- name
- android-mobile-security-sandbox-jamboree
- description
- JAMBOREE Android security testing framework integrating Magisk, Burp Suite, Objection, and Frida for comprehensive mobile app penetration testing
- triggers
- ["set up android security testing environment","configure jamboree framework for mobile pentesting","integrate burp suite with android emulator","bypass ssl pinning on android app","use objection to hook android methods","set up magisk for rooted testing environment","intercept android app traffic with burp","automate frida scripts for android analysis"]
# Android Mobile Security Sandbox JAMBOREE
> Skill by [ara.so](https://ara.so) — Security Skills collection
## Overview
JAMBOREE (Java Android Magisk Burp Objection Root Emulator Easy) is a unified Android security testing framework that orchestrates multiple tools into a cohesive pentesting environment. It automates the integration of:
- **Magisk modules** for systemless root and module management
- **Burp Suite proxy** for traffic interception and certificate handling
- **Objection/Frida** for runtime instrumentation and hooking
- **Rooted Android emulators** optimized for security testing
This framework eliminates fragmented workflows by providing pre-configured components that work together seamlessly for Android application security assessment.
## Installation
### Prerequisites
Ensure the following are installed:
```bash
# Java Development Kit 11+
java -version
# Android SDK with platform tools
which adb
# Python 3.8+ for Objection
python3 --version
# Frida tools
pip3 install frida-tools objection
```
### Framework Setup
```bash
# Clone the repository
git clone https://github.com/hero-mike/Android-Mobile-Security-Sandbox-Testing.git
cd Android-Mobile-Security-Sandbox-Testing
# Run the orchestration script
chmod +x orchestration/deploy.sh
./orchestration/deploy.sh
# Verify installation
./orchestration/validate.sh
```
The deployment script will:
1. Validate dependencies
2. Configure Android emulator with Magisk
3. Install Burp Suite CA certificates
4. Deploy Objection scripts and Frida gadgets
5. Set up proxy routing
## Core Components
### 1. Magisk Module Management
```bash
# Install Magisk modules
adb push modules/magisk/systemless/universal-safetynet-fix.zip /sdcard/
adb shell su -c "magisk --install-module /sdcard/universal-safetynet-fix.zip"
# List installed modules
adb shell su -c "ls /data/adb/modules"
# Enable/disable module
adb shell su -c "touch /data/adb/modules/module-name/disable"
adb reboot
# Remove module
adb shell su -c "rm -rf /data/adb/modules/module-name"
```
**Custom Module Installation:**
```bash
# Deploy custom init.d script
adb push configurations/android/custom-init.sh /data/adb/service.d/
adb shell su -c "chmod 755 /data/adb/service.d/custom-init.sh"
```
### 2. Burp Suite Integration
**Certificate Installation:**
```bash
# Export Burp CA certificate (DER format)
# In Burp: Proxy → Options → Import/Export CA certificate
# Convert to PEM and get hash
openssl x509 -inform DER -in burp-ca.der -out burp-ca.pem
CERT_HASH=$(openssl x509 -inform PEM -subject_hash_old -in burp-ca.pem | head -1)
# Install as system certificate
adb root
adb remount
adb push burp-ca.pem /system/etc/security/cacerts/${CERT_HASH}.0
adb shell chmod 644 /system/etc/security/cacerts/${CERT_HASH}.0
adb reboot
```
**Proxy Configuration:**
```bash
# Set system-wide proxy
adb shell settings put global http_proxy <HOST_IP>:8080
# Or use the provided configuration script
./orchestration/deployers/burp-proxy-setup.sh --host 192.168.1.100 --port 8080
# Verify proxy settings
adb shell settings get global http_proxy
# Clear proxy
adb shell settings put global http_proxy :0
```
**VPN-based Interception:**
```bash
# Install proxy VPN app
adb install modules/burp/proxy-vpn.apk
# Configure VPN tunnel
adb shell am start -n com.proxyvpn/.MainActivity \
--es PROXY_HOST "192.168.1.100" \
--ei PROXY_PORT 8080
```
### 3. Objection Runtime Instrumentation
**Basic Objection Usage:**
```bash
# List running apps
frida-ps -Ua
# Attach to running app
objection -g com.example.target explore
# Spawn app with Objection
objection -g com.example.target run
```
**SSL Pinning Bypass:**
```bash
# Inside Objection REPL
android sslpinning disable
# Or using custom script
objection -g com.example.target explore \
-s "android sslpinning disable" \
-s "jobs list"
```
**Common Objection Commands:**
```javascript
// List activities
android hooking list activities
// List classes
android hooking list classes
// Search for methods
android hooking search methods decrypt
// Hook specific method
android hooking watch class_method com.example.Crypto.decrypt --dump-args --dump-return
// Bypass root detection
android root disable
// List shared preferences
android file shared-preferences list
// Read specific preference
android file shared-preferences read com.example.target.prefs user_token
// SQLite operations
android sqlite list
android sqlite query /data/data/com.example.target/databases/main.db "SELECT * FROM users"
// Dump memory
memory dump all /tmp/memory-dump.bin
// Export class definitions
android hooking dump class com.example.target.MainActivity
```
**Custom Frida Scripts:**
Create `hooks/ssl-bypass.js`:
```javascript
Java.perform(function() {
console.log("[*] SSL Pinning Bypass Active");
// Hook OkHttp3 Certificate Pinner
var CertificatePinner = Java.use("okhttp3.CertificatePinner");
CertificatePinner.check.overload('java.lang.String', 'java.util.List').implementation = function() {
console.log("[+] Bypassed OkHttp3 Certificate Pinner");
};
// Hook TrustManagerImpl
var TrustManagerImpl = Java.use("com.android.org.conscrypt.TrustManagerImpl");
TrustManagerImpl.verifyChain.implementation = function(untrustedChain, trustAnchorChain, host, clientAuth, ocspData, tlsSctData) {
console.log("[+] Bypassed TrustManagerImpl verification for: " + host);
return untrustedChain;
};
// Hook SSLContext
var SSLContext = Java.use("javax.net.ssl.SSLContext");
SSLContext.init.overload('[Ljavax.net.ssl.KeyManager;', '[Ljavax.net.ssl.TrustManager;', 'java.security.SecureRandom').implementation = function(keyManager, trustManager, secureRandom) {
console.log("[+] SSLContext.init() called, accepting all certificates");
this.init.overload('[Ljavax.net.ssl.KeyManager;', '[Ljavax.net.ssl.TrustManager;', 'java.security.SecureRandom').call(this, keyManager, null, secureRandom);
};
});
```
Load custom script:
```bash
# Using Frida directly
frida -U -l hooks/ssl-bypass.js -f com.example.target
# Using Objection with custom script
objection -g com.example.target explore --startup-script hooks/ssl-bypass.js
```
**Method Hooking Template:**
```javascript
Java.perform(function() {
var TargetClass = Java.use("com.example.target.Crypto");
// Hook encryption method
TargetClass.encrypt.implementation = function(plaintext, key) {
console.log("[*] Encrypt called");
console.log("[*] Plaintext: " + plaintext);
console.log("[*] Key: " + key);
var result = this.encrypt(plaintext, key);
console.log("[*] Encrypted result: " + result);
return result;
};
// Hook with multiple overloads
TargetClass.processData.overload('java.lang.String').implementation = function(data) {
console.log("[*] processData(String) called with: " + data);
return this.processData(data);
};
TargetClass.processData.overload('[B').implementation = function(data) {
console.log("[*] processData(byte[]) called");
return this.processData(data);
};
});
```
### 4. Emulator Configuration
**Create Rooted AVD:**
```bash
# Using provided configuration
./orchestration/deployers/create-rooted-avd.sh \
--name jamboree-test \
--api 30 \
--arch x86_64
# Manual AVD creation
avdmanager create avd \
-n security-test \
-k "system-images;android-30;google_apis;x86_64" \
-d "pixel_4"
# Start emulator with writable system
emulator -avd security-test -writable-system -no-snapshot-load &
# Wait for boot
adb wait-for-device
# Install Magisk
adb install modules/magisk/Magisk-v26.1.apk
```
**Anti-Emulation Evasion:**
```bash
# Modify build properties
adb shell su -c "mount -o rw,remount /system"
adb shell su -c "echo 'ro.build.fingerprint=google/redfin/redfin:11/RQ3A.211001.001/7641976:user/release-keys' >> /system/build.prop"
adb shell su -c "echo 'ro.product.manufacturer=Google' >> /system/build.prop"
adb reboot
# Hide emulator artifacts
adb shell su -c "setprop ro.kernel.qemu 0"
adb shell su -c "setprop ro.hardware.goldfish 0"
```
## Workflow Patterns
### Complete Penetration Test Setup
```bash
#!/bin/bash
# setup-pentest.sh
TARGET_PACKAGE="com.example.target"
BURP_HOST="192.168.1.100"
BURP_PORT="8080"
echo "[*] Starting JAMBOREE penetration test environment"
# 1. Start emulator
emulator -avd jamboree-test -writable-system -no-snapshot-load &
adb wait-for-device
sleep 10
# 2. Configure proxy
adb shell settings put global http_proxy ${BURP_HOST}:${BURP_PORT}
# 3. Verify Magisk root
adb shell su -c "id" || { echo "[!] Root not available"; exit 1; }
# 4. Install target app
adb install -r target-app.apk
# 5. Start Objection with SSL bypass
objection -g ${TARGET_PACKAGE} explore \
--startup-script hooks/ssl-bypass.js &
echo "[+] Environment ready. Burp Suite should show traffic."
```
### Automated Hook Deployment
```python
# deploy_hooks.py
import frida
import sys
HOOKS = {
"crypto": """
Java.perform(function() {
var Cipher = Java.use("javax.crypto.Cipher");
Cipher.doFinal.overload('[B').implementation = function(data) {
console.log("[Cipher] doFinal called with " + data.length + " bytes");
return this.doFinal(data);
};
});
""",
"network": """
Java.perform(function() {
var URL = Java.use("java.net.URL");
URL.$init.overload('java.lang.String').implementation = function(url) {
console.log("[Network] URL requested: " + url);
return this.$init(url);
};
});
"""
}
def attach_hooks(package_name, hook_type):
device = frida.get_usb_device()
pid = device.spawn([package_name])
session = device.attach(pid)
script = session.create_script(HOOKS[hook_type])
script.on('message', lambda msg, data: print(msg))
script.load()
device.resume(pid)
print(f"[+] {hook_type} hooks attached to {package_name}")
sys.stdin.read()
if __name__ == "__main__":
attach_hooks(sys.argv[1], sys.argv[2])
```
Usage:
```bash
python3 deploy_hooks.py com.example.target crypto
```
### Traffic Analysis Workflow
```bash
# 1. Clear app data
adb shell pm clear com.example.target
# 2. Start packet capture
adb shell su -c "tcpdump -i wlan0 -w /sdcard/capture.pcap" &
# 3. Start Burp Suite listener on port 8080
# 4. Launch app with Objection
objection -g com.example.target explore \
-s "android sslpinning disable" \
-s "android root disable"
# 5. Perform actions in app
# 6. Stop capture and retrieve
adb shell su -c "killall tcpdump"
adb pull /sdcard/capture.pcap ./analysis/
```
## Configuration Files
### Burp Suite Extension Config
`configurations/burp/extension-config.json`:
```json
{
"proxy": {
"enabled": true,
"host": "0.0.0.0",
"port": 8080,
"ssl": {
"generateCert": true,
"certPath": "/certificates/burp-ca.pem"
}
},
"interceptRules": [
{
"match": ".*\\.api\\.example\\.com.*",
"action": "intercept",
"modifyHeaders": {
"User-Agent": "CustomAgent/1.0"
}
}
],
"bypassSSL": true
}
```
### Objection Startup Scripts
`configurations/objection/startup.js`:
```javascript
// Auto-load common bypasses
android sslpinning disable;
android root disable;
// Custom hooks
android hooking watch class_method com.example.target.Auth.login --dump-args --dump-return;
android hooking watch class_method com.example.target.Network.makeRequest --dump-args --dump-return;
// Monitor file operations
android hooking watch class java.io.FileOutputStream.$init --dump-args;
console.log("[JAMBOREE] Startup hooks loaded");
```
Ver no GitHub