Afrikaans
Akan
Albanian
Amharic
Arabic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
Frisian
Ga
Galician
Georgian
German
Guarani
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranรฎ)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Portuguese (Portugal)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
In this lecture I'm going to start with the first step which is creating a malicious Android and convinces
a victim to install it on his Android devices.
And once he installs the app on the device we're going to have access on these devices.
Now this will be done on phases so I'm going to show you how that can be done.
How can you get full access on the device.
We can shred the logs or contact the open can open so my full.
Excellent advice then I'm going to show you how to tune that.
How can you change Zeichen should become or change the app so it will be merged as a regular app.
How to convince the victim easily to install that.
So we're going to do that on faces now before we start.
I just want to let you know that many people do not consider to install anti-virus on of MacGuire or
on their tablet.
They only install that on the computers which is completely wrong because as you can see during this
section going to many attacks how easy it is compliance even if you have an antivirus installed on the
victim machine.
Still it can be bypassed.
So let's see.
So the first they were going to go to the next machine.
And before you stop we need to make sure that clinics are all the same that this actually is a primary
attack on the first I think I'm going to show you how to compromise.
More buy ins is on the senator.
Later on we're going to see how to compromise.
So as I explained this would be Choom and nothing would be related to that.
It's all network sitting.
So first let's see how to do that in a simple way then we're going to need to make it very very realistic
before starting that think I need to do the following.
I need to go to the sitting manager and say of my virtual machine and I need to make sure that the network
adapter it's on the senator.
It's you have to select Bridgett by default.
That virtual machine has in that setting.
But in this case you can use Bridgett and to make sure that we are on the same network.
We are going to open the terminal and check the IP of my Linux machine config which is 1 and 2 and 6
is that one that one's will see and I can check my MacGuire this way.
If you don't know how to to the setting up some wire and check IP you can install an app that is a nice
school Id like this one it's a free app.
Click on it.
It will show you your public IP and your private bank.
So in our case our private IPs 1 and 2 and 6 1 1 0 4 which is on the Senate or both of them are starting
with one and two and six is that window.
And then one those three and four that we need to create the figure and add to that think they know
it's a malicious code that will be executed on the victims.
I would also comment on that fine.
I will attach this file to the lectures we don't have to worry about memorizing the company.
We just go write it down together.
You can copy and paste but let's write it down to explaining why we are writing them.
So first comer is a massive venom and this is creating a B minus speed to create the payload and then
we're going to type the name of the Android right.
Slash metor writer slash read verse on those.
Or GCP now saying I already explained that it's a split second verse GCP means that the victim will
be connected to my machine and this will bypass your router firewall.
Any security setting because the connection will be reversed.
Well if you connect opposite which is binding connection most probably it's not very effective and the
security will drop the connection so the reverse disappears is much more effective Zometa.
It is a very very powerful payload that will give you full access on a mobile device that I need to
put the payload setting.
I mean I write down the speed at which machines are right here and host could be kept that it's Linux
it's consensus.
And then you can put the IP of your local machine can Linux machine which is 1 9 2 1 6 8 2 1 2 1 0 see.
So so sorry no no please.
So let me repeat it as if we know dumb.
My NSP is an android
maker
and really is that is all GCP and the host and Ikorodu going to put their local IP which is 1 9 2 2
1 6 the victim might be our idea because most probably would not be aware of spectrum might be but wonder
of wonders.
So no Calpol is any connection need to be done through a specific board.
I can put any port.
It's better to use any higher than 1024 but is a port 443 which is should be a spoof.
And this is because if someone is scanning the system and finds that the victim is connected to a device
put forth we suspect that this is a hack device or that his device has been hacked because this is a
regular port that anyone can connect to is related to actually a service that are greater than 3000
in Linux mean whatever output of that array directed to somewhere and I'm gonna lightening up the app.
I'm going to name it.
But you can name whatever you want.
Game anything you want and click on it.
Now this is a basic way it will be working in many most of the bars.
But you can even make it more enhanced You can encoded or encrypted the anti-virus will not detected.
The victim has an anti-virus from his wife.
You can see that there is a lot of things that can be done to make this application very hard to detect.
We can even begin to think later on in the section how to merge this application with one regular order.
Normally zapping picture has been created.
And he's saying that you know it can be encrypted it can be and this is the size and where it will be
safe to be saved and hopefully if you go here to the file manager and go to your home you should find
it took a picture.
So this is the first phase.
Second.
Let's go to our mobile device.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.