Afrikaans
Akan
Albanian
Amharic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranî)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Portuguese (Portugal)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
One of the things that would be very helpful in terms of analyzing Android applications for vulnerabilities
is the ability to D compile the application back into its source code with Java and languages that are
similar to Java that compile into a bite code that is run against virtual machine.
It's possible for us to reverse the compilation process to turn the bike code back in to something that
resembles the original source code.
Now the matching won't always be perfect.
You will do some information typically from it.
However most of the important pieces are going to still be there.
And since those pieces will be there we'll be able to not only understand what the application is doing
but actually be able to see the source code and be able to pick out specific vulnerable aspects that
we want to be able to work with.
So in this video may demonstrate how we can reverse reverse engineer essentially or compile an application.
So there's a lot of different ways that people will typically use to do this.
There are tools like API key tool and JD that will allow us to actually D compile the application and
then reverse it back into Java code.
I actually use one called GTD at JD X. And again I'll put links to these inside of a resources section
but inside of here there is essentially in the bin there's a gooey that we can launch when we launch
this we're able to actually compile any AP K that we may have on our computer so it come into our directory
here and I'm going to go grab the diva application that we installed and run this through the compiler
and what you'll see here is that we'll get a set of source code and a set of resources that are used
inside of this application.
When you're first looking at an application there's a lot of different information that's valuable to
us.
The manifest file is one that's going to be extremely useful.
It's gonna tell you a lot of different things such as the permissions that are used by the application.
It will tell you what activities exist inside the application.
It will tell you about intense.
It will tell you about things like content providers and such if they exist.
It will tell you what versions we target.
It will give you a whole plethora of high level information that will allow you to better understand
the attack surface that you're working with.
So this is one file that would be very useful for us to be able to look at resources are going to be
a lot of like the graphical interfaces and such that you're gonna be working with a lot of this really
isn't particularly useful I don't think.
Most of the time this is just sort of like you know trivial information that comes from this process.
The meta info will tell you different information.
There's some cert details that are sometimes potentially helpful as well as the manifest file which
could tell you a bit of valuable information potentially gives you a bit of a layout of some of the
things that exists inside of like the rest folder and it will allow you to get a bit of an understanding
behind like the contents of of the manifest for instance and then we also have this lib folder in this
lib folder has any sort of shared objects libraries that are used inside of the application.
These are typically written in C or C++ and compiled these can't be d compiled what we can do with these
is we can analyze like strings that may exist inside of them we might be able to break it down into
something that might be able to tell us some information about the shared library or shared object but
a lot of time these are things that we won't be able to necessarily dig into too deeply.
You'll see in a few examples we actually can go through these and gain some form of relevant information
and then finally we have our actual source code files which are the actual source of the application
itself.
If you take a look at these you'll be able to see you make each of the different pieces that goes into
building the actual application itself.
So you could pull up any of the code that actually exists and you'll be able to see exactly what code
is being used.
You can do this sort of thing with all.
I would say basically any Android application you should be able to get source code and that's it's
like heavily encrypted or obscured in some way.
This will typically be possible so a few other things that are useful for this.
We can search this for specific keywords so for instance we find an error message or something like
that that we want to look up.
We can try looking it up.
We can try looking up common things like password.
So you want to check off like what you actually a search.
You could search classes you could search methods fields code for instance and you can see here we can
sort of like pick out pieces of information that might be of interest to us.
So here's an example here where we're inserting into sequel a user username and password it seems.
So this for instance would be some information that might be able to gather from D compiling the application.
So this gives you a bit of an idea of how we can actually D compile Android applications and from here
we sort of have all the tools that we're going to need to have to be able to analyzed different applications
to be able to look at common Android vulnerabilities.
So that's what we will take a look at next.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.