Afrikaans
Akan
Albanian
Amharic
Arabic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranî)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Portuguese (Portugal)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
After creating a malicious app the next step is to copy this app to the victim.
By now this can be done in a different way.
You can share folders between Windows and Linux and copy them or you can copy uploads this app to any
free hosting or there is a different way for doing that.
And we're going to explain later on some sophisticated way.
But in my case I take a copy from the app and I copy it on the desktop.
And this is a fake because usually when you created by default it would be created inside your home
folder.
Then using Google Drive I will upload this app.
And the reason I copy it on the desktop because I notice that it will not be detected.
If you keep it on your home folder.
So here he usually point to his desktop.
This is my app and I'm going to create an open and he's going to start uploading the app.
It's a very small one so it has been uploaded successfully.
And then let's go to my computer here and let me download this app and copy it to my memory of this
is a copy and I'm going to add it to my memory card.
It can have even added to the and is not a problem.
I will create a folder
it's better to do it this way do not keep it anywhere just create a folder.
When you.
But here I can use this one folder based and now is a malicious app it's on my mobile.
Now before installing the malicious app I need to do something from the Linux machine which is installing
a handler.
And what is exactly the handler handler.
What happens when you run a malicious app from the victim machine.
He will try to connect to your Linux machine.
Now the stations that would be coming from them will by twos.
Can the Linux machine will try to reach the machine on full force.
So I have to open this port and run a listener that wouldn't wait for the app.
So we're going to do that test to be done for me at this point.
So all the steps are written in this fight to run the handler which would be used for
receiving the connection from the victim.
Once he runs this app so we're going to run MSF console as
soon and once it's up and running we can use their meters plate.
So he's a multi handler to expect a connection from the computer.
I'm going to specifies the name of the payload and there's a port and IP.
So let's wait.
It will take a few seconds until it run
ok.
Meanwhile let me activate the program
that will be used Moby's ins that allow me to connect with a computer
I have to run it from my mobile it is one
he's saying here you go.
This is just a safe time
because once we runs a hundred on the candy machine I'm going to install the app here and we're going
to see if that could be successful or not.
Kee
usually showing the identifications that I have to write in a machine 6 2 7 6 2 7 1 7 5 7 5.
It's a very easy application and I already made a lecture on how to use it.
So I shouldn't be a problem.
I think we are done.
Let's see
OK.
Now getting back to here.
Excellent.
Meet us ploy it has run.
Now we're going to need to use the exploit Monte handler.
If you go to copy and paste it here.
Excellent.
And then we need to specify it should be the same payload said payload.
Android Mr. Preter reverse TCAP so you should use the exact same payload AP
these
spelling mistakes are something it will show.
So its Android.
Mr Prater Yes.
And once Right now we need to specify the option in this period.
If you are not able to memorize you can type show options and it will show you in this specific payload
what option you need to add.
So as you can see we need to host says empty we need to put a port by the pool is 4 4 4 4.
But in our case we change it to 4 for SRI's we need to change that.
So lets do that.
So set
and host and we can ride our local IP.
Let me just make sure that we still have the same IP.
Sorry about that.
So let me trigs the IP of the machine.
If you see the same or change I can fake
it's the same thing.
So sit and host a can
equal
online to 1 6 8 8 1 8 1 0 3 and we need to change and think is should be taken
up and we need to change and porters well to keep it the same way we created in the payload report which
is for 4:43.
Now I believe nothing else is needed.
So let's explore it.
Let's go on the 100 handler by typing exploit and the handler will run.
So now as you can see he's listening and waiting for the connection.
What I'm going to do next we will go to zoom in.
And I'll try to run this app.
So I'll go to the file
should be in the file and manager.
Is it OK to sign manager and as the car it moves inside and you find a folder by the name of new folder
where is it.
Yep.
So that's just one new folder.
It should be easy to go.
And this is that and
of course you need to allow this options that unknown source.
Otherwise it will not be installed.
But later on you're going to see that we can merge this one with another app that when you
manipulate this option and cannot be detected that it's something malicious and install.
And once that happens it is installed.
Let's see what happened to our Linux machine.
So the app has been installed and in our machine we just need to give it a few seconds and let's see
what will happen.
I'm going to pause until the talk and see how it will be connected.
So once I open the application as you can see emitter Prater station has been opened between my machine
and the vector machine.
And here are Zimet operators.
And now I have full access on the image on a mobile device.
And if you need to know what can be done you just need to type help and you will see all the comments
that you can do.
You can see all the activity you can see if this device is rooted or not if it's rooted actually can
have more option.
You can see the call logs you can see a contact You can see it's a mess.
It's an unbelievable application.
Now next I'm going to show you some of those commands that can be used but actually nothing need to
be explained you just need to copy and paste the comment and you can see how to use them.
So as you can see you can open the webcam you can open the mike.
Everything can be done on that device once the app has been installed.
It's quite interesting.
And as we agree later on going to see how to tune this attack so it would be very hard to detect right
now just the basic upset.
So let's see the post attack.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.