日韩精品一区二区三区高清_久久国产热这里只有精品8_天天做爽夜夜做爽_一本岛在免费一二三区

合肥生活安徽新聞合肥交通合肥房產生活服務合肥教育合肥招聘合肥旅游文化藝術合肥美食合肥地圖合肥社保合肥醫院企業服務合肥法律

代寫Lab05  InsecureBankv2 01程序
代寫Lab05  InsecureBankv2 01程序

時間:2025-10-22  來源:合肥網hfw.cc  作者:hfw.cc 我要糾錯


Lab05 
InsecureBankv2 01



Module Code & Title:           
Programme Code & Title:
Instructor:         
Student Name:         
Student Number:


Lab Time: dd/mm/yyyy



PLEASE BE AWARE: Do not try this lab on your personal phone. If a personal Android device is used, make a backup of the data on device.

Note: You need to submit a detailed lab report, with screenshots, to describe what you have done and what you have observed. You also need to provide explanations for the observations that are interesting or surprising. Finally, answer all questions in the lab instructions if there are any.

Task 0, Install drozer
drozer (formerly Mercury) is the leading security testing framework for Android. The website is 
https://github.com/WithSecureLabs/drozer

Option 1, install latest drozer
Follow the instructions, install it with pip
pipx install drozer

Option 2, install drozer 2.4
The latest version of drozer supports python3.x. An older version is for python 2.x. If you only have Python 2.x, please install drozer 2.4. 
Download drozer-2.4.4.win32.msi and save it in the python27 folder. Ignore the warning message. 
Go to Windows Security  Virus & threat protection, and under Virus & threat protection settings select Manage settings. Switch Real-time protection to Off. 
Double click msi to install it. When asking for python version, choose the python27.

There are two options to run drozer with python2 instead of python3:
Option 1, each time before running drozer type (use your own path for python27):
set path=C:\Python27;C:\Python27\Scripts;%path%

option 2, open drozer.bat under the directory C:\Python27\Scripts, replace python.exe to C:\python27\python.exe

Back to the cmd, navigate to C:\Python27\Scripts, type:
drozer
We should see some information. Type:
drozer console connect
We should find an error.
Install libraries.
python -m pip install service_identity

After successfully installing drozer on the PC, install drozer.apk in the Android device.
download drozer.apk from 
https://labs.withsecure.com/tools/drozer
select drozer (Agent .apk only)

Open Android Studio, turn on a device. Drag the apk to the device to install it. Do not use a higher version of Android. Drozer does not support it.

Open the Drozer in the device.

Task 1, install InsecureBankv2 and tools
Step 1, install python 2.7.x.
Download and install it.
Assuming that your Python installation is in C:\Python27\, add this to your PATH: C:\Python27\;C:\Python27\Scripts\

Step 2, install pip if you have not installed it.
In the CMD, try pip
pip -help
If it returns an error, navigate to the python directory, type:
python -m ensurepip --upgrade
run:
python -m pip install protobuf
python -m pip install pyopenssl
python -m pip install twisted

Step 3
InsecureBank is a purposely vulnerable app designed for educational purposes. It has a server and an apk.
https://github.com/dineshshetty/Android-InsecureBankv2
We need to launch the server so that the vulnerable app can connect to it, and we can start reversing.

Download InsecureBankv2.apk.  Install it in virtual device. If it says the SDK version is lower, try this:
.\adb install --bypass-low-target-sdk-block InsecureBankv2.apk
Please use your own path for InsecureBank2.apk here.

Step 4, setup AndroLab server.
The back end for the InsecureBankv2 application is a simple python server running simple Flask and CherryPy web frameworks. The server component can be found in the AndroLabServer folder in the
InsecureBankv2 project source folder.

Download AndroLab source code. Navigate to the AndroLab directory. To set up the AndroLab server, use pip to install the necessary requirements.
C:\Python27\python.exe -m pip install -r requirements.txt

step 5,
Once all the requirements were installed, run the HTTP server on the default port 8888.
C:\Python27\python.exe app.py
If you encounter an “ImportError: No module named wsgiserver”, run
C:\Python27\python.exe -m pip install wsgiserver
If you encounter an “ImportError: No module named wsgiserver” error, change “from web.wsgiserver import CherryPyWSGIServer” to
from cheroot.wsgi import Server as CherryPyWSGIServer

then run again the “app.py” file to start the server.

view the available arguments for the AndroLab server component.
python app.py –help

Step, 6
Drag InsecureBankv2.pak file onto the emulator screen.
Or we use Android Debug Bridge (ADB) to connect to the emulator and install the InsecureBankv2 APK file.
adb install InsecureBankv2.apk
Once successfully installed, the application icon appears on the emulator.

Step 7, 
Once installed, open the app.


There are pre-defined users, login with either of them.
• dinesh/Dinesh@123$ 
• jack/Jack@123$
When the correct set of credentials is entered, the click of the Login button redirects us to the next screen.

Task 2
Login Vulnerabilities: Login Bypass
There are two ways to bypass login. One is using apk tool to find target activity and run it through adb. The other one is using drozer.

Option one: apk + adb
Step 1, reverse engineering the apk file.
Navigate to the apktool and run
apktool d C:\{Your Path}\InsecureBankv2.apk

Step 2, 
Look at the AndroidManifest.xml file. There are four exported Activities.


Find the activity name “PostLogin”. Using ADB, we can call this exported activity.
adb shell am start -n com.android.insecurebankv2/com.android.insecurebankv2.PostLogin

This will bring a new Activity to us that should only be available after logging in successfully, demonstrating that the login can be bypassed entirely.




Option two: drozer
Step 1, 
Run drozer in the device. The Drozer server runs on port 31415 of your device. We need to set up a suitable port forward so that our PC can connect to a TCP socket opened by the Agent inside the emulator. By default, Drozer uses port 31415. Forwarding port 31415 on the host to port 31415 on the device.
adb forward tcp:31415 tcp:31415
then, connect drozer to the device:
.\drozer console connect
This time we should find that drozer is successfully installed and working.


Step 2,
Find package name of the InsecureBankv2 application
dz> run app.package.list -f bank

determine attack surface:
dz> run app.package.attacksurface com.android.insecurebankv2
We will find the following information:

Attack Surface:
  5 activities exported
  1 broadcast receivers exported
  1 content providers exported
  0 services exported
    is debuggable
It enumerates exported activities along with the permissions necessary to invoke them, i.e. activities that can be launched by other processes on Android device. Let’s launch it
dz> run app.activity.info -a com.android.insecurebankv2
We will find:

Package: com.android.insecurebankv2
  com.android.insecurebankv2.LoginActivity
    Permission: null
  com.android.insecurebankv2.PostLogin
    Permission: null
  com.android.insecurebankv2.DoTransfer
    Permission: null
  com.android.insecurebankv2.ViewStatement
    Permission: null
  com.android.insecurebankv2.ChangePassword
    Permission: null
There are 5 exported activities. One can guess that LoginActivity is probably the one launched when the application starts. Here we will launch PostLogin activity to see what will happen.
dz> run app.activity.start --component com.android.insecurebankv2 com.android.insecurebankv2. PostLogin
Questions:
What if we launch ChangePassword? Show your screenshot.
Can an unauthenticated person have access to the device? What can he/she do after that?

If we want to fix this, remove the highlighted line.


Task 3, Hidden Create User Button for Admins
Step 1, find the source code for the “LoginActivity”.


We will find that the login activity has a hidden button. A check is performed to determine if a resource string called “is_admin” is set to “no”. If this is true, then the “setVisibility(8)” method is used to set the button invisible without taking any space for layout purposes. 

Step 2, patch the vulnerability.
Since this is a string resource, the value we need to modify should be located under the “/res/values/” directories in the strings.xml file. Open this file and change the “is_admin” value from “no” to “yes”, then save the changes.


Step 3,
Use apktool again to rebuild the application with the now modified strings.xml file.
apktool b -f -d InsecureBankv2/
We can find the new generated apk in folder dist.

Sign it.
Find the tool zipalign and apksigner, for me they are in folder


uninstall the unaltered version of the application from the emulator before installing the new APK.
# install
adb install button_InsecureBankv2-final.apk
Once successfully installed, open the application and a new button called “Create user” appears.

Step 7,
However, looking at the source code for the “createUser()” method shows that the button does not actually allow us to create a user, so this concludes the vulnerability.


Task 4, Insecure Logging
The “DoLogin” activity produces a debug log message whenever a user attempts to login.

These logs can be dumped using logcat. The command below will show all the log messages for the application while it is running.
adb logcat | grep "$(adb shell ps | grep com.android.insecurebankv2  | awk '{print $2}')"
If we attempt to login while logcat is running, we will see a log message that shows the username and password we used to successfully login.



Examining the code carefully, we find if the username is “devadmin”, the application does not require a password.  

請加QQ:99515681  郵箱:99515681@qq.com   WX:codinghelp

掃一掃在手機打開當前頁
  • 上一篇:代寫COM682 Cloud Native Development 程序 Coursework
  • 下一篇:代寫  COMP3771 推薦系統 代寫python System Prototype
  • 無相關信息
    合肥生活資訊

    合肥圖文信息
    仿真分析咨詢外包服務-結構 / 熱 / CFD流體 / 電磁 / 光學CAE代做
    仿真分析咨詢外包服務-結構 / 熱 / CFD流體
    流體仿真外包多少錢_專業CFD分析代做_友商科技CAE仿真
    流體仿真外包多少錢_專業CFD分析代做_友商科
    CAE仿真分析代做公司 CFD流體仿真服務 管路流場仿真外包
    CAE仿真分析代做公司 CFD流體仿真服務 管路
    流體CFD仿真分析_代做咨詢服務_Fluent 仿真技術服務
    流體CFD仿真分析_代做咨詢服務_Fluent 仿真
    結構仿真分析服務_CAE代做咨詢外包_剛強度疲勞振動
    結構仿真分析服務_CAE代做咨詢外包_剛強度疲
    流體cfd仿真分析服務 7類仿真分析代做服務40個行業
    流體cfd仿真分析服務 7類仿真分析代做服務4
    超全面的拼多多電商運營技巧,多多開團助手,多多出評軟件徽y1698861
    超全面的拼多多電商運營技巧,多多開團助手
    CAE有限元仿真分析團隊,2026仿真代做咨詢服務平臺
    CAE有限元仿真分析團隊,2026仿真代做咨詢服
  • 豆包網頁版入口 Trae 目錄網 排行網

    關于我們 | 打賞支持 | 廣告服務 | 聯系我們 | 網站地圖 | 免責聲明 | 幫助中心 | 友情鏈接 |

    Copyright © 2025 hfw.cc Inc. All Rights Reserved. 合肥網 版權所有
    ICP備06013414號-3 公安備 42010502001045

    日韩精品一区二区三区高清_久久国产热这里只有精品8_天天做爽夜夜做爽_一本岛在免费一二三区

      <em id="rw4ev"></em>

        <tr id="rw4ev"></tr>

        <nav id="rw4ev"></nav>
        <strike id="rw4ev"><pre id="rw4ev"></pre></strike>
        日韩欧美999| 一区二区三区四区五区视频在线观看| 午夜国产在线| 午夜一区二区三区视频| 免费看ww视频网站入口| 久久99精品国产| 91久久久精品国产| 日韩欧美视频一区二区三区四区| 日韩欧美在线精品| 在线不卡一区二区| 日本免费看黄| 欧美日韩三级在线观看| 欧美日韩国产一二| 精品中文字幕在线播放| 91最新在线| 国产色综合网| 久久精品最新免费国产成人| 亚洲热在线观看| 亚洲最大黄色| 国产欧美日韩中文字幕| 欧美wwww| 国产123在线| 亚洲男人在线| 国产三级视频在线播放线观看| 欧美日韩在线播放一区| 不卡专区在线| 国产区高清在线| 亚洲狠狠婷婷综合久久久久图片| 国产99在线|亚洲| 欧美日韩中文国产| 亚洲一区中文字幕在线观看| 欧美日韩在线播放三区四区| 精品视频在线视频| 国产欧美日韩在线播放| 精品乱子伦一区二区| 日韩精品丝袜在线| 日韩精品视频中文在线观看| 国产黄在线观看免费观看不卡| 国产福利在线播放| 久久精品国产91精品亚洲| 亚洲天堂视频一区| 日韩精品视频网| 99亚洲视频| 亚洲福利在线看| 人人做人人澡人人爽欧美| 欧美日韩亚洲第一| 欧美 亚洲 精品 三区| 免费中文字幕日韩欧美| 国产一级在线播放| 中文字幕 亚洲一区| 91精品在线免费观看| 欧美一级免费在线观看| www高清在线视频日韩欧美| 中文字幕日韩国产| 国产高清大尺度一区二区不卡| 国产一区久久| 免费在线亚洲| 精品久久在线| 国产高清精品二区| 中文字幕精品一区二区三区在线| 国产一区不卡精品| 国产一卡2卡3卡四卡网站| 黄色国产网站在线播放| 在线三级av| 亚洲免费中文字幕| 国产在成人精品线拍偷自揄拍| 日韩三级免费观看| 一区二区三区在线免费| 国产传媒久久久| 欧美国产一级| 精品人妻一区二区三区视频| 国产亚洲污的网站| 国产一区在线观看视频| 国产成人精品综合网站| 综合激情一区| 久久麻豆视频| 视频一区二区精品的福利| 日韩精品在线免费观看| 国产乱国产乱300精品| 亚亚洲欧洲精品| 日韩国产在线不卡视频| 国产嫩草影院久久久久| 亚洲国产一区自拍| 欧美啪啪一区| 97最新国自产拍视频在线完整在线看| 日韩国产欧美三级| 日韩欧美国产成人一区二区| 日韩视频免费直播| 91精品国产丝袜白色高跟鞋| 精品日韩视频| 中文字幕五月欧美| 欧美亚洲国产日韩2020| 日韩不卡一二区| 日韩精品欧美在线| 亚洲免费福利视频| 久久精品夜夜夜夜久久| 91av久久久| 1区不卡电影| 午夜一区二区三区免费| 国产三级视频网站| 国产视频一区三区| 欧美国产一级| 国产一二三四| 欧美国产一级| 日韩午夜黄色| 二区三区中文字幕| 香蕉视频亚洲一级| 一区二区三区在线播放视频| 国产一区在线不卡| 国产95在线|亚洲| 欧美久久久网站| www.老鸭窝.com| 精品国产乱码一区二区| 国产欧美日韩中文久久| 日本免费在线视频不卡一不卡二| 国产一区在线不卡| 最近高清中文在线字幕在线观看1| 精品视频资源站| 久久久综合av| 日韩精品视频中文在线观看| 日本va欧美va精品发布| 国产免费一级| 一区二区不卡视频| 日韩在线视频精品| 国产欧美自拍一区| 欧美日韩精品综合| 精品中文字幕在线| www.久久久精品| 成年人黄国产| 最近高清中文在线字幕在线观看1| 日韩国产高清一区| 亚洲精品中文字幕乱码三区不卡| 一区二区日韩av| 中文字幕国产亚洲| 亚洲黄在线观看| 在线欧美一级视频| 91精品国产91久久久久| 欧美日韩综合高清一区二区| 91精品久久久久久久久久| 欧美 日韩 国产 在线观看| 日韩视频国产视频| 亚洲国产欧美日韩在线| 欧美日韩三级视频| 欧美中文字幕第一页| 91精品国产综合久久久久久| 二区视频在线观看| 欧美日韩精品不卡| 日韩午夜高潮| 在线一区免费| 国产在线拍偷自揄拍精品| 91精品国产综合久久久久久漫画| 亚洲国产欧美日韩精品| 久久久综合av| 精品不卡一区二区| 欧美日韩亚洲天堂| 亚洲a级在线播放观看| 久久久91精品国产| 深夜福利亚洲| 第一页在线观看| 国产不卡在线观看视频| 91久久精品网| 亚洲女人天堂a在线播放| 中文字幕日韩国产| 国产黄在线观看免费观看不卡|