n security-test \ -k "system-images;android-30;google_apis;x86_64" \ -d "pixel_4" # Start emulator with writable system emulator -avd security-test -writable-system -no-snapshot-load & # Wait for boot adb wait-for-device # Install Magisk adb install modules/magisk/Magisk-v26.1.apk ``` **Anti-Emulation Evasion:** ```bash # Modify build properties adb shell su -c "mount -o rw,remount /system" adb shell su -c "echo 'ro.build.fingerprint=google/redfin/redfin:11/RQ3A.211001.001/7641976:user/release-keys' >> /system/build.prop" adb shell su -c "echo 'ro.product.manufacturer=Google' >> /system/build.prop" adb reboot # Hide emulator artifacts adb shell su -c "setprop ro.kernel.qemu 0" adb shell su -c "setprop ro.hardware.goldfish 0" ``` ## Workflow Patterns ### Complete Penetration Test Setup ```bash #!/bin/bash # setup-pentest.sh TARGET_PACKAGE="com.example.target" BURP_HOST="192.168.1.100" BURP_PORT="8080" echo "[*] Starting JAMBOREE penetration test environment" # 1. Start emulator emulator -avd jamboree-test -writable-system -no-snapshot-load & adb wait-for-device sleep 10 # 2. Configure proxy adb shell settings put global http_proxy ${BURP_HOST}:${BURP_PORT} # 3. Verify Magisk root adb shell su -c "id" || { echo "[!] Root not available"; exit 1; } # 4. Install target app adb install -r target-app.apk # 5. Start Objection with SSL bypass objection -g ${TARGET_PACKAGE} explore \ --startup-script hooks/ssl-bypass.js & echo "[+] Environment ready. Burp Suite should show traffic." ``` ### Automated Hook Deployment ```python # deploy_hooks.py import frida import sys HOOKS = { "crypto": """ Java.perform(function() { var Cipher = Java.use("javax.crypto.Cipher"); Cipher.doFinal.overload('[B').implementation = function(data) { console.log("[Cipher] doFinal called with " + data.length + " bytes"); return this.doFinal(data); }; }); """, "network": """ Java.perform(function() { var URL = Java.use("java.net.URL"); URL.$init.overload('java.lang.String').implementation = function(url) { console.log("[Network] URL requested: " + url); return this.$init(url); }; }); """ } def attach_hooks(package_name, hook_type): device = frida.get_usb_device() pid = device.spawn([package_name]) session = device.attach(pid) script = session.create_script(HOOKS[hook_type]) script.on('message', lambda msg, data: print(msg)) script.load() device.resume(pid) print(f"[+] {hook_type} hooks attached to {package_name}") sys.stdin.read() if __name__ == "__main__": attach_hooks(sys.argv[1], sys.argv[2]) ``` Usage: ```bash python3 deploy_hooks.py com.example.target crypto ``` ### Traffic Analysis Workflow ```bash # 1. Clear app data adb shell pm clear com.example.target # 2. Start packet capture adb shell su -c "tcpdump -i wlan0 -w /sdcard/capture.pcap" & # 3. Start Burp Suite listener on port 8080 # 4. Launch app with Objection objection -g com.example.target explore \ -s "android sslpinning disable" \ -s "android root disable" # 5. Perform actions in app # 6. Stop capture and retrieve adb shell su -c "killall tcpdump" adb pull /sdcard/capture.pcap ./analysis/ ``` ## Configuration Files ### Burp Suite Extension Config `configurations/burp/extension-config.json`: ```json { "proxy": { "enabled": true, "host": "0.0.0.0", "port": 8080, "ssl": { "generateCert": true, "certPath": "/certificates/burp-ca.pem" } }, "interceptRules": [ { "match": ".*\\.api\\.example\\.com.*", "action": "intercept", "modifyHeaders": { "User-Agent": "CustomAgent/1.0" } } ], "bypassSSL": true } ``` ### Objection Startup Scripts `configurations/objection/startup.js`: ```javascript // Auto-load common bypasses android sslpinning disable; android root disable; // Custom hooks android hooking watch class_method com.example.target.Auth.login --dump-args --dump-return; android hooking watch class_method com.example.target.Network.makeRequest --dump-args --dump-return; // Monitor file operations android hooking watch class java.io.FileOutputStream.$init --dump-args; console.log("[JAMBOREE] Startup hooks loaded"); ```
Ver no GitHub
Este SKILL.md e muito grande, entao o SkillsMP mostra aqui apenas a primeira secao. Ver no GitHub