โŒ

Reading view

There are new articles available, click to refresh the page.

Swapper โ€“ A Pure Regex Match/Replace Burp Extension

To get a valid session token to use with Burp Suite tools, I ended up writing a small Python extension (110 lines of code, but whoโ€™s counting?) that obtained a new session token for each request, allowing items like Intruder to work as intended. Cool, I was able to use it during the test, but I would like this to be repeatable. So, this blog is releasing Swapper, a regex pattern-based match/replace Burp Suite extension.

The post Swapper โ€“ A Pure Regex Match/Replace Burp Extension appeared first on Black Hills Information Security, Inc..

Intercepting Traffic for Mobile Applications that Bypass the System Proxy

This is a foolproof guide to intercepting traffic from mobile applications built on Flutter, which historically have been especially challenging to intercept.

The post Intercepting Traffic for Mobile Applications that Bypass the System Proxy appeared first on Black Hills Information Security, Inc..

How to Install LineageOS on Your Android Deviceย 

Hey guys, my name is Connor. I am a web developer here at BHIS who also loves hacking phones. Particularly, Android phones!ย Today, I am going to show you the basics [โ€ฆ]

The post How to Install LineageOS on Your Android Deviceย  appeared first on Black Hills Information Security, Inc..

Field Guide to the Android Manifest File

Every Android application has a โ€œmanifest.xmlโ€ file located in the root directory of the APK. (Remember APKs are just zip files.) The manifest file is like a guide to the application.

The post Field Guide to the Android Manifest File appeared first on Black Hills Information Security, Inc..

Start to Finish: Configuring an Android Phone for Pentesting

Jeff Barbi // *Guest Post Background Unless youโ€™re pentesting mobile apps consistently, itโ€™s easy for your methodologies to fall out of date. Each new version of Android brings with it [โ€ฆ]

The post Start to Finish: Configuring an Android Phone for Pentesting appeared first on Black Hills Information Security, Inc..

Embedding Meterpreter in Android APK

Joff Thyer// Mobile is everywhere these days. So many applications in our daily life are being migrated towards a cloud deployment whereby the front end technology is back to the [โ€ฆ]

The post Embedding Meterpreter in Android APK appeared first on Black Hills Information Security, Inc..

Android Dev & Penetration Testing Setup โ€“ Part 3: Installing the drozer Attack Framework

Joff Thyer // Editorโ€™s Note: ย This is part 3 of a 3 part series. ย Part 1 discussed configuring your virtual machine engine and virtual hardware emulation. ย Part 2ย covered installing Android [โ€ฆ]

The post Android Dev & Penetration Testing Setup โ€“ Part 3: Installing the drozer Attack Framework appeared first on Black Hills Information Security, Inc..

Android Dev & Penetration Testing Setup โ€“ Part 2: Installing Android Studio

Joff Thyer // Editorโ€™s Note: ย This is part 2 of a 3 part series. ย Part 1ย discussed configuring your virtual machine engine and virtual hardware emulation. ย Part 2 (this part) covers [โ€ฆ]

The post Android Dev & Penetration Testing Setup โ€“ Part 2: Installing Android Studio appeared first on Black Hills Information Security, Inc..

Android Dev & Penetration Testing Setup โ€“ Part 1

Joff Thyer // Editorโ€™s Note: ย This is part 1 of a 3 part series. ย Part 1 will discuss configuring your virtual machine engine and virtual hardware emulation. ย Part 2ย covers installing [โ€ฆ]

The post Android Dev & Penetration Testing Setup โ€“ Part 1 appeared first on Black Hills Information Security, Inc..

โŒ