Getting Started with Android App Testing with Genymotion

แชร์
ฝัง
  • เผยแพร่เมื่อ 29 ก.ย. 2024
  • Okay so we've done iOS so by popular demand here is Android! In this episode, I show you how to get started with android app testing by using an emulator. Using Genymotion we set up an emulator, proxy our traffic into burp and see what APIs the Yahoo Mail app is calling. Much more simple than iOS, and you don't even need an android phone! Android is still a minority when it comes to platforms to hack, so don't worry you'll still be finding those bugs that no one else can!
    Did you know this episode was sponsored by Intigriti? Sign up with my link go.intigriti.co... I'm so pleased with everyone's positive response to the Intigriti sponsorship and I'm so pleased you folks are finding bugs and even finding your first bugs! Thank you for being awesome!
    Resources
    - Genymotion: www.genymotion...
    - Using your device: / root-detection-ssl-pin...
    - What is SSL pinning: owasp.org/www-...
    - FRIDA: frida.re

ความคิดเห็น • 129

  • @wolfrevokcats7890
    @wolfrevokcats7890 7 หลายเดือนก่อน +1

    Hi Kathy, appreciate if you could make videos about Magisk, frida, objection, to bypass root detection & SSL pinning

  • @ArunKumar-sg6jf
    @ArunKumar-sg6jf 4 ปีที่แล้ว

    Are u using Android phone for this testing

    • @InsiderPhD
      @InsiderPhD  4 ปีที่แล้ว

      I'm using genymotion and android in an emulator :)

  • @khaledmohamed5564
    @khaledmohamed5564 3 หลายเดือนก่อน +1

    You are the most helpful Bug bounty content creator and I learnt a lot from you, I hope you make more videos about Android Pentesting because Web is sooooo much competitive.

  • @gyangaha109
    @gyangaha109 2 ปีที่แล้ว +1

    Can't intercept native mobile app like facebook. But able to intercept via browser. Tried SSLUnpinning with Xposed Installer but still can't intercept native facebook app traffic. Can somebody help? thanks

  • @sudosuraj
    @sudosuraj ปีที่แล้ว +1

    next : th-cam.com/video/aQGbYfalRTA/w-d-xo.html

  • @babay-mp4bq
    @babay-mp4bq 3 ปีที่แล้ว +1

    Hello,is it illegal if i use free license of genymotion for bug bounty hunting ?

    • @sandeepsingh87
      @sandeepsingh87 3 ปีที่แล้ว

      did you find the answer, is it illegal?

  • @xdmotivation
    @xdmotivation 4 ปีที่แล้ว +5

    Full respect

  • @sandeepsingh87
    @sandeepsingh87 3 ปีที่แล้ว +1

    After downloading, Genymotion is stuck at starting virtual device, does anyone have any idea how to solve it?

  • @bagasrizki973
    @bagasrizki973 4 ปีที่แล้ว +4

    Yesss mobile app hunting, thanks Katie!

  • @assanendiaye6279
    @assanendiaye6279 2 ปีที่แล้ว

    Hello guys I want to clone my phone one genymotion is that possible? Literally, I want to virtualize my phone.

  • @lukeempty3386
    @lukeempty3386 ปีที่แล้ว

    This doesn't really work anymore on more up to date android stuff. Burp certificate need to be installed in the system section and not user, this guy has a few videos you can use to set it up using android studio
    th-cam.com/video/Jg4hyZfFTdc/w-d-xo.html

  • @historymystery4915
    @historymystery4915 2 ปีที่แล้ว

    Oh god thank u so muchhh ...u saved my like u saved d world for mee u n angelll lol thankkk u so muchh hahha !!!

  • @mr.kn0w1t4ll2
    @mr.kn0w1t4ll2 4 ปีที่แล้ว +2

    Been wanting to get into android for a while now, the video really helped! Thanks a lot !!
    btw, could you also make a tutorial on how to disable ssl pinning on mobile applications ?

    • @InsiderPhD
      @InsiderPhD  4 ปีที่แล้ว

      I’ve included one in the description I don’t work physical android devices I’m afraid so I can’t include a tutorial on that! I work with iOS mainly!

  • @talishgarg1151
    @talishgarg1151 4 ปีที่แล้ว +2

    Amazing! Could you make a video on Frida too as there is very little content for that online

    • @InsiderPhD
      @InsiderPhD  4 ปีที่แล้ว +2

      For sure! I want to cover FRIDA with a focus on bug hunting which I think is really lacking in general! But I need to learn FRIDA first :)

  • @wardellcastles
    @wardellcastles 4 ปีที่แล้ว +2

    Katie.. thanks for the vid. Basic question though. Since the same APIs are used by both Web and Mobile version of an App, what's the purpose of testing APIs on a mobile emulator vs the web version of the App?

    • @InsiderPhD
      @InsiderPhD  4 ปีที่แล้ว +4

      So sometimes the mobile app uses a different API (usually to batch requests because of signal issues), also a website may not actually use an API but a mobile app has to.

    • @wardellcastles
      @wardellcastles 4 ปีที่แล้ว

      @@InsiderPhD Makes sense. I have so much to learn. You are a treasure.

    • @InsiderPhD
      @InsiderPhD  4 ปีที่แล้ว +1

      That's was a great question! I will include it in the next video!

    • @Mersal-uj5nh
      @Mersal-uj5nh 4 ปีที่แล้ว

      I was thinking the same but you asked it 💞🙏

  • @kmunikrishnareddy7471
    @kmunikrishnareddy7471 4 ปีที่แล้ว +1

    Can i use burp in my mobile phone without a pc?

    • @Log.Rhythm
      @Log.Rhythm 7 หลายเดือนก่อน

      No, but you can with Caido

  • @DEADCODE_
    @DEADCODE_ ปีที่แล้ว

    I registered by your link

  • @saranshsrivastav9743
    @saranshsrivastav9743 4 ปีที่แล้ว +1

    Thanks katie the video was amazing but I didn't understand the part in the end where you said google apps doesn't provide ssl bypass so why does yahoo have ssl bypass ? and in this way why don't other companies can do just like google so that no one can attack their application

    • @InsiderPhD
      @InsiderPhD  4 ปีที่แล้ว +2

      The emulator version has it turned off for everything but Google apps, basically. But physical devices do have SSL pinning. If you want to test a physical device you need to bypass the SSL pinning. Also, it doesn't stop people from attacking an application but helps reduce MITM attacks which tend to be more common for mobile devices, think fake "free wifi" which is actually used to find credentials.

    • @saranshsrivastav9743
      @saranshsrivastav9743 4 ปีที่แล้ว

      @@InsiderPhD got it thanks again you are amazing

  • @atNguyen-gm6cf
    @atNguyen-gm6cf 2 ปีที่แล้ว

    Cảm ơn bạn mong bạn ra nhiều video về testing android . Tôi là sinh viên an toàn thông tin đến từ Việt Nam

  • @Haidderispro
    @Haidderispro 2 ปีที่แล้ว

    I have an iPhone but can’t jailbreak it maybe because my iOS version or because it’s an iPhone 12. So thinking about doing this instead for bug hunting. Is there way to use burp with iPhone without jail breaking?

  • @abhhibirdawade9657
    @abhhibirdawade9657 4 ปีที่แล้ว +2

    Katie your amazing !!

  • @iandonohue7257
    @iandonohue7257 ปีที่แล้ว

    hey katie! thank you for your content you are really helping - i have one question - why is my google nexus 6 different from the demonstration? i have slightly different apps and cannot access - even after GApps? i had to go into network internet>internet>androidwifi> the little pencil in the top right of the box> roggle the advanced options carrot

  • @anujkumarpatel2686
    @anujkumarpatel2686 4 ปีที่แล้ว +1

    great content you are the best

  • @watchvideoswatchvideos6958
    @watchvideoswatchvideos6958 4 ปีที่แล้ว +1

    Amazing info katie, thank you so much!!

  • @Stas1983ful
    @Stas1983ful 3 ปีที่แล้ว

    I have't modify network when click to WiredSSID

  • @karthikkarthik-kf6bb
    @karthikkarthik-kf6bb 3 ปีที่แล้ว

    But the android version is 5 right?
    So some apps won't be installed for testing ...

  • @xormagic5190
    @xormagic5190 3 ปีที่แล้ว

    I have notice your gmail address is leaked in the video 13:25 ☝😀😀

    • @InsiderPhD
      @InsiderPhD  3 ปีที่แล้ว

      It’s nothing private :) just an unused email that I don’t want people to try (they won’t get a reply!)

  • @khushmanvar9038
    @khushmanvar9038 4 ปีที่แล้ว +1

    Thank you madam. These content is really helpful!

    • @InsiderPhD
      @InsiderPhD  4 ปีที่แล้ว

      Aww thank you so much, I’m glad it helped you!

  • @billapatigoutham6066
    @billapatigoutham6066 4 ปีที่แล้ว +1

    Thank you so much for sharing 👍

  • @AjayKumar-xl4jc
    @AjayKumar-xl4jc 4 ปีที่แล้ว +1

    Woow this is a another useful and interesting video thanks

    • @InsiderPhD
      @InsiderPhD  4 ปีที่แล้ว +1

      Glad you think so!

  • @cyrexplays5031
    @cyrexplays5031 4 ปีที่แล้ว

    My ooxe extension not displaying on burp suite.
    But other extensions are displaying.
    What's the problem??

  • @bugbountyvideo
    @bugbountyvideo 3 ปีที่แล้ว

    Awesome katie

  • @aryankushwaha4261
    @aryankushwaha4261 3 ปีที่แล้ว

    Love watching your videos...........!!!!!!
    💓💓💓💓💓💓💓💓💓💓💓💓

  • @nixsonblackstone7900
    @nixsonblackstone7900 4 ปีที่แล้ว +1

    You're the best katie

  • @sy-gamer9556
    @sy-gamer9556 4 ปีที่แล้ว

    hi katie wnted to ask i want to do both on ios and android bug bounty so is it necessary to have a mac for ios or an iphone is ok

  • @learningwithtom4104
    @learningwithtom4104 2 ปีที่แล้ว

    Thanks for helping getting started with Android PT. Will surely share once i find a vaild bug. Thanks once again. Keep up the good work.

  • @girishpadia6449
    @girishpadia6449 4 ปีที่แล้ว +1

    Please make a video on Frida.

    • @InsiderPhD
      @InsiderPhD  4 ปีที่แล้ว

      Definitely coming!

  • @xormagic5190
    @xormagic5190 3 ปีที่แล้ว

    Hi,
    Katie your video realy help me. Thank you for such a good contents.

  • @savirsuda
    @savirsuda 3 ปีที่แล้ว

    Thanks for this video :)

  • @igwenonso4084
    @igwenonso4084 2 ปีที่แล้ว

    just seeing this now I LOVE IT keep up the good work katie😚

  • @TomcatGoesBr
    @TomcatGoesBr 4 ปีที่แล้ว +1

    you re LEGEND !

    • @InsiderPhD
      @InsiderPhD  4 ปีที่แล้ว

      Thank you soo much!

  • @shopflicker
    @shopflicker 3 ปีที่แล้ว

    we need more video for android bug bounty

  • @_clavita
    @_clavita 3 ปีที่แล้ว

    thanks this video helped me setting my mobile env :)

  • @mehboob9324
    @mehboob9324 3 ปีที่แล้ว

    This was really help full i watched a few videos about it, but you explained it very well and now its working finally , thankss

  • @yoshi5113
    @yoshi5113 3 ปีที่แล้ว

    hi Katie, have you ever used BRIDA? I hope you can demo it on your TH-cam channel, because I think this tools will be great ..

    • @InsiderPhD
      @InsiderPhD  3 ปีที่แล้ว

      No I will definitely check it out!

  • @ggmaxx66
    @ggmaxx66 3 ปีที่แล้ว

    anyone know why you cannot configure manual proxy settings in android os ver 7.0 and above? 6.0 os instructions don't work and the manual says to open a wifi edit button which is not there. blogs have said this was changed for os 7.0 and above.

    • @ggmaxx66
      @ggmaxx66 3 ปีที่แล้ว

      here's why ==> to set manual proxy for android 0s 7 and above => hit advanced options WITHOUT entering a password. this will open the advanced options tab ( three days later ) *whew*

  • @akmutik6259
    @akmutik6259 3 ปีที่แล้ว

    That's not bypassing ssl pining
    You just installed certificate if the app encrypts the network internally you cannot intercept it through burp

    • @InsiderPhD
      @InsiderPhD  3 ปีที่แล้ว

      No it’s not :)

  • @ΑριστοςΜηλιαρεσης
    @ΑριστοςΜηλιαρεσης 3 ปีที่แล้ว

    Genymotion is not free, isn't there some free alternative?

    • @InsiderPhD
      @InsiderPhD  3 ปีที่แล้ว +1

      You can use another emulator, or a physical device. Genymotion is free for personal use

    • @mackeman1356
      @mackeman1356 ปีที่แล้ว

      its network feature is now for licensed only
      @@InsiderPhD

  • @James-mb5xt
    @James-mb5xt 3 ปีที่แล้ว

    Hey !! What about SSL Pinning ?? Any idea about this ?? I lost my whole damn week but didnt find any solution to intercept APPLICATION traffic ..

    • @InsiderPhD
      @InsiderPhD  3 ปีที่แล้ว

      SSL pinning is definitely an issue, I’m sorry I didn’t cover it, I’ll update this video ASAP :)

    • @James-mb5xt
      @James-mb5xt 3 ปีที่แล้ว

      @@InsiderPhD Please

  • @albonycal
    @albonycal 4 ปีที่แล้ว +1

    Yes!! New video 🎉

  • @anujkumarpatel2686
    @anujkumarpatel2686 4 ปีที่แล้ว

    katie you are awesome

  • @asadmehar3632
    @asadmehar3632 3 ปีที่แล้ว

    Please make more videos into Android bug hunting

    • @InsiderPhD
      @InsiderPhD  3 ปีที่แล้ว

      FRIDA is coming next!

  • @chad4634
    @chad4634 3 ปีที่แล้ว

    Thx Zo Usefull

  • @kentslaves
    @kentslaves 4 ปีที่แล้ว +1

    Useful and entertaining, Katie! Keep it up! 😍

    • @InsiderPhD
      @InsiderPhD  4 ปีที่แล้ว

      Thank you so much!!

  • @AmitChauhan-sp1cw
    @AmitChauhan-sp1cw 4 ปีที่แล้ว

    Can I use physical device ? Will it make some difference

    • @InsiderPhD
      @InsiderPhD  4 ปีที่แล้ว +1

      I included instructions for a physical device in the description it’s a little harder to get setup as you need to disable ssl pinning

  • @Mrr_Ball
    @Mrr_Ball 4 ปีที่แล้ว

    Where is time stamps

  • @rahul.mishr411
    @rahul.mishr411 4 ปีที่แล้ว

    Thank you for amazing lectures.

  • @MRIDULSG
    @MRIDULSG 4 ปีที่แล้ว

    If you want to work with frida then I recommend using Runtime Mobile Security Framework which has a webui to run scripts and easy to setup

    • @InsiderPhD
      @InsiderPhD  4 ปีที่แล้ว

      Thanks for the tip!

  • @James-dt6xv
    @James-dt6xv 3 ปีที่แล้ว

    hi katie
    first of all a big thanks for your great videos, I've learned a lot from them :)
    but sadly I have a problem with setting up the burp to intercept the apps data :(
    I first tried to use genymotion but it didn't work because it just fails while installing Gapps so I used memu instead then installed the burp cert and it captures data while using browser but for apps it just returns TLS errors in dashboard (the client failed to negotiate a TLS connection to ...)
    I don't know what to do, please help me I really want to start android hacking :(

    • @erickguzman1406
      @erickguzman1406 2 ปีที่แล้ว

      Already tried with another device on Genymotion?

  • @jakariaislamshanto1217
    @jakariaislamshanto1217 4 ปีที่แล้ว +1

    Man you are getting better .

    • @InsiderPhD
      @InsiderPhD  4 ปีที่แล้ว +1

      Thank you for this comment :) I'm trying new things with my content and trying to push myself out of my comfort zone so it means a lot to know my improvement is noted!

    • @AjayKumar-xl4jc
      @AjayKumar-xl4jc 4 ปีที่แล้ว

      No man she is girl

    • @jakariaislamshanto1217
      @jakariaislamshanto1217 4 ปีที่แล้ว

      @@AjayKumar-xl4jcMan : a member of the species Homo sapiens or all the members of this species collectively, without regard to sex:

  • @mageshsal1015
    @mageshsal1015 3 ปีที่แล้ว

    Wow cool, tysm ❤️❤️

  • @anujkumarpatel2686
    @anujkumarpatel2686 4 ปีที่แล้ว

    can please anyone explain what is an endpoint i am kinda confuse

    • @InsiderPhD
      @InsiderPhD  4 ปีที่แล้ว

      Endpoint is just a URL which exists, so www.youtube.com is an endpoint but www.youtube.com/watch isn't cause it redirects to the home screen cause it doesn't exist

    • @anujkumarpatel2686
      @anujkumarpatel2686 4 ปีที่แล้ว

      @@InsiderPhD thanks katie much love to you

  • @AkashwithUS
    @AkashwithUS 4 ปีที่แล้ว

    Mam
    How go fetch newly added subdomains in a particular program !!!!

    • @InsiderPhD
      @InsiderPhD  4 ปีที่แล้ว +2

      Coming in 2 weeks going to go over subdomain enum + amass :D

    • @InsiderPhD
      @InsiderPhD  4 ปีที่แล้ว +1

      2 months* sorry!

    • @AkashwithUS
      @AkashwithUS 4 ปีที่แล้ว

      @@InsiderPhD Thanks for you reply ♥️
      Sublist3r vs knockpy vs chaospy vs subjack vs HostileSubBruteforcer

    • @AkashwithUS
      @AkashwithUS 4 ปีที่แล้ว

      @@InsiderPhD it's ok mam
      Quality contents take time☺️🤞

  • @joshgordon7299
    @joshgordon7299 4 ปีที่แล้ว

    You're awesome

  • @DictionaryMath5903
    @DictionaryMath5903 3 ปีที่แล้ว

    Just discovered your channel. Love your work! I'm about to sign up but I just want to clarify - are you tied to a single bug bounty platform? Just asking because from what I understand, different platforms can cater to different regions/industries.

    • @InsiderPhD
      @InsiderPhD  3 ปีที่แล้ว +1

      Nope you can hunt on any platform I’m on Bugcrowd, HackerOne and Intigriti

    • @DictionaryMath5903
      @DictionaryMath5903 3 ปีที่แล้ว

      @@InsiderPhD that's great. thank you!

  • @danielmaina4817
    @danielmaina4817 4 ปีที่แล้ว

    U explain things so well .wish u were my lecturer 😅😅

    • @InsiderPhD
      @InsiderPhD  4 ปีที่แล้ว +1

      I am your online lecturer! :D

    • @danielmaina4817
      @danielmaina4817 4 ปีที่แล้ว

      @@InsiderPhD very true .. you videos help me to my first bug.. though it was duplicate...
      U do great work

    • @InsiderPhD
      @InsiderPhD  4 ปีที่แล้ว +1

      That's AWESOME congrats! Finding your first bug means you got the skills to find bugs 100%, but you just weren't quick enough this time, but you'll get much quicker as you learn more!

    • @danielmaina4817
      @danielmaina4817 4 ปีที่แล้ว

      @@InsiderPhD thanks alot...

  • @RAVIJATAV007
    @RAVIJATAV007 4 ปีที่แล้ว

    🦋

  • @learnlylearnaboutmanything7112
    @learnlylearnaboutmanything7112 4 ปีที่แล้ว

    Excellent explaination 😃😃

    • @InsiderPhD
      @InsiderPhD  4 ปีที่แล้ว +1

      Thank you! 😃 I hope you learn many things :)

    • @learnlylearnaboutmanything7112
      @learnlylearnaboutmanything7112 4 ปีที่แล้ว

      @@InsiderPhD yep I did , looking forward for next video 😃😄

  • @himanshu4316
    @himanshu4316 4 ปีที่แล้ว

    Thank you!! Good intro video on android PT.

    • @InsiderPhD
      @InsiderPhD  4 ปีที่แล้ว +2

      Aww thank you! I'm definitely going to cover some more stuff like RE and Frida for both Android + iOS later on

    • @himanshu4316
      @himanshu4316 4 ปีที่แล้ว

      Oh yes!! I'm eagerly waiting for that.. I started my career in PT majorly on Android PT. Currently in Incident Response field.. Was looking to start BB in Android field since not many do it as you mentioned. .. This video refreshed my good ol memories!!! Cheers..

    • @InsiderPhD
      @InsiderPhD  4 ปีที่แล้ว +1

      Nice! Android bb is a great place at the moment, lots of resources available but still few people hacking, there's a ton of low hanging fruit in android apps!