{"id":13843303,"url":"https://github.com/zsdlove/ApkVulCheck","last_synced_at":"2025-07-11T18:31:34.575Z","repository":{"id":49365057,"uuid":"139135887","full_name":"zsdlove/ApkVulCheck","owner":"zsdlove","description":"This is a tool to help androidcoder to check the flaws in their projects.","archived":false,"fork":false,"pushed_at":"2024-04-11T05:21:34.000Z","size":2934,"stargazers_count":252,"open_issues_count":3,"forks_count":86,"subscribers_count":8,"default_branch":"master","last_synced_at":"2024-11-21T14:38:59.205Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/zsdlove.png","metadata":{"files":{"readme":"readme.txt","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2018-06-29T10:23:55.000Z","updated_at":"2024-08-26T06:54:59.000Z","dependencies_parsed_at":"2024-11-28T04:45:34.786Z","dependency_job_id":null,"html_url":"https://github.com/zsdlove/ApkVulCheck","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/zsdlove/ApkVulCheck","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/zsdlove%2FApkVulCheck","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/zsdlove%2FApkVulCheck/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/zsdlove%2FApkVulCheck/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/zsdlove%2FApkVulCheck/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/zsdlove","download_url":"https://codeload.github.com/zsdlove/ApkVulCheck/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/zsdlove%2FApkVulCheck/sbom","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":264870249,"owners_count":23676189,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-04T17:01:59.053Z","updated_at":"2025-07-11T18:31:33.961Z","avatar_url":"https://github.com/zsdlove.png","language":"Python","funding_links":[],"categories":["Python (1887)","Python"],"sub_categories":[],"readme":"安卓漏洞扫描工具简介\n0x1目前支持的漏洞类型：\n1、任意文件读写漏洞\n2、密钥硬编码漏洞\n3、强制类型转换本地拒绝服务漏洞\n4、系统组件本地拒绝服务漏洞\n5、Intent Schema URL漏洞\n6、Content Provider组件本地SQL注入漏洞\n7、代码动态加载安全检测\n8、证书弱校验\n9、主机名弱校验\n10、HTTPS敏感数据劫持漏洞\n11、Hash算法不安全\n12、AES弱加密\n13、Locat泄露隐私信息\n14、日志泄漏风险\n15、PendingIntent误用风险\n16、Intent隐式调用\n17、数据库文件任意读写\n18、WebView系统隐藏接口漏洞检测\n19、WebView组件远程代码执行漏洞检测\n20、WebView忽略SSL证书错误检测\n21、WebView明文存储密码\n22、SharedPreferences任意读写\n23、任意文件读写\n24、随机数使用不安全\n25、组件权限检查\n26、应用是否可调式检查\n27、应用权限检查\n28、应用自定义权限检查\n30、应用备份漏洞检查\n31、顺网恶意sdk检测\n其他:恶意sdk\u0026广告sdk等。\n0x2 使用方法：\n\n命令行参数：\nargs:\n\t--taskpath [apkpath]\n\t--output json/html\n\nexamples:\n\tpython AndroidCodeCheck.py --taskpath [path to apk] --output json\n\n0x3 报告输出\n报告输出路径在report下\n1、json格式\n结果以json格式输出，方便和其他的系统集成。\n2、html格式\n请使用浏览器查看。\n\n0x4 更新说明\n\n2020/7/18\n支持了一下python3，调整了下项目结构.\n\n2019/3/14更新说明\n支持顺网恶意sdk检测，如需检测apk中是否使用了顺网恶意sdk，请及时更新规则库。\n\n2018/8/2更新说明\n增加了对应用是否可调式的判断\n2018/8/2更新说明\n增加了对应用加固类型识别的插件\n现在支持的识别厂商有：\n娜迦\n娜迦企业版\n爱加密\n爱加密企业版\n梆梆免费版\n360\n通付盾\n网秦\n百度\n阿里聚安全\n腾讯\n腾讯御安全\n网易易盾\nAPKProtect\n几维安全\n顶像科技\n盛大\n瑞星\n\n2018/8/1更新说明\n增加了对manifest.xml文件的解析，据此获得apk文件的一些信息，包括：\n1、包名信息\n2、申请的权限信息\n3、自定义的权限信息\n4、组件信息，包括四大组件（activity，service，receiver，provider）\n漏洞判断主要增加了：\n1、针对activity，service，receiver，provider四大组件的导出属性进行判断\n2、增加了备份漏洞的判断\n\n如果你有什么建议愿意交流一下，请联系我：\nqq:747289639\nemail:747289639@qq.com\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fzsdlove%2FApkVulCheck","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fzsdlove%2FApkVulCheck","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fzsdlove%2FApkVulCheck/lists"}