SKILL: Android Pentesting Tricks — Expert Attack Playbook
AI LOAD INSTRUCTION: Expert Android application security testing techniques. Covers SSL pinning bypass (Frida/Objection/LSPosed), component exposure, WebView exploitation, intent redirection, root detection bypass, and Play Integrity evasion. Base models miss Frida hook specifics and multi-layer bypass chains.
Before going deep, consider loading:
Advanced Reference
Also load FRIDA_SCRIPTS.md when you need:
- Ready-to-use Frida script templates for common Android testing tasks
- Detailed hook points for OkHttp, Retrofit, Volley, WebView
- Root detection bypass script collection
1. SSL PINNING BYPASS
1.1 Frida Universal Bypass
| Hook Point | Library/Class | Coverage |
|---|
X509TrustManager.checkServerTrusted | Android SDK | All standard HTTPS |
OkHttpClient.Builder.sslSocketFactory | OkHttp 3.x/4.x | Square OkHttp |
CertificatePinner.check | OkHttp 3.x/4.x | OkHttp pinning |
HttpsURLConnection.setSSLSocketFactory | Android SDK | Legacy HTTPS |
SSLContext.init | Android SDK | Custom SSL contexts |
WebViewClient.onReceivedSslError | WebView | WebView SSL errors |
TrustManagerFactory.getTrustManagers | Android SDK | Factory-created TMs |
1.2 Objection (Quick Method)
1.3 Network Security Config (Debug Builds)
If you can modify the APK or it's a debug build:
1.4 Magisk Module Approach
| Module | Method | Scope |
|---|
| LSPosed + TrustMeAlready | Hooks system-wide TrustManager | All apps |
| LSPosed + SSLUnpinning | Targeted SSL bypass | Per-app |
| MagiskTrustUserCerts | Moves user CA to system store | All apps trusting system CAs |
| ConscryptTrustUserCerts | Patches Conscrypt | Newer Android (7+) |
2. COMPONENT EXPOSURE
2.1 Exported Activities
2.2 Content Providers
| Provider Type | Attack Vector | Impact |
|---|
| Database-backed | SQL injection via query() projection/selection | Data leak, auth bypass |
| File-backed | Path traversal via URI | Read arbitrary files |
| Parcelable | Type confusion in custom Parcelable | Code execution |
2.3 Broadcast Receivers
2.4 Exported Services
3. WEBVIEW VULNERABILITIES
3.1 JavaScript Interface RCE (Pre-API 17)
3.2 Modern WebView Attacks
| Vulnerability | Condition | Exploit |
|---|
setJavaScriptEnabled(true) + untrusted content | JS enabled + attacker controls loaded URL | XSS → bridge access |
setAllowFileAccessFromFileURLs(true) | file:// can read other file:// | Load file:///data/data/com.target/... |
setAllowUniversalAccessFromFileURLs(true) | file:// can access any origin | Exfiltrate via XHR to attacker |
loadUrl(user_controlled) | User input in loadUrl | javascript: scheme or file:// |
shouldOverrideUrlLoading bypass | Incomplete URL validation | Redirect to attacker-controlled page |
evaluateJavascript with tainted data | User data in JS execution | XSS in WebView context |
3.3 Deep Link to WebView Chain
4. INTENT REDIRECTION
Exported activity receives an Intent and starts another (internal) activity using data from the received Intent.
| Pattern | Indicator | Risk |
|---|
getParcelableExtra → startActivity | Intent-in-Intent | Start non-exported activities |
getStringExtra("url") → startActivity(Intent.ACTION_VIEW) | URL forwarding | Open arbitrary URLs |
getStringExtra("class") → Class.forName → startActivity | Dynamic class loading | Start any activity by name |
5. ROOT DETECTION BYPASS
5.1 Common Root Detection Checks
| Check | What It Detects | Frida Bypass |
|---|
su binary exists | /system/xbin/su, /sbin/su | Hook File.exists() → return false |
| Build tags contain "test-keys" | Build.TAGS | Hook Build.TAGS → return "release-keys" |
| Magisk Manager installed | Package name check | Hook PackageManager.getPackageInfo |
| Superuser.apk present | Su management app | Hook File.exists() |
| RootBeer library | Multi-check root detection | Hook all RootBeer check methods |
| SafetyNet/Play Integrity | Server-side attestation | Requires Magisk DenyList + module |
| Abnormal system properties | ro.debuggable=1, etc. | Hook SystemProperties.get |
5.2 Magisk DenyList (Previously MagiskHide)
6. PLAY INTEGRITY / SAFETYNET BYPASS
| Level | What It Checks | Bypass Difficulty |
|---|
| Basic Integrity | Not rooted, not emulator | Easy (Magisk + DenyList) |
| Device Integrity | Bootloader locked, verified boot | Hard (requires locked bootloader) |
| Strong Integrity | Hardware-backed attestation | Very hard (hardware TEE) |
Techniques:
- Magisk with Zygisk enabled + DenyList for target app
- Play Integrity Fix (PIF) Magisk module: spoofs device fingerprint
- Shamiko module: hides root from specific apps
- Custom ROM with locked bootloader (Pixel-specific tricks)
7. TAPJACKING (OVERLAY ATTACKS)
| Android Version | Protection | Bypass |
|---|
| Pre-6.0 | None | Full overlay |
| 6.0–11 | filterTouchesWhenObscured (opt-in) | Apps not using it are vulnerable |
| 12+ | Untrusted touches blocked for overlay windows | Partial overlays, timing-based |
9. ADDITIONAL TRICKS
9.1 Debuggable App Exploitation
9.2 Drozer (Component Testing Framework)
9.3 Clipboard Sniffing
10. ANDROID PENTESTING DECISION TREE