Skip to main content

jamboree-android-security-sandbox

Configure and orchestrate Android security testing environments with Magisk, Burp Suite, Objection, and rooted emulators for penetration testing.

来源信息

仓库
reason-machines/security-skills
最近来源活动
2026年7月1日 08:31
检测到的 SKILL.md 语言
英语
星标
12
分支
1

安装方式

默认使用会先检查来源的 Prompt;你也可以切换为直接命令,或下载本地副本。

检查来源文件

决定是否安装前,请先阅读 SKILL.md,以及 SkillsMP 当前展示的配套文件。

正在显示 SKILL.md

SKILL.md
来源说明 · 只读预览
name
jamboree-android-security-sandbox
description
Configure and orchestrate Android security testing environments with Magisk, Burp Suite, Objection, and rooted emulators for penetration testing.
triggers
["set up android security testing environment","configure burp suite with android emulator","use objection to hook android app","bypass android certificate pinning","set up magisk modules for testing","configure rooted android emulator for pentesting","intercept android app traffic with burp","hook android runtime with frida objection"]
# JAMBOREE Android Security Sandbox Skill > Skill by [ara.so](https://ara.so) — Security Skills collection ## Overview JAMBOREE (Java Android Magisk Burp Objection Root Emulator Easy) is a unified Android security testing framework that integrates: - **Magisk**: Systemless root and module management - **Burp Suite**: HTTPS traffic interception and analysis - **Objection**: Frida-powered runtime instrumentation - **Rooted Emulator**: Pre-configured Android Virtual Devices This skill enables AI agents to help developers configure, deploy, and use JAMBOREE for Android application security assessment, penetration testing, and reverse engineering. ## Installation ### Prerequisites Verification Before deployment, verify the environment has required dependencies: ```bash # Check Java version (JDK 11+) java -version # Verify Android SDK and platform tools adb version avdmanager list # Confirm Python 3 for Objection python3 --version # Check Burp Suite installation which burpsuite || echo "Burp Suite not found in PATH" ``` ### Core Installation Steps 1. **Clone and Initialize** ```bash git clone https://github.com/hero-mike/Android-Mobile-Security-Sandbox-Testing.git cd Android-Mobile-Security-Sandbox-Testing # Run environment validation ./orchestration/validators/check-prerequisites.sh ``` 2. **Deploy Core Components** ```bash # Phase 1: Environment validation ./orchestration/validators/validate-all.sh # Phase 2: Deploy Magisk modules ./orchestration/deployers/deploy-magisk.sh # Phase 3: Configure Burp Suite integration ./orchestration/deployers/setup-burp-proxy.sh # Phase 4: Install Objection environment ./orchestration/deployers/install-objection.sh ``` 3. **Calibrate Settings** ```bash # Customize configuration cp configurations/android/default.conf configurations/android/custom.conf nano configurations/android/custom.conf # Apply calibration ./orchestration/calibrators/apply-config.sh custom ``` ## Configuration ### Android Emulator Setup Create or modify an AVD for security testing: ```bash # List available system images avdmanager list targets # Create rooted AVD (x86_64, Android 13) avdmanager create avd \ -n jamboree-test \ -k "system-images;android-33;google_apis_playstore;x86_64" \ -d "pixel_5" \ -c 4096M # Start emulator with writable system emulator -avd jamboree-test -writable-system -no-snapshot-load & # Wait for boot adb wait-for-device adb root adb remount ``` ### Magisk Module Configuration Deploy core modules for testing: ```bash # Push Magisk Manager APK adb install modules/magisk/MagiskManager.apk # Install BusyBox module adb push modules/magisk/systemless/busybox.zip /sdcard/ adb shell magisk --install-module /sdcard/busybox.zip # Install certificate pinning bypass module adb push modules/magisk/systemless/ssl-unpinning.zip /sdcard/ adb shell magisk --install-module /sdcard/ssl-unpinning.zip # Reboot to apply adb reboot adb wait-for-device ``` ### Burp Suite Proxy Setup Configure system-wide traffic interception: ```bash # Generate and install Burp CA certificate openssl x509 -inform DER -in burp-cert.der -out burp-cert.pem CERT_HASH=$(openssl x509 -inform PEM -subject_hash_old -in burp-cert.pem | head -1) # Push to system certificate store adb root adb remount adb push burp-cert.pem /system/etc/security/cacerts/${CERT_HASH}.0 adb shell chmod 644 /system/etc/security/cacerts/${CERT_HASH}.0 # Configure proxy settings (Wi-Fi) adb shell settings put global http_proxy ${BURP_HOST}:${BURP_PORT} # Or use iptables redirection adb shell iptables -t nat -A OUTPUT -p tcp --dport 80 -j DNAT --to-destination ${BURP_HOST}:${BURP_PORT} adb shell iptables -t nat -A OUTPUT -p tcp --dport 443 -j DNAT --to-destination ${BURP_HOST}:${BURP_PORT} ``` Configuration file example (`configurations/network/burp-proxy.conf`): ```ini [proxy] host = 192.168.1.100 port = 8080 upstream_proxy = cert_path = ./modules/burp/certificates/burp-ca.pem [interception] mode = transparent dns_spoofing = true ssl_passthrough = false [filters] include_hosts = *.example.com,*.target-app.io exclude_hosts = *.google.com,*.android.com ``` ### Objection Environment Install and configure Objection with Frida: ```bash # Install Objection via pip pip3 install objection # Install Frida server on device FRIDA_VERSION=$(frida --version) wget https://github.com/frida/frida/releases/download/${FRIDA_VERSION}/frida-server-${FRIDA_VERSION}-android-x86_64.xz unxz frida-server-${FRIDA_VERSION}-android-x86_64.xz adb push frida-server-${FRIDA_VERSION}-android-x86_64 /data/local/tmp/frida-server adb shell "chmod 755 /data/local/tmp/frida-server" adb shell "/data/local/tmp/frida-server &" ``` ## Key Commands and Workflows ### Basic Application Analysis ```bash # List installed packages adb shell pm list packages | grep -i target # Get package information adb shell dumpsys package com.example.targetapp # Pull APK for static analysis adb shell pm path com.example.targetapp adb pull /data/app/~~random~~/com.example.targetapp-hash==/base.apk ``` ### Objection Runtime Hooking Launch Objection against a running app: ```bash # Spawn app with Objection objection -g com.example.targetapp explore # Or attach to running process objection -g $(adb shell pidof com.example.targetapp) explore ``` Common Objection commands in the interactive shell: ```javascript // List activities and classes android hooking list activities android hooking list classes // Search for methods android hooking search methods encrypt android hooking search classes database // Hook method and print arguments android hooking watch class_method com.example.crypto.AES.encrypt --dump-args --dump-return // Bypass root detection android root disable // Bypass SSL pinning android sslpinning disable // Explore SQLite databases sqlite connect /data/data/com.example.targetapp/databases/app.db .tables SELECT * FROM users; // Dump SharedPreferences android hooking list shared_preferences android hooking get shared_preference com.example.targetapp_preferences // Memory operations memory dump all com.example.targetapp memory search "password" --string ``` ### Advanced Frida Scripts Custom hooking scripts in `modules/objection/scripts/`: **hook-crypto.js** - Monitor cryptographic operations: ```javascript Java.perform(function() { var Cipher = Java.use('javax.crypto.Cipher'); Cipher.doFinal.overload('[B').implementation = function(input) { console.log('[Cipher.doFinal] Input length: ' + input.length); console.log('[Cipher.doFinal] Input hex: ' + bytesToHex(input)); var result = this.doFinal(input); console.log('[Cipher.doFinal] Output length: ' + result.length); console.log('[Cipher.doFinal] Output hex: ' + bytesToHex(result)); return result; }; function bytesToHex(bytes) { var hex = []; for (var i = 0; i < bytes.length && i < 32; i++) { hex.push(('0' + (bytes[i] & 0xFF).toString(16)).slice(-2)); } return hex.join(' ') + (bytes.length > 32 ? '...' : ''); } console.log('[+] Cipher.doFinal hooked'); }); ``` **bypass-root-check.js** - Defeat root detection: ```javascript Java.perform(function() { var RootDetection = Java.use('com.example.security.RootDetection'); RootDetection.isRooted.implementation = function() { console.log('[Root Detection] Bypass triggered'); return false; }; RootDetection.checkSuperUser.implementation = function() { console.log('[Root Detection] SuperUser check bypassed'); return false; }; RootDetection.checkBuildTags.implementation = function() { console.log('[Root Detection] Build tags check bypassed'); return false; }; console.log('[+] Root detection bypassed'); }); ``` Load custom scripts: ```bash # Via Objection objection -g com.example.targetapp explore -s modules/objection/scripts/hook-crypto.js # Via Frida directly frida -U -l modules/objection/scripts/bypass-root-check.js -f com.example.targetapp ``` ### Burp Suite Automation Extend Burp with Python extensions in `modules/burp/extensions/`: **auto-scanner.py** - Automated endpoint discovery: ```python from burp import IBurpExtender, IHttpListener, ITab from javax.swing import JPanel, JTextArea, JScrollPane import json class BurpExtender(IBurpExtender, IHttpListener, ITab): def registerExtenderCallbacks(self, callbacks): self._callbacks = callbacks self._helpers = callbacks.getHelpers() callbacks.setExtensionName("JAMBOREE Auto Scanner") self.endpoints = set() self.setup_ui() callbacks.registerHttpListener(self) def processHttpMessage(self, toolFlag, messageIsRequest, messageInfo): if not messageIsRequest: return request = messageInfo.getRequest() analyzedRequest = self._helpers.analyzeRequest(messageInfo) url = analyzedRequest.getUrl() endpoint = f"{url.getProtocol()}://{url.getHost()}{url.getPath()}" if endpoint not in self.endpoints: self.endpoints.add(endpoint) self.update_display() def setup_ui(self): self.panel = JPanel() self.textarea = JTextArea(20, 80) self.textarea.setEditable(False) scrollPane = JScrollPane(self.textarea) self.panel.add(scrollPane) self._callbacks.addSuiteTab(self) def update_display(self): output = "\n".join(sorted(self.endpoints)) self.textarea.setText(f"Discovered Endpoints ({len(self.endpoints)}):\n\n{output}") def getTabCaption(self): return "JAMBOREE Scanner" def getUiComponent(self): return self.panel ``` ### Traffic Analysis Workflow Complete workflow for intercepting and analyzing app traffic: ```bash # 1. Start Frida server adb shell "/data/local/tmp/frida-server &" # 2. Launch Burp Suite burpsuite --proxy-port=${BURP_PORT} & # 3. Configure device proxy adb shell settings put global http_proxy ${BURP_HOST}:${BURP_PORT} # 4. Disable SSL pinning with Objection objection -g com.example.targetapp explore <<EOF android sslpinning disable exit EOF # 5. Launch app adb shell am start -n com.example.targetapp/.MainActivity # 6. Monitor traffic in Burp and extract patterns # Burp Suite captures all HTTP/HTTPS traffic automatically # 7. Export findings # From Burp: Proxy > HTTP History > Save items ``` ## Common Patterns ### Pattern 1: API Endpoint Discovery and Analysis ```bash #!/bin/bash # discover-apis.sh PACKAGE=$1 DURATION=${2:-300} # 5 minutes default echo "[+] Starting API discovery for ${PACKAGE}" # Start network capture adb shell tcpdump -i any -w /sdcard/capture.pcap & TCPDUMP_PID=$! # Launch app with Objection hooks objection -g ${PACKAGE} explore <<EOF android hooking watch class_method okhttp3.OkHttpClient.newCall --dump-args --dump-return android hooking watch class_method retrofit2.Retrofit.create --dump-args exit EOF & # Wait for specified duration sleep ${DURATION} # Stop capture kill ${TCPDUMP_PID} adb pull /sdcard/capture.pcap ./analysis/ # Parse with tshark tshark -r ./analysis/capture.pcap -Y "http || tls" -T fields \ -e http.request.full_uri \ -e tls.handshake.extensions_server_name | sort -u > ./analysis/endpoints.txt echo "[+] Discovered $(wc -l < ./analysis/endpoints.txt) unique endpoints" cat ./analysis/endpoints.txt ``` ### Pattern 2: Database Extraction and Analysis ```bash #!/bin/bash # extract-databases.sh PACKAGE=$1 OUTPUT_DIR="./databases/${PACKAGE}" mkdir -p ${OUTPUT_DIR} # Find all SQLite databases adb shell "run-as ${PACKAGE} find /data/data/${PACKAGE} -name '*.db'" | while read DB_PATH; do DB_NAME=$(basename ${DB_PATH}) echo "[+] Extracting ${DB_NAME}" # Copy to accessible location adb shell "run-as ${PACKAGE} cp ${DB_PATH} /sdcard/${DB_NAME}" adb pull /sdcard/${DB_NAME} ${OUTPUT_DIR}/ # Analyze schema sqlite3 ${OUTPUT_DIR}/${DB_NAME} ".schema" > ${OUTPUT_DIR}/${DB_NAME}.schema.sql # Dump data sqlite3 ${OUTPUT_DIR}/${DB_NAME} ".dump" > ${OUTPUT_DIR}/${DB_NAME}.dump.sql echo "[+] ${DB_NAME}: $(sqlite3 ${OUTPUT_DIR}/${DB_NAME} 'SELECT COUNT(*) FROM sqlite_master WHERE type=\"table\"') tables" done ``` ### Pattern 3: Automated Certificate Pinning Bypass Create a persistent bypass module: ```javascript
在 GitHub 查看
这个 SKILL.md 很大,SkillsMP 这里只预览前一段内容。 在 GitHub 查看