Ecosyste.ms: Awesome

An open API service indexing awesome lists of open source software.

Awesome Lists | Featured Topics | Projects

https://github.com/WindXaa/Android-Vulnerability-Mining

Android APP漏洞之战系列,主要讲述如何快速挖掘APP漏洞
https://github.com/WindXaa/Android-Vulnerability-Mining

android vulnerable-mining

Last synced: about 1 month ago
JSON representation

Android APP漏洞之战系列,主要讲述如何快速挖掘APP漏洞

Awesome Lists containing this project

README

        

# Android Vulnerability Mining
> 本文整理了Android APP 漏洞挖掘学习的帖子,主要为Android APP漏洞之战,相关附件存放在知识星球:安全后厨

===========================================================

# 《Android APP漏洞之战系列》

## (1)工具篇

- [01.Android APP漏洞挖掘三板斧——drozer+Inspeckage(Xposed)+MobSF](https://bbs.pediy.com/thread-269196.htm)
- [02.Android APP漏洞之战(0)——打造Windows端Android安全工具包](https://mp.weixin.qq.com/s/-HrAwWqPdMQZZ8VYcvsukw)
- [03.Android APP漏洞之战(15)——非root环境下的hook、抓包、脱壳](https://bbs.pediy.com/thread-275552.htm)
- [04.Android APP漏洞之战(16)——新漏洞挖掘工具三件套](https://mp.weixin.qq.com/s?__biz=MzI3MDQ1NDE2OA==&mid=2247487564&idx=1&sn=ba311de5fa67cc99de8885f7dc8d2de3&chksm=ead18cbbdda605ad34e32a9ef7ff45a64e89dbe5aa54118d4588d11e82465607e6b5fea91f4f&token=318214511&lang=zh_CN#rd)

## (2)技巧篇

- [01.Android APP漏洞之战(10)——调试与反调试详解](https://bbs.pediy.com/thread-272452.htm)
- [02.Android 常用Hook技术方案详解](https://bbs.pediy.com/thread-272870.htm)
- [03.Android APP漏洞之战(11)——整体壳脱壳技巧详解](https://bbs.pediy.com/thread-273293.htm)
- [04.Android APP漏洞之战(14)——Ollvm混淆与反混淆](https://mp.weixin.qq.com/s/lcyIakgOcNQaFBn5bfnwrg)

## (3)基础篇————四大组件漏洞篇

- [01.Android APP漏洞之战(1)——Activity漏洞挖掘详解](https://bbs.pediy.com/thread-269211.htm)
- [02.Android APP漏洞之战(2)——Service漏洞挖掘详解](https://bbs.pediy.com/thread-269255.htm)
- [03.Android APP漏洞之战(3)——Broadcast Recevier漏洞详解 ](https://bbs.pediy.com/thread-269309.htm)
- [04.Android APP漏洞之战(4)——Content Provider漏洞详解](https://bbs.pediy.com/thread-269447.htm)

## (4)进阶篇1————基本配置漏洞篇

- [01.Android APP漏洞之战(5)——权限安全和安全配置漏洞详解](https://bbs.pediy.com/thread-269988.htm)
- [02.Android APP漏洞之战(7)——信息泄露漏洞详解](https://bbs.pediy.com/thread-271122.htm)

## (5)进阶篇2————网络漏洞挖掘篇

- [01.Android协议分析(四)——Http/Https中间人攻击APP升级劫持漏洞:解析CNVD-2021-40179和CNVD-2021-45684](https://bbs.pediy.com/thread-268464.htm)
- [02.Android APP漏洞之战(6)——HTTP/HTTPs通信漏洞详解](https://bbs.pediy.com/thread-270634.htm)
- [03.Android APP漏洞之战(9)——验证码漏洞挖掘详解 ](https://bbs.pediy.com/thread-272270.htm)

## (6)进阶篇3————SQL、XSS、文件上传漏洞篇
- [01.Android 漏洞之战(12)————Sql漏洞初探](https://bbs.pediy.com/thread-273613.htm)

## (7)进阶篇3————APP重大漏洞分析篇

- [01.Android APP漏洞之战(8)——插件化漏洞和解压缩漏洞详解](https://bbs.pediy.com/user-home-905443.htm)
- [02.Android APP漏洞之战(13)——Webview漏洞详解](https://bbs.pediy.com/thread-273867.htm)

## 未完待续

===========================================================

## 相关附件,存放在知识星球,欢迎加入知识星球——安全后厨

考虑加群的广告号太多,需要加微信群朋友,加小编微信,回复:安全后厨

![640](https://tva3.sinaimg.cn/wap360/006jP03Oly1h7zufjtez2j30tu14fjur.jpg)