AndroidTamer 5 to be launched soon based on Debian 10 (buster) to be launched today. Tamer5 is codenamed Aarush more here https://t.co/fWibyFDM1V. That also means AndroidTamer 4 is End Of Life from today. Will not be able to handle support request for it : https://t.co/PWgq7Bc8XW
Rules for Android Application Security
A collection of Semgrep rules derived from the #OWASP#MASTG for Android apps
Use the rules to scan them against decompiled APK files to find vulnerabilities #BugBounty#Pentesting
https://t.co/5SXIpxYYcF
AERoot is a command line tool that allows you to give the root privileges to any process running on the Android emulator : https://t.co/e2HDLpM5gv by @quarkslab#MobileSecurity#AndroidSecurity#redteam
Tech Talk🔼Upload
📴Tamir @tamir_zb revealed how the Android kernel (CVE-2021-1961) vulnerability was discovered & how he managed to overcome all existing security mitigations thus creating a 100% reliable exploit
🍿Enjoy the talk▶️https://t.co/vDJrabWE3w
#NullconGoa2022
I found a vulnerability that allowed me to unlock any @Google Pixel phone without knowing the passcode. This may be my most impactful bug so far.
Google fixed the issue in the November 5, 2022 security patch. Update your devices!
https://t.co/LUwSvEMF3w
In addition, starting today, all updates to existing apps that use the Google Play Billing Library must use Billing Library version 4 or newer.
Details: https://t.co/Arn1wbBELh
(Thanks to @PatelPoojan92 for the reminder)
I've posted several threads on how app archiving will work, and @AssembleDebug's videos show it works exactly as I described!
By the way, this feature is also being worked on for Android TV/Google TV.
https://t.co/nSMmY6y5bg
Here are the slides from our (@mast3root and I) talk on #Frida for Mobile app security testing at #THREATCON2022
This is a breadth first talk on Frida's capabilities on Android/iOS.
https://t.co/3PHX0HJk0V
PDF at https://t.co/zEKKEFN9Mz
Games with latent memory corruption bugs such as Among Us, Diablo Immortal and others can now be used on GrapheneOS thanks to our new per-app exploit protection compatibility mode. Uses 39-bit address space and Scudo instead of 48-bit and hardened_malloc.
https://t.co/ORp32gD9sZ
TIL that it's possible to enable fastbootd on Samsung devices by hex patching the recovery image. It's apparently already there but hidden if engineering mode isn't enabled.
MagiskOnWSA is back, albeit in a new repo that requires building it locally instead of via GitHub Actions! Many speculate its (ab)use of GitHub Actions was why the original repo was disabled.
https://t.co/452SPOvcKF
https://t.co/2IwZHC9gGI
H/T @DavidBerdik