{"id":410310,"date":"2024-06-29T21:18:27","date_gmt":"2024-06-29T21:18:27","guid":{"rendered":"http:\/\/savepearlharbor.com\/?p=410310"},"modified":"-0001-11-30T00:00:00","modified_gmt":"-0001-11-29T21:00:00","slug":"","status":"publish","type":"post","link":"https:\/\/savepearlharbor.com\/?p=410310","title":{"rendered":"<span>\u041f\u043e\u0434\u0431\u043e\u0440\u043a\u0430 \u043c\u0430\u0442\u0435\u0440\u0438\u0430\u043b\u043e\u0432 \u043f\u043e \u043c\u043e\u0431\u0438\u043b\u044c\u043d\u043e\u0439 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u00abAwesome Mobile Security\u00bb<\/span>"},"content":{"rendered":"<div><!--[--><!--]--><\/div>\n<div id=\"post-content-body\">\n<div>\n<div class=\"article-formatted-body article-formatted-body article-formatted-body_version-2\">\n<div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\">\n<p>\u041f\u0440\u0438\u0432\u0435\u0442, \u0425\u0430\u0431\u0440!<\/p>\n<p>\u041c\u0435\u043d\u044f \u0437\u043e\u0432\u0443\u0442 \u042e\u0440\u0438\u0439 \u0428\u0430\u0431\u0430\u043b\u0438\u043d, \u044f \u043e\u0434\u0438\u043d \u0438\u0437 \u043e\u0441\u043d\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 &#171;\u0421\u0442\u0438\u043d\u0433\u0440\u0435\u0439 \u0422\u0435\u0445\u043d\u043e\u043b\u043e\u0434\u0436\u0438\u0437&#187; (\u0432\u0445\u043e\u0434\u0438\u0442 \u0432 \u0433\u0440\u0443\u043f\u043f\u0443 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0439 Swordfish Security), \u043c\u044b \u0440\u0430\u0437\u0440\u0430\u0431\u0430\u0442\u044b\u0432\u0430\u0435\u043c \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u0443 \u0430\u043d\u0430\u043b\u0438\u0437\u0430 \u0437\u0430\u0449\u0438\u0449\u0435\u043d\u043d\u043e\u0441\u0442\u0438 \u043c\u043e\u0431\u0438\u043b\u044c\u043d\u044b\u0445 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439 iOS \u0438 Android. <\/p>\n<p>\u041f\u043e \u0434\u043e\u043b\u0433\u0443 \u0441\u043b\u0443\u0436\u0431\u044b \u043c\u044b \u043f\u043e\u0434\u043f\u0438\u0441\u0430\u043d\u044b \u043d\u0430 \u0431\u043e\u043b\u044c\u0448\u043e\u0435 \u043a\u043e\u043b\u0438\u0447\u0435\u0441\u0442\u0432\u043e \u0440\u0435\u0441\u0443\u0440\u0441\u043e\u0432 \u0438 \u043f\u0440\u043e\u0440\u0430\u0431\u0430\u0442\u044b\u0432\u0430\u0435\u043c \u0432\u0441\u0435 \u0441\u0442\u0430\u0442\u044c\u0438 \u0438 \u043c\u0430\u0442\u0435\u0440\u0438\u0430\u043b\u044b, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043e\u0442\u043d\u043e\u0441\u044f\u0442\u0441\u044f \u043a \u0442\u0435\u043c\u0435 \u043c\u043e\u0431\u0438\u043b\u044c\u043d\u043e\u0439 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438. \u0421\u0430\u043c\u044b\u043c \u0433\u043b\u0430\u0432\u043d\u044b\u043c \u0438 \u0438\u043d\u0442\u0435\u0440\u0435\u0441\u043d\u044b\u043c \u043c\u044b \u0445\u043e\u0442\u0438\u043c \u043f\u043e\u0434\u0435\u043b\u0438\u0442\u044c\u0441\u044f \u0441 \u0432\u0430\u043c\u0438. \u041c\u0430\u0442\u0435\u0440\u0438\u0430\u043b \u0431\u0443\u0434\u0435\u0442 \u043f\u043e\u043b\u0435\u0437\u0435\u043d \u0432\u0441\u0435\u043c, \u043a\u0442\u043e \u0441\u043b\u0435\u0434\u0438\u0442 \u0437\u0430 \u043f\u043e\u044f\u0432\u043b\u0435\u043d\u0438\u0435\u043c \u043d\u043e\u0432\u043e\u0439 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u0438 \u043e \u0441\u043f\u043e\u0441\u043e\u0431\u0430\u0445 \u043f\u043e\u0438\u0441\u043a\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u043e \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u043a\u0435 \u043d\u043e\u0432\u044b\u0445 \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u043e\u0432, \u0438 \u0432 \u0446\u0435\u043b\u043e\u043c \u0438\u043d\u0442\u0435\u0440\u0435\u0441\u0443\u0435\u0442\u0441\u044f \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u044c\u044e \u043c\u043e\u0431\u0438\u043b\u044c\u043d\u044b\u0445 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439.<\/p>\n<figure class=\"full-width\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w780q1\/getpro\/habr\/upload_files\/058\/2b5\/9ec\/0582b59ec484244e45930be404179eff.jpg\" width=\"1920\" height=\"1080\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/058\/2b5\/9ec\/0582b59ec484244e45930be404179eff.jpg\" data-blurred=\"true\"\/><figcaption><\/figcaption><\/figure>\n<h2>\u041e\u0433\u043b\u0430\u0432\u043b\u0435\u043d\u0438\u0435<\/h2>\n<ul>\n<li>\n<p><a href=\"#%D0%B2%D1%81%D1%82%D1%83%D0%BF%D0%BB%D0%B5%D0%BD%D0%B8%D0%B5\">\u0412\u0441\u0442\u0443\u043f\u043b\u0435\u043d\u0438\u0435<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"#ios\">iOS Security Awesome<\/a><\/p>\n<ul>\n<li>\n<p><a href=\"#iostools\">\u0418\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u044b \u0430\u043d\u0430\u043b\u0438\u0437\u0430<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"#iosdefencetools\">\u0418\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u044b \u0437\u0430\u0449\u0438\u0442\u044b<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"#iosctf\">\u0423\u044f\u0437\u0432\u0438\u043c\u044b\u0435 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"#iosvideo\">\u0412\u0438\u0434\u0435\u043e<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"#iospapers\">\u0421\u0442\u0430\u0442\u044c\u0438<\/a><\/p>\n<\/li>\n<\/ul>\n<\/li>\n<li>\n<p><a href=\"#android\">Android Security Awesome<\/a><\/p>\n<ul>\n<li>\n<p><a href=\"#androidtools\">\u0418\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u044b \u0430\u043d\u0430\u043b\u0438\u0437\u0430<\/a><\/p>\n<ul>\n<li>\n<p><a href=\"#androidtoolscommon\">\u041e\u0431\u0449\u0438\u0435<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"#androidtoolsdynamic\">\u0414\u0438\u043d\u0430\u043c\u0438\u0447\u0435\u0441\u043a\u0438\u0439 \u0430\u043d\u0430\u043b\u0438\u0437<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"#androidtoolsonline\">\u041e\u043d\u043b\u0430\u0439\u043d \u0430\u043d\u0430\u043b\u0438\u0437\u0430\u0442\u043e\u0440\u044b<\/a><\/p>\n<\/li>\n<\/ul>\n<\/li>\n<li>\n<p><a href=\"#androiddefencetools\">\u0418\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u044b \u0437\u0430\u0449\u0438\u0442\u044b<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"#androidvulnerableapps\">\u0423\u044f\u0437\u0432\u0438\u043c\u044b\u0435 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"#androidctf\">CTF<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"#androidctfwalk\">\u041f\u0440\u043e\u0445\u043e\u0436\u0434\u0435\u043d\u0438\u0435 CTF<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"#androidvideo\">\u0412\u0438\u0434\u0435\u043e<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"#androidpodcast\">\u041f\u043e\u0434\u043a\u0430\u0441\u0442\u044b<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"#androidpapers\">\u0421\u0442\u0430\u0442\u044c\u0438<\/a><\/p>\n<\/li>\n<\/ul>\n<\/li>\n<li>\n<p><a href=\"#%D0%B7%D0%B0%D0%BA%D0%BB%D1%8E%D1%87%D0%B5%D0%BD%D0%B8%D0%B5\">\u0417\u0430\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u0435<\/a><\/p>\n<\/li>\n<\/ul>\n<p><a class=\"anchor\" name=\"%D0%B2%D1%81%D1%82%D1%83%D0%BF%D0%BB%D0%B5%D0%BD%D0%B8%D0%B5\" id=\"\u0432\u0441\u0442\u0443\u043f\u043b\u0435\u043d\u0438\u0435\"><\/a><\/p>\n<h2>\u0412\u0441\u0442\u0443\u043f\u043b\u0435\u043d\u0438\u0435<\/h2>\n<p>\u0417\u0434\u0435\u0441\u044c \u0441\u043e\u0431\u0440\u0430\u043d\u044b \u043c\u0430\u0442\u0435\u0440\u0438\u0430\u043b\u044b, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043c\u043e\u0433\u0443\u0442 \u0431\u044b\u0442\u044c \u043f\u043e\u043b\u0435\u0437\u043d\u044b \u0441 \u043f\u0440\u0430\u043a\u0442\u0438\u0447\u0435\u0441\u043a\u043e\u0439 \u0442\u043e\u0447\u043a\u0438 \u0437\u0440\u0435\u043d\u0438\u044f. \u0418\u0437 \u043d\u0438\u0445 \u043c\u043e\u0436\u043d\u043e \u0443\u0437\u043d\u0430\u0442\u044c \u043e \u043d\u043e\u0432\u044b\u0445 \u0441\u043f\u043e\u0441\u043e\u0431\u0430\u0445 \u0430\u0442\u0430\u043a \u043d\u0430 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f, \u043f\u0440\u043e\u0447\u0438\u0442\u0430\u0442\u044c \u043e \u043d\u043e\u0432\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044f\u0445, \u0438\u0437\u0443\u0447\u0438\u0442\u044c, \u043a\u0430\u043a \u0440\u0430\u0431\u043e\u0442\u0430\u044e\u0442 \u043c\u0435\u0445\u0430\u043d\u0438\u0437\u043c\u044b \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0438 \u0442.\u0434. \u0414\u043b\u044f \u0443\u0434\u043e\u0431\u0441\u0442\u0432\u0430 \u0432\u0441\u0435 \u043c\u0430\u0442\u0435\u0440\u0438\u0430\u043b\u044b, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0435\u0441\u0442\u044c \u043d\u0430 \u0440\u0443\u0441\u0441\u043a\u043e\u043c \u044f\u0437\u044b\u043a\u0435, \u0432\u044b\u0434\u0435\u043b\u0435\u043d\u044b \u0432 \u043f\u043e\u0434\u043f\u0443\u043d\u043a\u0442\u044b. \u0414\u043b\u044f \u043f\u0440\u043e\u0441\u0442\u043e\u0442\u044b \u043d\u0430\u0432\u0438\u0433\u0430\u0446\u0438\u0438 \u0435\u0441\u0442\u044c \u043e\u0433\u043b\u0430\u0432\u043b\u0435\u043d\u0438\u0435, \u0432\u0441\u0435 \u0441\u0441\u044b\u043b\u043a\u0438 \u0441\u043f\u0440\u044f\u0442\u0430\u043d\u044b \u043f\u043e\u0434 \u0440\u0430\u0441\u043a\u0440\u044b\u0432\u0430\u044e\u0449\u0438\u0435\u0441\u044f \u044d\u043b\u0435\u043c\u0435\u043d\u0442\u044b.<\/p>\n<\/p>\n<p><a class=\"anchor\" name=\"ios\" id=\"ios\"><\/a><\/p>\n<h2>iOS Security Awesome<\/h2>\n<p>\u0412 \u044d\u0442\u043e\u0439 \u043f\u043e\u0434\u0431\u043e\u0440\u043a\u0435 &#8212; \u043c\u0430\u0442\u0435\u0440\u0438\u0430\u043b\u044b \u043f\u043e \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 iOS-\u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439, \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0435 \u0441\u0442\u0430\u0442\u044c\u0438, \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u043d\u0438\u044f, \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u044b \u0430\u043d\u0430\u043b\u0438\u0437\u0430 \u0438 \u043f\u043e\u043b\u0435\u0437\u043d\u044b\u0435 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0438 \u0434\u043b\u044f \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0435\u043d\u0438\u044f \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438. <\/p>\n<p><a class=\"anchor\" name=\"iostools\" id=\"iostools\"><\/a><\/p>\n<h3>\u0418\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u044b \u0430\u043d\u0430\u043b\u0438\u0437\u0430<\/h3>\n<p>\u0412\u0441\u0435, \u0447\u0442\u043e \u043c\u043e\u0436\u0435\u0442 \u043f\u0440\u0438\u0433\u043e\u0434\u0438\u0442\u044c\u0441\u044f \u043f\u0440\u0438 \u0430\u043d\u0430\u043b\u0438\u0437\u0435 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439: \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0435 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0438, \u043c\u043e\u0434\u0443\u043b\u0438 \u0434\u043b\u044f \u043f\u043e\u0438\u0441\u043a\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u0446\u0435\u043b\u044b\u0435 \u0444\u0440\u0435\u0439\u043c\u0432\u043e\u0440\u043a\u0438 \u0438 \u0441\u0438\u0441\u0442\u0435\u043c\u044b.<\/p>\n<details class=\"spoiler\">\n<summary>\u0421\u0441\u044b\u043b\u043a\u0438<\/summary>\n<div class=\"spoiler__content\">\n<ul>\n<li>\n<p><a href=\"https:\/\/github.com\/ChiChou\/bagbak\">bagbak<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/Swordfish-Security\/awesome-ios-security\/blob\/main\">PassionFruit<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/Swordfish-Security\/awesome-ios-security\/blob\/main\">GrapeFruit<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/securing\/IOSSecuritySuite\">IOS Security Suite<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/ios.cfw.guide\/blocking-jailbreak-detection\/#tweaks\">Blocking Jailbreak Detection Tweaks<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/evilpenguin\/NetworkSniffer\">NetworkSniffer<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/0x36\/ghidra_kernelcache\/\">Ghidra iOS kernelcache framework for reverse engineering<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/AloneMonkey\/frida-ios-dump\">frida-ios-dump<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/stefanesser\/dumpdecrypted\">dumpdecrypted<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/DerekSelander\/yacd\">Yet Another Code Decrypter<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/hot3eed\/xpcspy\">xpcspy &#8212; Bidirectional XPC message interception and more<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/checkra.in\/\">checkra1n jailbreak<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/frida\/frida\/releases\">Frida<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/sensepost\/objection\">Objection &#8212; mobile exploration toolkit by Frida<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/BishopFox\/bfinject\">Bfinject<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"http:\/\/www.i-funbox.com\/\">iFunbox<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.libimobiledevice.org\/\">Libimobiledevice &#8212; library to communicate with the services of the Apple ios devices<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.veracode.com\/sites\/default\/files\/Resources\/Tools\/iRETTool.zip\">iRET (iOS Reverse Engineering Toolkit)<\/a>\u00a0<\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/portswigger.net\/burp\/communitydownload\">Burp Suite<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/cydia.saurik.com\/api\/latest\/3\">Cycript<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/abrignoni\/iLEAPP\">iLEAPP &#8212; iOS Logs, Events, And Preferences Parser<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/cutter.re\/\">Cutter &#8212; Free and Open Source RE Platform powered by radare2<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/shinvou\/decrypt0r\">decrypt0r &#8212; automatically download and decrypt SecureRom stuff<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/MobSF\/Mobile-Security-Framework-MobSF\">Mobile-Security-Framework MobSF<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/m0bilesecurity\/RMS-Runtime-Mobile-Security\">Runtime Mobile Security (RMS) &#8212; is a powerful web interface that helps you to manipulate Android and iOS Apps at Runtime<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/NorthwaveSecurity\/fridax\">fridax<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/mobexler.com\/\">MOBEXLER<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/h0nus\/QRGen\">Generate Malformed QRCodes<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/huntergregal\/scansploit\">Tool for Injecting Malicious Payloads Into Barcodes<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/lcamtuf.coredump.cx\/afl\/\">AFL &#8212; american fuzzy lop<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/m2sup3rn0va.github.io\/SiAAA\/\">Setup for i0S and Android Application Analysis<\/a>\u00a0<\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/Ebryx\/AES-Killer\">AES Killer (Burpsuite Plugin)<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/ptswarm\/reFlutter\">ReFlutter<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/lief-project\/LIEF\">Lief<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/mvt-project\/mvt\">Mobile Verification Toolkit<\/a><\/p>\n<\/li>\n<\/ul>\n<\/div>\n<\/details>\n<p><a class=\"anchor\" name=\"iosdefencetools\" id=\"iosdefencetools\"><\/a><\/p>\n<h3>\u0418\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u044b \u0437\u0430\u0449\u0438\u0442\u044b<\/h3>\n<p>\u0411\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0438, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043c\u043e\u0433\u0443\u0442 \u043f\u043e\u043c\u043e\u0447\u044c \u043f\u0440\u0438 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u043a\u0435 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f.<\/p>\n<details class=\"spoiler\">\n<summary>\u0421\u0441\u044b\u043b\u043a\u0438<\/summary>\n<div class=\"spoiler__content\">\n<ul>\n<li>\n<p><a href=\"https:\/\/github.com\/agens-no\/EllipticCurveKeyPair\">EllipticCurveKeyPair<\/a>\u00a0&#8212; \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0430 \u0434\u043b\u044f \u0443\u0434\u043e\u0431\u043d\u043e\u0439 \u0440\u0430\u0431\u043e\u0442\u044b \u0441 SecurityEnclave<\/p>\n<\/li>\n<\/ul>\n<\/div>\n<\/details>\n<p><a class=\"anchor\" name=\"iosctf\" id=\"iosctf\"><\/a><\/p>\n<h3>\u0423\u044f\u0437\u0432\u0438\u043c\u044b\u0435 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f<\/h3>\n<p>\u0417\u0434\u0435\u0441\u044c &#8212; \u043e \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0445 CTF \u0438 \u043e \u0442\u043e\u043c, \u043a\u0430\u043a \u0438\u0445 \u043f\u0440\u043e\u0445\u043e\u0434\u0438\u0442\u044c. \u0412\u0441\u0435 \u044d\u0442\u043e \u043f\u043e\u043c\u043e\u0436\u0435\u0442 \u043f\u043e\u043f\u0440\u0430\u043a\u0442\u0438\u043a\u043e\u0432\u0430\u0442\u044c\u0441\u044f \u0438 \u043f\u043e\u043d\u044f\u0442\u044c, \u043a\u0430\u043a\u0438\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043c\u043e\u0433\u0443\u0442 \u0431\u044b\u0442\u044c \u0432 iOS-\u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f\u0445 \u0438 \u043a\u0430\u043a \u0438\u0445 \u0438\u0441\u043a\u0430\u0442\u044c. \u041f\u043e\u043a\u0430 \u0447\u0442\u043e \u0438 \u0441\u0430\u043c\u0438 \u0437\u0430\u0434\u0430\u043d\u0438\u044f, \u0438 \u043f\u0440\u043e\u0445\u043e\u0436\u0434\u0435\u043d\u0438\u044f \u043e\u0431\u044a\u0435\u0434\u0438\u043d\u0438\u043b \u0432 \u043e\u0434\u0438\u043d \u043f\u0443\u043d\u043a\u0442. \u041a\u043e\u0433\u0434\u0430 \u0438\u0445 \u0441\u0442\u0430\u043d\u0435\u0442 \u0431\u043e\u043b\u044c\u0448\u0435, \u043c\u043e\u0436\u043d\u043e \u0431\u0443\u0434\u0435\u0442 \u0440\u0430\u0437\u0434\u0435\u043b\u0438\u0442\u044c (\u043a\u0430\u043a \u044d\u0442\u043e \u0441\u0434\u0435\u043b\u0430\u043d\u043e \u0434\u043b\u044f Android). <\/p>\n<details class=\"spoiler\">\n<summary>\u0421\u0441\u044b\u043b\u043a\u0438<\/summary>\n<div class=\"spoiler__content\">\n<ul>\n<li>\n<p><a href=\"https:\/\/github.com\/GeoSn0w\/Myriam\">Myriam iOS<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"http:\/\/securitycompass.github.io\/iPhoneLabs\/\">ExploitMe Mobile iPhone Labs<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/hankbao\/owasp-igoat\">Owasp: iGoat<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/prateek147\/DVIA\">Damn Vulnerable iOS App (DVIA)<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/prateek147\/DVIA-v2\">Damn Vulnerable iOS App (DVIA) v2<\/a><\/p>\n<ul>\n<li>\n<p><a href=\"https:\/\/philkeeble.com\/categories\/#ios\">DVIA Walkthrow<\/a><\/p>\n<\/li>\n<\/ul>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/OWASP\/OMTG-Hacking-Playground\">OWASP: OMTG-Hacking-Playground<\/a><\/p>\n<\/li>\n<li>\n<p>Magnet Virtual Summit 2020 CTF (iOS)<\/p>\n<ul>\n<li>\n<p><a href=\"https:\/\/www.stark4n6.com\/2020\/06\/magnet-virtual-summit-2020-ctf-ios.html\">writeup 1<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/dfir300.blogspot.com\/2020\/06\/mvs2020ctf-write-up-ios.html\">writeup 2<\/a><\/p>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/div>\n<\/details>\n<p><a class=\"anchor\" name=\"iosvideo\" id=\"iosvideo\"><\/a><\/p>\n<h3>\u0412\u0438\u0434\u0435\u043e<\/h3>\n<p>\u0417\u0434\u0435\u0441\u044c \u0441\u043e\u0431\u0440\u0430\u043d\u044b \u0432\u0441\u0435 \u0432\u0438\u0434\u0435\u043e, \u0438\u043c\u0435\u044e\u0449\u0438\u0435 \u043e\u0442\u043d\u043e\u0448\u0435\u043d\u0438\u0435 \u043a \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 iOS. \u041f\u043e\u043a\u0430 \u0447\u0442\u043e \u044f \u043d\u0430\u0448\u0435\u043b \u0442\u043e\u043b\u044c\u043a\u043e \u0430\u043d\u0433\u043b\u043e\u044f\u0437\u044b\u0447\u043d\u044b\u0435 \u043c\u0430\u0442\u0435\u0440\u0438\u0430\u043b\u044b, \u043d\u043e \u043d\u0430\u0434\u0435\u044e\u0441\u044c, \u0447\u0442\u043e \u0432 \u0434\u0430\u043b\u044c\u043d\u0435\u0439\u0448\u0435\u043c \u0434\u043e\u0431\u0430\u0432\u044f\u0442\u0441\u044f \u0438 \u043d\u0430 \u0440\u0443\u0441\u0441\u043a\u043e\u043c \u044f\u0437\u044b\u043a\u0435.<\/p>\n<h4>En<\/h4>\n<details class=\"spoiler\">\n<summary>\u0421\u0441\u044b\u043b\u043a\u0438<\/summary>\n<div class=\"spoiler__content\">\n<ul>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=2CKrw7ErzCY\">iOS Application Vulnerabilities and how to find them<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=8cOx7vfszZU&amp;feature=youtu.be\">Attacking iPhone XS Max<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=BLGFriOKz6U\">Behind the Scenes of iOS Security<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=07VqX4bbXTI\">Analyzing and Attacking Apple Kernel Drivers<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=bP5VP7vLLKo\">Remotely Compromising iOS via Wi-Fi and Escaping the Sandbox<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=7UNeUT_sRos\">Demystifying the Secure Enclave Processor<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=DJFxhShJ6Ns\">HackPac Hacking Pointer Authentication in iOS User Space<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=DNW6Im31lQo\">iOS 10 Kernel Heap Revisited<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=p512McKXukU\">Recreating An iOS 0-Day Jailbreak Out Of Apple&#8217;s Security Updates<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=b6LI6j_aJ9k\">Building Secure iOS Apps (you don\u2019t have to learn it the hard way!)<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=9JuBUpRPLRs\">The Worst Mobile Apps<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=KeWcZ-Dd6tA\">Learn modding Unity apps and games with Frida<\/a><\/p>\n<\/li>\n<\/ul>\n<\/div>\n<\/details>\n<p><a class=\"anchor\" name=\"iospapers\" id=\"iospapers\"><\/a><\/p>\n<h3>\u0421\u0442\u0430\u0442\u044c\u0438<\/h3>\n<p>\u0412 \u044d\u0442\u043e\u043c \u0431\u043b\u043e\u043a\u0435 &#8212; \u0440\u0430\u0437\u043d\u043e\u043e\u0431\u0440\u0430\u0437\u043d\u044b\u0435 \u0441\u0442\u0430\u0442\u044c\u0438 \u0438 \u043c\u0430\u0442\u0435\u0440\u0438\u0430\u043b\u044b \u043f\u043e iOS. \u0420\u0443\u0441\u0441\u043a\u043e\u044f\u0437\u044b\u0447\u043d\u044b\u0435 \u0438 \u0430\u043d\u0433\u043b\u043e\u044f\u0437\u044b\u0447\u043d\u044b\u0435 &#8212; \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u043e. \u0411\u043b\u043e\u043a \u0441\u043e \u0441\u0442\u0430\u0442\u044c\u044f\u043c\u0438, \u043e\u0442\u043d\u043e\u0441\u044f\u0449\u0438\u043c\u0438\u0441\u044f \u043a Frida, &#8212; \u0432 \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u043e\u043c \u0440\u0430\u0437\u0434\u0435\u043b\u0435, \u043f\u043e\u0441\u043a\u043e\u043b\u044c\u043a\u0443 \u0441\u0435\u0433\u043e\u0434\u043d\u044f \u044d\u0442\u043e, \u043d\u0430\u0432\u0435\u0440\u043d\u043e\u0435, \u0441\u0430\u043c\u044b\u0439 \u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u043d\u044b\u0439 \u0444\u0440\u0435\u0439\u043c\u0432\u043e\u0440\u043a \u0434\u043b\u044f \u0442\u0435\u0441\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f. \u041d\u0430\u0432\u0435\u0440\u043d\u044f\u043a\u0430 \u043f\u043e\u043b\u0435\u0437\u043d\u043e \u043f\u043e\u0441\u043c\u043e\u0442\u0440\u0435\u0442\u044c, \u043a\u0430\u043a \u043e\u043d \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u0442\u0441\u044f \u043d\u0430 \u0440\u0435\u0430\u043b\u044c\u043d\u044b\u0445 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f\u0445.<\/p>\n<h4>Ru<\/h4>\n<details class=\"spoiler\">\n<summary>\u0421\u0441\u044b\u043b\u043a\u0438<\/summary>\n<div class=\"spoiler__content\">\n<ul>\n<li>\n<p><a href=\"https:\/\/habr.com\/ru\/company\/pt\/blog\/155937\/\">\u0412\u0430\u0448 \u0444\u043e\u043d\u0430\u0440\u0438\u043a \u043c\u043e\u0436\u0435\u0442 \u043e\u0442\u043f\u0440\u0430\u0432\u043b\u044f\u0442\u044c SMS<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/habr.com\/ru\/post\/556582\/\">\u041f\u0440\u043e\u0446\u0435\u0441\u0441 \u0437\u0430\u0433\u0440\u0443\u0437\u043a\u0438 iPhone. \u0427\u0430\u0441\u0442\u044c 1: Boot ROM<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/habr.com\/ru\/post\/569034\/\">\u0413\u0430\u0439\u0434 \u043f\u043e \u0440\u0435\u0432\u0435\u0440\u0441\u0443 iOS \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f \u043d\u0430 \u043f\u0440\u0438\u043c\u0435\u0440\u0435 ExpressVPN<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/habr.com\/ru\/company\/jugru\/blog\/570220\/\">\u0412\u0437\u043b\u043e\u043c \u0438 \u0432\u043d\u0435\u0434\u0440\u0435\u043d\u0438\u0435 \u0441\u0432\u043e\u0435\u0433\u043e \u043a\u043e\u0434\u0430 \u0432 \u0447\u0443\u0436\u043e\u0435 iOS-\u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0435<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/habr.com\/ru\/company\/wrike\/blog\/544754\/\">\u0411\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u044c iOS-\u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439: \u0433\u0430\u0439\u0434 \u0434\u043b\u044f \u043d\u043e\u0432\u0438\u0447\u043a\u043e\u0432<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/habr.com\/ru\/company\/swordfish_security\/blog\/525772\/\">Just for fun: \u0421\u043a\u043e\u043b\u044c\u043a\u043e \u00ab\u0436\u0438\u0432\u0435\u0442\u00bb iOS \u0434\u043e Jailbreak<\/a><\/p>\n<\/li>\n<\/ul>\n<\/div>\n<\/details>\n<h4>En<\/h4>\n<details class=\"spoiler\">\n<summary>\u0421\u0441\u044b\u043b\u043a\u0438<\/summary>\n<div class=\"spoiler__content\">\n<h4>Frida<\/h4>\n<ul>\n<li>\n<p><a href=\"https:\/\/syrion.me\/blog\/ios-swift-antijailbreak-bypass-frida\/\">iOS Swift Anti-Jailbreak Bypass with Frida<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.romainthomas.fr\/post\/21-07-pokemongo-anti-frida-jailbreak-bypass\/\">Gotta Catch &#8216;Em All: Frida &amp; jailbreak detection<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.amazon.com\/Beginning-Frida-Learning-Android-JavaScript\/dp\/B094ZQ1HHC\">Beginning Frida: Learning Frida use on Linux and (just a bit on) Wintel and Android systems with Python and JavaScript (Frida. hooking, and other tools)<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/kylesmile1103\/Learn-Frida\">Learn how to use Frida with Unity app<\/a><\/p>\n<\/li>\n<\/ul>\n<h4>\u041f\u0440\u043e\u0447\u0435\u0435<\/h4>\n<ul>\n<li>\n<p><a href=\"https:\/\/github.com\/writeups\/iOS\">iOS Write ups<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/rentry.co\/newvw\">iOS Internals &amp; Security Testing<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/curvedlayer.com\/2020\/08\/09\/ios-simulator-plugin-simctl.html\">Hacking iOS Simulator with simctl and dynamic libraries<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/siguza.github.io\/psychicpaper\/\">Psychic Paper<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/wojciechregula.blog\/post\/stealing-your-sms-messages-with-ios-0day\/\">Stealing your SMS messages with iOS 0day<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/bhavukjain.com\/blog\/2020\/05\/30\/zeroday-signin-with-apple\/\">Zero-day in Sign in with Apple<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.synacktiv.com\/en\/publications\/return-of-the-ios-sandbox-escape-lightspeeds-back-in-the-race.html\">Return of the ios sandbox escape: lightspeeds back in the race<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/this-pin-can-be-easily-guessed.github.io\/\">PIN Selection on Smartphones<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/googleprojectzero.blogspot.com\/2020\/06\/a-survey-of-recent-ios-kernel-exploits.html\">A survey of recent iOS kernel exploits<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.elcomsoft.com\/2020\/06\/apple-two-factor-authentication-sms-vs-trusted-devices\/\">Apple Two-Factor Authentication: SMS vs. Trusted Devices<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.nviso.eu\/2020\/06\/12\/intercepting-flutter-traffic-on-ios\/\">Intercepting Flutter traffic on iOS<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/aeonlucid.com\/Snapchat-detection-on-iOS\/\">Snapchat detection on iOS<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/secfault-security.com\/blog\/chain3.html\">Writing an iOS Kernel Exploit from Scratch<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.elcomsoft.com\/2020\/07\/4-ways-to-handle-iphone-backup-passwords\/\">The Four Ways to Deal with iPhone Backup Passwords<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.elcomsoft.com\/2020\/08\/extracting-and-decrypting-ios-keychain-physical-logical-and-cloud-options-explored\/\">Extracting and Decrypting iOS Keychain: Physical, Logical and Cloud Options Explored<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/googleprojectzero.blogspot.com\/2020\/07\/one-byte-to-rule-them-all.html\">iOS Kernel Explotation &#8212; One Byte to rule them all<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.infoq.com\/presentations\/ios-security\/\">Modern iOS Application Security<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.bugcrowd.com\/resources\/webinars\/reverse-engineering-ios-mobile-apps\/\">Reverse Engineering iOS Mobile Apps<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/media.ccc.de\/v\/36c3-10806-ktrw_the_journey_to_build_a_debuggable_iphone\">KTRW: The journey to build a debuggable iPhone<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/media.ccc.de\/v\/36c3-11238-the_one_weird_trick_securerom_hates\">The One Weird Trick SecureROM Hates<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/media.ccc.de\/v\/36c3-11034-tales_of_old_untethering_ios_11\">Tales of old: untethering iOS 11-Spoiler: Apple is bad at patching<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/media.ccc.de\/v\/36c3-10497-messenger_hacking_remotely_compromising_an_iphone_through_imessage\">Messenger Hacking: Remotely Compromising an iPhone through iMessage<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/vimeo.com\/231806976\">Reverse Engineering the iOS Simulator\u2019s SpringBoard<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/ansjdnakjdnajkd\/iOS\">Most usable tools for iOS penetration testing<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/0xmachos\/iOS-Security-Guides\">iOS-Security-Guides<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/i.blackhat.com\/eu-19\/Thursday\/eu-19-Yen-Trust-In-Apples-Secret-Garden-Exploring-Reversing-Apples-Continuity-Protocol-3.pdf\">Trust in Apple&#8217;s Secret Garden: Exploring &amp; Reversing Apple&#8217;s Continuity Protocol-Slides<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/manuals.info.apple.com\/MANUALS\/1000\/MA1902\/en_US\/apple-platform-security-guide.pdf\">Apple Platform Security<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/2013.appsecusa.org\/2013\/wp-content\/uploads\/2013\/12\/viaForensics-AppSecUSA-Nov-2013.pdf\">Mobile security, forensics &amp; malware analysis with Santoku Linux<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.redteam.pl\/2020\/08\/stealing-local-files-using-safari-web.html?m=1\">Stealing local files using Safari Web Share API<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/muirey03.blogspot.com\/2020\/09\/cve-2020-9964-ios-infoleak.html?m=1\">CVE-2020-9964 &#8212; An iOS infoleak<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/raw.githubusercontent.com\/windknown\/presentations\/master\/Attack_Secure_Boot_of_SEP.pdf\">Attack Secure Boot of SEP<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.elcomsoft.com\/2020\/09\/ios-14-forensics-what-has-changed-since-ios-13-7\/\">iOS 14 Forensics: What Has Changed Since iOS 13.7<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/samcurry.net\/hacking-apple\/\">We Hacked Apple for 3 Months: Here\u2019s What We Found<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/medium.com\/@ali.pourhadi\/fun-with-xpc-153fd772d409\">Fun with XPC<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.cyclon3.com\/bypass-facebook-ssl-certificate-pinning-for-ios\">Bypass Facebook SSL Certificate Pinning for iOS<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.cyclon3.com\/bypass-instagram-ssl-certificate-pinning-for-ios\">Bypass Instagram SSL Certificate Pinning for iOS<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/bellis1000.medium.com\/aslr-the-ios-kernel-how-virtual-address-spaces-are-randomised-d76d14dc7ebb\">ASLR &amp; the iOS Kernel \u2014 How virtual address spaces are randomised<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/ansjdnakjdnajkd\/iOS\">iOS\/macOS penetration testing cheatsheet<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/m1racles.com\/\">M1ssing Register Access Controls Leak EL0 State<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/worthdoingbadly.com\/macappsios\/\">Jailbroken iOS can&#8217;t run macOS apps. I spent a week to find out why.<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.chichou.me\/2021\/06\/20\/quick-analysis-wifid\/\">Quick Analysis for the SSID Format String Bug<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/threatpost.com\/unpatched-iphone-bug-remote-takeover\/167922\/\">Unpatched iPhone Bug Allows Remote Device Takeover<\/a><\/p>\n<\/li>\n<li>\n<p>Reverse Engineering Starling Bank<\/p>\n<ul>\n<li>\n<p><a href=\"https:\/\/hot3eed.github.io\/2020\/07\/30\/starling_p1_obfuscations.html\">Part I: Obfuscation Techniques<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/hot3eed.github.io\/2020\/08\/02\/starling_p2_detections_mitigations.html\">Part II: Jailbreak &amp; Debugger Detection, Weaknesses &amp; Mitigations<\/a><\/p>\n<\/li>\n<\/ul>\n<\/li>\n<li>\n<p><a href=\"https:\/\/xperylab.medium.com\/protonmail-forensic-decryption-of-ios-app-8e9ae9f50953\">ProtonMail : forensic decryption of iOS App<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/alephsecurity\/xnu-qemu-arm64\">iOS on QEMU<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/twitter.com\/ddouhine\/status\/1430881952559685633?s=28\">Proxying is not the only way to monitor network traffic on your iOS mobile apps<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.elcomsoft.com\/2020\/04\/forensic-guide-to-imessage-whatsapp-telegram-signal-and-skype-data-acquisition\/\">Forensic guide to iMessage, WhatsApp, Telegram, Signal and Skype data acquisition<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/research.checkpoint.com\/2020\/mobile-as-attack-vector-using-mdm\/\">Malware uses Corporate MDM as attack vector<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/mobexler.com\/checklist.htm\">Mobexler Checklist<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/20\/f\/barcode-reader-apps-on-google-play-found-using-new-ad-fraud-technique.html\">Ad Fraud Spotted in Barcode Reader Malware Analysis<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.elcomsoft.com\/2020\/06\/researching-confide-messenger-encryption\/\">Researching Confide Messenger Encryption<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/hot3eed.github.io\/snap_part1_obfuscations.html\">Reverse Engineering Snapchat (Part I): Obfuscation Techniques<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/hot3eed.github.io\/2020\/06\/22\/snap_p2_deobfuscation.html\">Reverse Engineering Snapchat (Part II): Deobfuscating the Undeobfuscatable<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/abss.me\/posts\/fcm-takeover\/\">Firebase Cloud Messaging Service Takeover<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.allysonomalley.com\/2020\/01\/06\/saying-goodbye-to-my-favorite-5-minute-p1\/\">Saying Goodbye to my Favorite 5 Minute P1<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.tst.sh\/reverse-engineering-flutter-apps-part-1\/\">Reverse engineering Flutter apps (Part 1)<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/hitcon.org\/2020\/slides\/How%20I%20Hacked%20Facebook%20Again!.pdf\">How I Hacked facebook Again!<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/research.checkpoint.com\/2020\/instagram_rce-code-execution-vulnerability-in-instagram-app-for-android-and-ios\/\">Instagram_RCE: Code Execution Vulnerability in Instagram App for Android and iOS<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/infosecwriteups.com\/how-to-use-ghidra-to-reverse-engineer-mobile-application-c2c89dc5b9aa\">How to use Ghidra to Reverse Engineer Mobile Application<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/suam.wtf\/posts\/react-native-application-static-analysis-en\/\">React Native Application Static Analysis<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/medium.com\/@meshal_\/pentesting-non-proxy-aware-mobile-applications-65161f62a965\">Pentesting Non-Proxy Aware Mobile Applications Without Root\/Jailbreak<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"http:\/\/phrack.org\/issues\/70\/12.html#article\">CVE-2021-30737 &#8212; Vulnerability Overview<\/a><\/p>\n<ul>\n<li>\n<p><a href=\"https:\/\/googleprojectzero.blogspot.com\/2022\/04\/cve-2021-30737-xerubs-2021-ios-asn1.html\">CVE-2021-30737, @xerub&#8217;s 2021 iOS ASN.1 Vulnerability<\/a><\/p>\n<\/li>\n<\/ul>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/OWASP\/owasp-mstg\/\">OWASP MSTG<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/mega.nz\/folder\/spoGDToC#zjYFlRAU7S06u5jSaQnvYw\">Full Mobile Hacking Course<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/academy.nowsecure.com\/\">NowSecure Academy<\/a><\/p>\n<\/li>\n<\/ul>\n<\/div>\n<\/details>\n<p><a class=\"anchor\" name=\"android\" id=\"android\"><\/a><\/p>\n<h2>Android Security Awesome<\/h2>\n<p>\u0412 \u0434\u0430\u043d\u043d\u043e\u043c \u0440\u0430\u0437\u0434\u0435\u043b\u0435 \u0441\u043e\u0431\u0440\u0430\u043d\u044b \u043c\u0430\u0442\u0435\u0440\u0438\u0430\u043b\u044b \u043f\u043e \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 Android-\u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439, \u0432\u043a\u043b\u044e\u0447\u0430\u044f \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0435 \u0441\u0442\u0430\u0442\u044c\u0438, \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u043d\u0438\u044f, \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u044b \u0430\u043d\u0430\u043b\u0438\u0437\u0430 \u0438 \u043f\u043e\u043b\u0435\u0437\u043d\u044b\u0435 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0438 \u0434\u043b\u044f \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0435\u043d\u0438\u044f \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439. <\/p>\n<p><a class=\"anchor\" name=\"androidtools\" id=\"androidtools\"><\/a><\/p>\n<h3>\u0418\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u044b \u0430\u043d\u0430\u043b\u0438\u0437\u0430<\/h3>\n<p>\u042d\u0442\u043e\u0442 \u0431\u043b\u043e\u043a \u0440\u0430\u0437\u0431\u0438\u0442 \u043d\u0430 \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u0447\u0430\u0441\u0442\u0435\u0439. \u0421\u043d\u0430\u0447\u0430\u043b\u0430 \u043c\u043e\u0436\u043d\u043e \u0443\u0432\u0438\u0434\u0435\u0442\u044c \u043e\u0431\u0449\u0438\u0435 \u0440\u0435\u0448\u0435\u043d\u0438\u044f \u0434\u043b\u044f \u0430\u043d\u0430\u043b\u0438\u0437\u0430 \u0438 \u043f\u043e\u0438\u0441\u043a\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439. \u041d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0438\u0437 \u043d\u0438\u0445 \u043f\u0435\u0440\u0435\u0441\u0435\u043a\u0430\u044e\u0442\u0441\u044f \u0441 \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u0430\u043c\u0438 \u0434\u043b\u044f iOS, \u043f\u043e\u0442\u043e\u043c\u0443 \u0447\u0442\u043e \u0441\u0440\u0435\u0434\u0438 \u043d\u0438\u0445 \u0432\u0441\u0442\u0440\u0435\u0447\u0430\u044e\u0442\u0441\u044f \u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0430\u043b\u044c\u043d\u044b\u0435 \u0444\u0440\u0435\u0439\u043c\u0432\u043e\u0440\u043a\u0438 (\u043d\u043e \u0442\u0430\u043a\u0438\u0445 \u043d\u0435\u043c\u043d\u043e\u0433\u043e).<\/p>\n<p> \u041f\u043e\u0441\u043b\u0435 \u0438\u0434\u0443\u0442 \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u044b, \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u044b\u0435 \u0434\u043b\u044f \u0434\u0438\u043d\u0430\u043c\u0438\u0447\u0435\u0441\u043a\u043e\u0433\u043e \u0430\u043d\u0430\u043b\u0438\u0437\u0430 (\u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u043e \u0437\u0430\u043f\u0443\u0441\u043a\u0430\u0442\u044c \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0435 \u043d\u0430 \u0440\u0435\u0430\u043b\u044c\u043d\u043e\u043c \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0435 \u0438\u043b\u0438 \u044d\u043c\u0443\u043b\u044f\u0442\u043e\u0440\u0435). <\/p>\n<p>\u041d\u0443 \u0438 \u043f\u043e\u0441\u043b\u0435\u0434\u043d\u0438\u043c \u043f\u0443\u043d\u043a\u0442\u043e\u043c &#8212; \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u044b, \u0434\u043e\u0441\u0442\u0443\u043f\u043d\u044b\u0435 online, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f \u043a\u043e\u0442\u043e\u0440\u044b\u0435, \u043c\u043e\u0436\u043d\u043e \u0437\u0430\u0433\u0440\u0443\u0437\u0438\u0442\u044c \u0444\u0430\u0439\u043b \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f \u0438 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0447\u0435\u0440\u0435\u0437 \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u043e\u0435 \u0432\u0440\u0435\u043c\u044f \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442.<\/p>\n<p><a class=\"anchor\" name=\"androidtoolscommon\" id=\"androidtoolscommon\"><\/a><\/p>\n<h4>\u041e\u0431\u0449\u0438\u0435<\/h4>\n<details class=\"spoiler\">\n<summary>\u0421\u0441\u044b\u043b\u043a\u0438<\/summary>\n<div class=\"spoiler__content\">\n<ul>\n<li>\n<p><a href=\"https:\/\/beta.pithus.org\/\">Pithus<\/a>\u00a0(<a href=\"https:\/\/github.com\/Pithus\/bazaar\">github<\/a>) &#8212; free and open-source platform to analyze Android applications<\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/idanr1986\/cuckoodroid-2.0\">CuckooDroid 2.0 &#8212; Automated Android Malware Analysis<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/quark-engine\/quark-engine\">QARK &#8212; An Obfuscation-Neglect Android Malware Scoring System<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/linkedin\/qark\">QARK \u2013 Quick Android Review Kit<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/play.google.com\/store\/apps\/details?id=org.proxydroid&amp;hl=ru\">ProxyDroid<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/ASHWIN990\/ADB-Toolkit\">ADB Toolkit<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/darvincisec\/InjectFakeSecurityProvider\">InjectFakeSecurityProvider<\/a>\u00a0&#8212; print the key, key size, algorithm parameters, keystore password in logcat<\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/Ch0pin\/medusa\">MEDUSA<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/JakeWharton\/diffuse\">diffuse<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/daniellockyer\/apkdiff\">ApkDiff<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/charles2gan\/GDA-android-reversing-Tool\">GDA(GJoy Dex Analyzer)<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/evilpenguin\/APKProxyHelper\">APKProxyHelper<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/APKLab\/APKLab\">APKLab<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/m2sup3rn0va\/RASEv1\">RASE &#8212; Persistent Rooting Android Studio Emulator<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/ElderDrivers\/EdXposed\">EdXposed Framework<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/enovella\/fridroid-unpacker\">fridroid-unpacker<\/a>\u00a0&#8212; Defeat Java packers via Frida instrumentation<\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/devkekops\/checkkarlmarx\">CheckKarlMarx<\/a>\u00a0&#8212; Security \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 \u0434\u043b\u044f \u0440\u0435\u043b\u0438\u0437\u043d\u044b\u0445 \u0441\u0431\u043e\u0440\u043e\u043a<\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/windy-purple\/parserDex\/blob\/master\/%E5%AD%97%E7%AC%A6%E4%B8%B2%E8%A7%A3%E6%9E%90\/parserDexStrings.py\">parserDex<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/androguard\/androguard\">Androguard<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"http:\/\/pag.arguslab.org\/argus-saf\">Amandroid \u2013 A Static Analysis Framework<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/maaaaz\/androwarn\/\">Androwarn \u2013 Yet Another Static Code Analyzer<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/sonyxperiadev\/ApkAnalyser\">APK Analyzer \u2013 Static and Virtual Analysis Tool<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/honeynet\/apkinspector\/\">APK Inspector \u2013 A Powerful GUI Tool<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/hahwul\/droid-hunter\">Droid Hunter \u2013 Android application vulnerability analysis and Android pentest tool<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/google\/error-prone\">Error Prone \u2013 Static Analysis Tool<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"http:\/\/findbugs.sourceforge.net\/downloads.html\">Findbugs \u2013 Find Bugs in Java Programs<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/find-sec-bugs\/find-sec-bugs\/\">Find Security Bugs \u2013 A SpotBugs plugin for security audits of Java web applications.<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/secure-software-engineering\/FlowDroid\">Flow Droid \u2013 Static Data Flow Tracker<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/JesusFreke\/smali\">Smali\/Baksmali \u2013 Assembler\/Disassembler for the dex format<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/EugenioDelfa\/Smali-CFGs\">Smali-CFGs \u2013 Smali Control Flow Graph\u2019s<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.cs.washington.edu\/sparta\">SPARTA \u2013 Static Program Analysis for Reliable Trusted Apps<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/plv.colorado.edu\/projects\/thresher\/\">Thresher \u2013 To check heap reachability properties<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/Sukelluskello\/VectorAttackScanner\">Vector Attack Scanner \u2013 To search vulnerable points to attack<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/novoda\/gradle-static-analysis-plugin\">Gradle Static Analysis Plugin<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/noveogroup\/android-check\">Android Check \u2013 Static Code analysis plugin for Android Project<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/dwisiswant0\/apkleaks\">APK Leaks \u2013 Scanning APK file for URIs, endpoints &amp; secrets<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/NorthwaveSecurity\/fridax\">fridax<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/mobexler.com\/\">MOBEXLER<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/h0nus\/QRGen\">Generate Malformed QRCodes<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/huntergregal\/scansploit\">Tool for Injecting Malicious Payloads Into Barcodes<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/lcamtuf.coredump.cx\/afl\/\">AFL &#8212; american fuzzy lop<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/m2sup3rn0va.github.io\/SiAAA\/\">Setup for i0S and Android Application Analysis<\/a>\u00a0&#8212; This is a cheatsheet to install tools required for i0S and Android application pentesting<\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/Ebryx\/AES-Killer\">AES Killer (Burpsuite Plugin)<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/ptswarm\/reFlutter\">ReFlutter<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/lief-project\/LIEF\">Lief<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/mvt-project\/mvt\">Mobile Verification Toolkit<\/a><\/p>\n<\/li>\n<\/ul>\n<\/div>\n<\/details>\n<p><a class=\"anchor\" name=\"androidtoolsdynamic\" id=\"androidtoolsdynamic\"><\/a><\/p>\n<h4>\u0414\u0438\u043d\u0430\u043c\u0438\u0447\u0435\u0441\u043a\u0438\u0439 \u0430\u043d\u0430\u043b\u0438\u0437<\/h4>\n<details class=\"spoiler\">\n<summary>\u0421\u0441\u044b\u043b\u043a\u0438<\/summary>\n<div class=\"spoiler__content\">\n<ul>\n<li>\n<p><a href=\"https:\/\/stingray-mobile.ru\/\">Stingray<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/abhi-r3v0\/Adhrit\">Adhrit &#8212; Android Security Suite for in-depth reconnaissance and static bytecode analysis based on Ghera benchmarks<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/AndroidHooker\/hooker\">Android Hooker &#8212; Opensource project for dynamic analyses of Android applications<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"http:\/\/appaudit.io\/\">AppAudit &#8212; Online tool ( including an API) uses dynamic and static analysis<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/ucsb-seclab\/baredroid\">AppAudit &#8212; A bare-metal analysis tool on Android devices<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/pjlantz\/droidbox\">DroidBox &#8212; Dynamic analysis of Android applications<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/antojoseph\/droid-ff\">Droid-FF &#8212; Android File Fuzzing Framework<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/labs.f-secure.com\/tools\/drozer\/\">Drozer<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/programa-stic\/marvin-django\">Marvin &#8212; Analyzes Android applications and allows tracking of an app<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/ac-pm\/Inspeckage\">Inspeckage<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/mingyuan-xia\/PATDroid\">PATDroid &#8212; Collection of tools and data structures for analyzing Android applications<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/sh4hin\/Androl4b\">AndroL4b &#8212; Android security virtual machine based on ubuntu-mate<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/radareorg\/radare2\">Radare2 &#8212; Unix-like reverse engineering framework and commandline tools<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/cutter.re\/\">Cutter &#8212; Free and Open Source RE Platform powered by radare2<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/bytecodeviewer.com\/\">ByteCodeViewer &#8212; Android APK Reverse Engineering Suite (Decompiler, Editor, Debugger)<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/MobSF\/Mobile-Security-Framework-MobSF\">Mobile-Security-Framework MobSF<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/m0bilesecurity\/RMS-Runtime-Mobile-Security\">Runtime Mobile Security (RMS) &#8212; is a powerful web interface that helps you to manipulate Android and iOS Apps at Runtime<\/a><\/p>\n<\/li>\n<\/ul>\n<\/div>\n<\/details>\n<p><a class=\"anchor\" name=\"androidtoolsonline\" id=\"androidtoolsonline\"><\/a><\/p>\n<h4>\u041e\u043d\u043b\u0430\u0439\u043d-\u0430\u043d\u0430\u043b\u0438\u0437\u0430\u0442\u043e\u0440\u044b<\/h4>\n<details class=\"spoiler\">\n<summary>\u0421\u0441\u044b\u043b\u043a\u0438<\/summary>\n<div class=\"spoiler__content\">\n<ul>\n<li>\n<p><a href=\"http:\/\/www.decompileandroid.com\/\">Android APK Decompiler<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.ostorlab.co\/scan\/mobile\/\">Ostor Lab<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/quixxisecurity.com\/\">Quixxi<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"http:\/\/www.visualthreat.com\/UIupload.action\">Visual Threat<\/a><\/p>\n<\/li>\n<\/ul>\n<\/div>\n<\/details>\n<p><a class=\"anchor\" name=\"androiddefencetools\" id=\"androiddefencetools\"><\/a><\/p>\n<h3>\u0418\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u044b \u0437\u0430\u0449\u0438\u0442\u044b<\/h3>\n<p>\u0411\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0438, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043c\u043e\u0433\u0443\u0442 \u043f\u043e\u043c\u043e\u0447\u044c \u043f\u0440\u0438 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u043a\u0435 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f.<\/p>\n<details class=\"spoiler\">\n<summary>\u0421\u0441\u044b\u043b\u043a\u0438<\/summary>\n<div class=\"spoiler__content\">\n<ul>\n<li>\n<p><a href=\"https:\/\/github.com\/RedMadRobot\/PINkman\">PINkman is a library to help implementing an authentication by a PIN code in a secure manner<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/su-vikas\/conbeerlib\">Conbeerlib is an Android library for detecting if an app is running inside a virtual container.<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/Fi5t\/secured-datastore\">Secured Proto DataStore<\/a><\/p>\n<\/li>\n<\/ul>\n<\/div>\n<\/details>\n<p><a class=\"anchor\" name=\"androidvulnerableapps\" id=\"androidvulnerableapps\"><\/a><\/p>\n<h3>\u0423\u044f\u0437\u0432\u0438\u043c\u044b\u0435 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f<\/h3>\n<p>\u0420\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u044b\u0435 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f, \u043d\u0430 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043c\u043e\u0436\u043d\u043e \u043f\u043e\u0442\u0440\u0435\u043d\u0438\u0440\u043e\u0432\u0430\u0442\u044c\u0441\u044f \u0432 \u0430\u043d\u0430\u043b\u0438\u0437\u0435 \u0438 \u043f\u043e\u0441\u043c\u043e\u0442\u0440\u0435\u0442\u044c, \u043a\u0430\u043a\u0438\u0435 \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u044b \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0432\u043e\u043e\u0431\u0449\u0435 \u0431\u044b\u0432\u0430\u044e\u0442.<\/p>\n<details class=\"spoiler\">\n<summary>\u0421\u0441\u044b\u043b\u043a\u0438<\/summary>\n<div class=\"spoiler__content\">\n<ul>\n<li>\n<p><a href=\"https:\/\/github.com\/t0thkr1s\/allsafe\">Allsafe<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/hax0rgb\/InsecureShop\">InsecureShop<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/OWASP\/OMTG-Hacking-Playground\">OWASP: OMTG-Hacking-Playground<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"http:\/\/payatu.com\/damn-insecure-and-vulnerable-app\/\">Damn insecure and vulnerable App (DIVA)<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/rewanth1997\/Damn-Vulnerable-Bank\">Damn-Vulnerable-Bank<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/B3nac\/InjuredAndroid\">InjuredAndroid<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/logicalhacking\/DVHMA\">Damn Vulnerable Hybrid Mobile App (DVHMA)<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"http:\/\/securitycompass.github.io\/AndroidLabs\/setup.html\">ExploitMe labs by SecurityCompass<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/dineshshetty\/Android-InsecureBankv2\">InsecureBankv2<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/mwrlabs\/drozer\/releases\/download\/2.3.4\/sieve.apk\">Sieve (Vulnerable \u2018Password Manager\u2019 app)<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/tanprathan\/sievePWN\">sievePWN<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/SecurityCompass\/AndroidLabs\">Android Labs<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/CyberScions\/Digitalbank\">Digitalbank<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/CSPF-Founder\/DodoVulnerableBank\">Dodo vulnerable bank<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/dan7800\/VulnerableAndroidAppOracle\">Oracle android app<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"http:\/\/urdusecurity.blogspot.co.ke\/2014\/08\/Exploiting-debuggable-android-apps.html\">Urdu vulnerable app<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"http:\/\/imthezuk.blogspot.co.ke\/2011\/07\/creating-vulnerable-android-application.html?m=1\">MoshZuk<\/a>\u00a0<a href=\"https:\/\/dl.dropboxusercontent.com\/u\/37776965\/Work\/MoshZuk.apk\">File<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/appknox\/vulnerable-application\">Appknox<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/Lance0312\/VulnApp\">Vuln app<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/arroway\/dvfa\">Damn Vulnerable FirefoxOS Application<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/rafaeltoledo\/android-security\">Android security sandbox<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/oversecured\/ovaa\">OVAA (Oversecured Vulnerable Android App)<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/OWASP\/SecurityShepherd\">SecurityShepherd<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/OWASP\/owasp-mstg\/tree\/master\/Crackmes\">OWASP-mstg<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/htbridge\/pivaa\">Purposefully Insecure and Vulnerable Android Application (PIIVA)<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/mwrlabs\/drozer\/releases\/download\/2.3.4\/sieve.apk\">Sieve app<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/Lance0312\/VulnApp\">Vulnerable Android Application<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/rafaeltoledo\/android-security\">Android-security<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/shahenshah99\/VulnDroid\">VulnDroid<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/rossmarks.uk\/blog\/fridalab\/\">FridaLab<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/santoku-linux.com\/\">Santoku Linux &#8212; Mobile Security VM<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/jaiswalakshansh\/Vuldroid\">Vuldroid<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/DamnVulnerableCryptoApp\/DamnVulnerableCryptoApp\/\">DamnVulnerableCryptoApp<\/a><\/p>\n<\/li>\n<\/ul>\n<\/div>\n<\/details>\n<p><a class=\"anchor\" name=\"androidctf\" id=\"androidctf\"><\/a><\/p>\n<h3>CTF<\/h3>\n<p>\u0417\u0434\u0435\u0441\u044c &#8212; \u0431\u043e\u043b\u044c\u0448\u0430\u044f \u043f\u043e\u0434\u0431\u043e\u0440\u043a\u0430 \u0432\u0441\u0435\u0432\u043e\u0437\u043c\u043e\u0436\u043d\u044b\u0445 CTF-\u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439. \u041a\u0430\u043a \u043f\u0440\u0430\u0432\u0438\u043b\u043e, \u043e\u043d\u0438 \u043d\u0430\u043c\u043d\u043e\u0433\u043e \u0441\u043b\u043e\u0436\u043d\u0435\u0435, \u0447\u0435\u043c \u0443\u044f\u0437\u0432\u0438\u043c\u044b\u0435 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f \u0438\u0437 \u043f\u0440\u0435\u0434\u044b\u0434\u0443\u0449\u0435\u0433\u043e \u0440\u0430\u0437\u0434\u0435\u043b\u0430, \u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044e\u0442\u0441\u044f \u043d\u0430 \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0445 \u0441\u043e\u0440\u0435\u0432\u043d\u043e\u0432\u0430\u043d\u0438\u044f\u0445 \u043d\u0430 \u043a\u043e\u043d\u0444\u0435\u0440\u0435\u043d\u0446\u0438\u044f\u0445 \u043f\u043e \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438. <\/p>\n<p>\u041e\u0447\u0435\u043d\u044c \u043f\u043e\u043b\u0435\u0437\u043d\u043e \u0431\u044b\u0432\u0430\u0435\u0442 \u0441\u0430\u043c\u043e\u043c\u0443 \u043f\u0440\u043e\u0445\u043e\u0434\u0438\u0442\u044c \u0442\u0430\u043a\u0438\u0435 CTF \u0438\u043b\u0438 \u043f\u043e\u0432\u0442\u043e\u0440\u044f\u0442\u044c \u0434\u0435\u0439\u0441\u0442\u0432\u0438\u044f, \u043e\u043f\u0438\u0441\u0430\u043d\u043d\u044b\u0435 \u0432 \u043f\u0440\u043e\u0445\u043e\u0436\u0434\u0435\u043d\u0438\u0438, \u0447\u0442\u043e\u0431\u044b \u043d\u0430\u0431\u0438\u0442\u044c \u0440\u0443\u043a\u0443 \u0438 \u043f\u043e\u0434\u0441\u043c\u043e\u0442\u0440\u0435\u0442\u044c \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u043d\u043e\u0432\u044b\u0445 \u043f\u0440\u0438\u0435\u043c\u043e\u0432 \u0430\u043d\u0430\u043b\u0438\u0437\u0430.<\/p>\n<details class=\"spoiler\">\n<summary>\u0421\u0441\u044b\u043b\u043a\u0438<\/summary>\n<div class=\"spoiler__content\">\n<ul>\n<li>\n<p><a href=\"https:\/\/www.romainthomas.fr\/post\/20-09-r2con-obfuscated-whitebox-part1\/re.pwnme.1.0.apk\">r2-pay<\/a><\/p>\n<ul>\n<li>\n<p><a href=\"https:\/\/www.romainthomas.fr\/post\/20-09-r2con-obfuscated-whitebox-part1\/\">Walkthrow r2-pay<\/a><\/p>\n<\/li>\n<\/ul>\n<\/li>\n<li>\n<p><a href=\"https:\/\/maddiestone.github.io\/AndroidAppRE\/index.html\">Android App RE<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/Checkmarx\/Goatlin\">Kotlin Goat &#8212; insecure mobile application<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/infosecwriteups.com\/hacker101-ctf-android-challenge-writeups-f830a382c3ce\">Hacker101 CTF: Android Challenge Writeups<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/google\/google-ctf\/tree\/master\/2021\/quals\/pwn-tridroid\">Google CTF 2021<\/a><\/p>\n<\/li>\n<li>\n<p>Google CTF 2020<\/p>\n<ul>\n<li>\n<p><a href=\"https:\/\/github.com\/google\/google-ctf\/tree\/master\/2020\/quals\/reversing-android\">writeup 1<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/luker983\/google-ctf-2020\/tree\/master\/reversing\/android\">writeup 2<\/a><\/p>\n<\/li>\n<\/ul>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/csivitu\/CTF-Write-ups\/blob\/master\/HacktivityCon%20CTF\/Mobile\/Mobile%20One\/mobile_one.apk\">HacktivityCon CTF Mobile 2020<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/Hong5489\/TrendMicroCTF2020\/blob\/main\/mobile2\/Keybox.apk\">Trend Micro CTF 2020<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/tlamb96\/kgb_messenger\">KGB Messenger<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/medium.com\/bugbountywriteup\/asis-ctf-sharel-walkthrough-da32f3533b40?\">ASIS CTF \u2014 ShareL Walkthrough<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/kiyadesu\/android-reversing-challenges\">Android reversing challenges<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/atekippe\/SecDSM_April_2019_IOT_CTF_Android_APP\">Android app for IOT CTF<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/nowsecure\/cybertruckchallenge19\">CyberTruck Challenge 2019 (Detroit USA)<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/o-o-overflow\/dc2019q-vitor-public\">Matryoshka-style Android reversing challenge<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/nowsecure\/cybertruckchallenge19\">Cybertruckchallenge19<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/gitlab.com\/cybears\/fall-of-cybeartron\/tree\/master\/challenges\/rev\/youshallnotpass\">You Shall Not Pass &#8212; BSides Canberra 2019<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/antojoseph\/androidCTF\">BSidesSF 2018 CTF<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/luc10\/h1-702-2018-ctf-wu\">h1-702-2018-ctf-wu<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/ToulouseHackingConvention\/bestpig-reverse-android-serial\">THC CTF 2018 &#8212; Reverse &#8212; Android serial<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/reoky\/android-crackme-challenge\">Android crack me challenges<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/OWASP\/owasp-mstg\/tree\/master\/Crackmes\">OWASP crack me<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/rednaga\/training\/tree\/master\/DEFCON23\/challenges\">Rednaga Challenges<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/team-sik.org\/wp-content\/uploads\/2017\/06\/AES-Decrypt.apk_.zip\">Android Hacking Event 2017: AES-Decrypt<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/team-sik.org\/wp-content\/uploads\/2017\/06\/Token-Generator.apk_.zip\">Android Hacking Event 2017: Token-Generator<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/team-sik.org\/wp-content\/uploads\/2017\/06\/FlagValidator.apk_.zip\">Android Hacking Event 2017: Flag-Validator<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/team-sik.org\/wp-content\/uploads\/2017\/06\/YouCanHideButYouCannotRun.apk_.zip\">Android Hacking Event 2017: You Can Hide \u2013 But You Cannot Run<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/team-sik.org\/wp-content\/uploads\/2017\/06\/WhyShouldIPay.apk_.zip\">Android Hacking Event 2017: Why Should I Pay?<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/team-sik.org\/wp-content\/uploads\/2017\/06\/esoteric.apk_.zip\">Android Hacking Event 2017: Esoteric<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/team-sik.org\/wp-content\/uploads\/2016\/06\/strangecalculator.apk_.zip\">Android Hacking Event 2016: StrangeCalculator<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/team-sik.org\/wp-content\/uploads\/2016\/06\/ReverseMe.apk_.zip\">Android Hacking Event 2016: ReverseMe<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/team-sik.org\/wp-content\/uploads\/2016\/06\/aBunchOfNative.apk_.zip\">Android Hacking Event 2016: ABunchOfNative<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/team-sik.org\/wp-content\/uploads\/2016\/06\/dynChallenge.apk_.zip\">Android Hacking Event 2016: DynChallenge<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"http:\/\/shell-storm.org\/repo\/CTF\/PicoCTF-2014\/Forensics\/Pickle%20Jar%20-%2030\/\">PicoCTF-2014: Pickle Jar &#8212; 30<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"http:\/\/shell-storm.org\/repo\/CTF\/PicoCTF-2014\/crypto\/Revenge%20of%20the%20Bleichenbacher%20-%20170\/\">PicoCTF-2014: Revenge of the Bleichenbacher<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/huyle333\/androidmitllctf2013\">Android MIT LL CTF 2013<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/labs.mwrinfosecurity.com\/blog\/2013\/03\/11\/bsides-challenge\/\">Evil Planner Bsides Challenge<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"http:\/\/www.droidsec.org\/wiki\/#crack-mes\">Crack-Mes<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"http:\/\/shell-storm.org\/repo\/CTF\/GreHack-2012\/reverse_engineering\/100-GrehAndroidMe.apk\/\">GreHack-2012 &#8212; GrehAndroidMe<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"http:\/\/www.hackplayers.com\/2010\/12\/reto-android-crackme1.html\">Hackplayers.com Crackmes (in Spanish so an extra challenge): crackme 1<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"http:\/\/www.hackplayers.com\/2011\/12\/reto-14-android-crackme2.html\">Hackplayers.com Crackmes (in Spanish so an extra challenge): crackme 2<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"http:\/\/shell-storm.org\/repo\/CTF\/Hacklu-2011\/Reversing\/Space%20Station%200xB321054A%20(300)\/\">Hack.Lu&#8217;s CTF 2011 Reverse Engineering 300<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"http:\/\/androidcracking.blogspot.com\/2012\/01\/way-of-android-cracker-0-rewrite.html\">Androidcracking.blogspot.com&#8217;s Crackme\u2019s: cracker 0<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"http:\/\/androidcracking.blogspot.com\/2010\/10\/way-of-android-cracker-1.html\">Androidcracking.blogspot.com&#8217;s Crackme\u2019s: cracker 1<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"http:\/\/shell-storm.org\/repo\/CTF\/Insomnia'hack-2K11\/Reverse\/validate.apk\">Insomnia&#8217;hack-2K11<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"http:\/\/shell-storm.org\/repo\/CTF\/CSAW-2011\/Reversing\/Reversing101%20-%20100%20Points\/\">CSAW-2011: Reversing101<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"http:\/\/shell-storm.org\/repo\/CTF\/Defcon-19-quals\/Binary_L33tness\/b300\/\">Defcon-19-quals: Binary_L33tness<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/as0ler\/Android-Examples\">Crack me&#8217;s<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/anonim1133\/CTF\">Anonim1133<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/CvvT\/challenge_for_ctf\">Challenge4ctf<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/jhong01\/ctfpro\">Ctfpro<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/rajasaur\/CTFDroid\">CTFDroid<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/artwyman\/android_ctf\">Android_ctf<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/KappaEtaKappa\/Robot-CTF-android\">Robot CTF Android<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/CTFK\/cl.ctfk\">Cl.ctfk<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/cryptax\/challenges\">Cryptax<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/play.google.com\/store\/apps\/details?id=com.ellize.hackerguide\">ECHO &#8212; Ethical hacker Order<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"http:\/\/ctf.hpandro.raviramesh.info\/\">hpAndro Vulnerable Application Challenges<\/a><\/p>\n<\/li>\n<\/ul>\n<\/div>\n<\/details>\n<p><a class=\"anchor\" name=\"androidctfwalk\" id=\"androidctfwalk\"><\/a><\/p>\n<h3>\u041f\u0440\u043e\u0445\u043e\u0436\u0434\u0435\u043d\u0438\u0435 CTF<\/h3>\n<p>\u041e\u043f\u0438\u0441\u0430\u043d\u0438\u044f \u043f\u0440\u043e\u0445\u043e\u0436\u0434\u0435\u043d\u0438\u044f \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0445 CTF \u043e\u0447\u0435\u043d\u044c \u043f\u043e\u043b\u0435\u0437\u043d\u044b \u0441 \u0442\u043e\u0447\u043a\u0438 \u0437\u0440\u0435\u043d\u0438\u044f \u043c\u0435\u0445\u0430\u043d\u0438\u043a\u0438 \u0430\u043d\u0430\u043b\u0438\u0437\u0430. \u0412 \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0441\u0442\u0430\u0442\u044c\u044f\u0445 \u043f\u0440\u0438\u0441\u0443\u0442\u0441\u0442\u0432\u0443\u044e\u0442 \u0438 \u0441\u0430\u043c\u0438 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f, \u043d\u0430 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043c\u043e\u0436\u043d\u043e \u043f\u043e\u0442\u0440\u0435\u043d\u0438\u0440\u043e\u0432\u0430\u0442\u044c\u0441\u044f.<\/p>\n<h4>Ru<\/h4>\n<details class=\"spoiler\">\n<summary>\u0421\u0441\u044b\u043b\u043a\u0438<\/summary>\n<div class=\"spoiler__content\">\n<ul>\n<li>\n<p><a href=\"https:\/\/habr.com\/ru\/company\/deliveryclub\/blog\/588026\/\">\u0420\u0435\u0432\u0435\u0440\u0441 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0433\u043e \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f \u043e\u0442 Delivery Club: \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u044b \u043a\u043e\u043d\u043a\u0443\u0440\u0441\u0430<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/fi5t.xyz\/posts\/neoquest2022-writeup-task7\/\">NeoQUEST 2022: \u0417\u0430\u0434\u0430\u043d\u0438\u0435 7<\/a><\/p>\n<\/li>\n<\/ul>\n<\/div>\n<\/details>\n<h4>En<\/h4>\n<details class=\"spoiler\">\n<summary>\u0421\u0441\u044b\u043b\u043a\u0438<\/summary>\n<div class=\"spoiler__content\">\n<ul>\n<li>\n<p>Solving CTF with Frida<\/p>\n<ul>\n<li>\n<p><a href=\"https:\/\/cmrodriguez.me\/blog\/hpandro-1\/\">Part 1<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/cmrodriguez.me\/blog\/hpandro-2\/\">Part 2<\/a><\/p>\n<\/li>\n<\/ul>\n<\/li>\n<li>\n<p>H@cktivityCon 2021 CTF<\/p>\n<ul>\n<li>\n<p><a href=\"https:\/\/blog.ikuamike.io\/posts\/2021\/hacktivitycon-2021-ctf\/\">writeup 1<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/infosecwriteups.com\/h-cktivitycon-2021-ctf-writeup-reactor-android-challenge-85d1d03d4502\">writeup 2<\/a><\/p>\n<\/li>\n<\/ul>\n<\/li>\n<li>\n<p><a href=\"https:\/\/evabssi.com\/write-up-du-ctf-android\/\">Write-up du CTF Android<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/cellebrite.com\/en\/part-1-walk-through-of-answers-to-the-2021-ctf-investigating-heisenbergs-android-device\/\">Cellebrite 2021 CTF \u2013 Investigating Heisenberg\u2019s Android Device<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/cellebrite.com\/en\/part-3-walk-through-of-answers-to-the-2021-ctf-marshas-iphone-ffs-and-backup\/\">Cellebrite 2021 CTF \u2013 Marsha\u2019s iPhone (FFS and Backup)<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/cellebrite.com\/en\/part-4-walk-through-of-answers-to-the-2021-ctf-beths-iphone\/\">Cellebrite 2021 CTF \u2013 Beth\u2019s iPhone<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/medium.com\/@williamskosasi\/cellebrite-ctf-2021-writeup-b73d821a708\">Cellebrite CTF 2021 Writeup<\/a><\/p>\n<\/li>\n<li>\n<p>H@cktivitycon 2021 \u2014 Mobile challenge writeup<\/p>\n<ul>\n<li>\n<p><a href=\"https:\/\/desterhuizen.medium.com\/h-cktivitycon-2021-mobile-challenge-writeup-2e1a8b0bc9d6\">writeup 1<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/infosecwriteups.com\/h-cktivitycon-2021-ctf-writeup-reactor-android-challenge-85d1d03d4502\">writeup 2<\/a><\/p>\n<\/li>\n<\/ul>\n<\/li>\n<li>\n<p><a href=\"https:\/\/infosecwriteups.com\/ctf-write-up-kryptonite-293f2f66c004\">CTF Write-Up: Kryptonite<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/Class-3E\/NahamCon2021-Writeups\/tree\/master\/Mobile\/Resourceful\">NahamCon 2021 Writeups<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/belkasoft.com\/belkactf-may2021-writeup\">BELKASOFT CTF MAY 2021: WRITE-UP<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/tatocaster.medium.com\/trend-micro-ctf-2020-keybox-writeup-cf5a69d2d091\">Trend Micro CTF 2020 \u2014 Keybox writeup<\/a><\/p>\n<\/li>\n<li>\n<p>STACK the Flags 2020: Mobile Challenges Write Up<\/p>\n<ul>\n<li>\n<p><a href=\"https:\/\/suntanchicken.medium.com\/stack-the-flags-2020-mobile-challenges-write-up-493578091e07\">writeup 1<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/Hong5489\/TrendMicroCTF2020\/tree\/main\/mobile2\">writeup 2<\/a><\/p>\n<\/li>\n<\/ul>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.goggleheadedhacker.com\/blog\/post\/19\">HacktivityCon CTF Mobile Writeup<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.ikuamike.io\/posts\/2020\/cyberspacectf-zulumeats3\/\">CyberSpaceKenya CTF<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.stark4n6.com\/2020\/06\/magnet-virtual-summit-2020-ctf-android.html\">Magnet Virtual Summit 2020 CTF (Anroid)<\/a><\/p>\n<\/li>\n<li>\n<p>Google CTF 2020: Android<\/p>\n<ul>\n<li>\n<p><a href=\"https:\/\/blackbeard666.github.io\/pwn_exhibit\/content\/2020_CTF\/GoogleCTF\/re_android\/android_writeup.html\">writeup 1<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/vsnrain\/ctf-writeups\/blob\/master\/2020\/googlectf\/README.md\">writeup 2<\/a><\/p>\n<\/li>\n<\/ul>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.ikuamike.io\/posts\/2020\/razictf-chasingalock-writeup\/\">RaziCTF 2020 WriteUp: Chasing a lock<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.petermstewart.net\/dfa-ccsc-spring-2020-ctf-apple-ios-forensics-with-ileapp\/\">DFA\/CCSC Spring 2020 CTF<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/klassiker\/ctf-writeups\/blob\/master\/2020\/appsec-il\/greatsuccess.md\">AppSecIL CTF)<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/dev.to\/igotinfected\/spoofing-an-ios-device-tsa-techie-sunshinectf-2020-write-up-2l0c\">SunshineCTF 2020 write-up<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/medium.com\/swlh\/reverse-engineering-and-modifying-an-android-game-apk-ctf-c617151b874c\">Reverse engineering and modifying an Android game (.apk) \u2014 CTF<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/anee.me\/droidcon-sec-t-ctf-2019-d796be91bb3f\">DroidCon, SEC-T CTF 2019<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/medium.com\/tsscyber\/ctf-writeup-you-shall-not-pass-2c7a9254549b\">You Shall Not Pass &#8212; BSides Canberra 2019<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/medium.com\/bugbountywriteup\/cybertruck-challenge-2019-android-ctf-e39c7f796530\">CyberTruck Challenge 2019 \u2014 Android CTF<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/aadityapurani.com\/2019\/03\/07\/bsidessf-ctf-2019-mobile-track\/\">Bsidessf-ctf-2019-mobile-track<\/a><\/p>\n<\/li>\n<li>\n<p>BsidesSF CTF &#8212; Challenge<\/p>\n<ul>\n<li>\n<p><a href=\"https:\/\/medium.com\/@itsc0rg1\/bsidessf-ctf-challenge-write-up-part-1-e849bc917d37\">Part 1<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/medium.com\/@itsc0rg1\/bsidessf-ctf-challenge-write-up-part-2-f8f597be659\">Part 2<\/a><\/p>\n<\/li>\n<\/ul>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.stark4n6.com\/2019\/04\/ctf-on-budget-magnet-user-summit-2019_9.html\">CTF on a Budget &#8212; Magnet User Summit 2019 &#8212; Mobile<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/corb3nik.github.io\/blog\/h1-202-2018\/h1-202-ctf\">H1 202 2018 \/ H1 202 CTF<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/aadityapurani.com\/2018\/06\/25\/h1-702-ctf-writeups\/#mobile\">H1-702 CTF (Capture the Flag)<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/medium.com\/@antojoseph_1995\/bsidessf-2018-ctf-android-reversing-forensics-challenge-f5522664b6a2\">BSidesSF 2018 CTF \u2014 Android Reversing\/Forensic Challenge<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.hackingarticles.in\/hack-the-android4-walkthrough-ctf-challenge\/\">Hack the Android4: Walkthrough (CTF Challenge)<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/w0y.at\/writeup\/2018\/07\/02\/google-ctf-quals-2018-shall-we-play-a-game.html\">Google CTF Quals 2018<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/mstajbakhsh.ir\/ilam-ctf-android-reverse-writeup\/\">Ilam CTF: Android Reverse WriteUp<\/a><\/p>\n<\/li>\n<li>\n<p>8st SharifCTF Android WriteUps:<\/p>\n<ul>\n<li>\n<p><a href=\"https:\/\/mstajbakhsh.ir\/8st-sharifctf-android-writeups-vol\/\">Vol I<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/mstajbakhsh.ir\/8st-sharifctf-android-writeups-vol-ii\/\">Vol II<\/a><\/p>\n<\/li>\n<\/ul>\n<\/li>\n<li>\n<p><a href=\"https:\/\/saarsec.rocks\/2018\/11\/27\/Gunshop.html\">ASIS 2018 Finals: Gunshop<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/pwning.re\/2018\/02\/23\/h1-202-writeup\/\">H1-202 CTF &#8212; Writeup<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.manchestergreyhats.co.uk\/2018\/03\/28\/m1con-ctf-writeup\/\">M1Con CTF Write up<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.manchestergreyhats.co.uk\/2018\/04\/18\/aes-decode-with-cyberchef\/\">AES decode with Cyberchef<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/ctfs\/write-ups-2017\/tree\/10bad9bd24b3f84c761faa4d78e223a3a29b2959\/bsidessf-ctf-2017\/reversing\/pinlock-150\">BSides San Francisco CTF 2017 : pinlock-150<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/ctfs\/write-ups-2017\/tree\/10bad9bd24b3f84c761faa4d78e223a3a29b2959\/bsidessf-ctf-2017\/reversing\/flag-receiver-200\">BSides San Francisco CTF 2017 : flag-receiver-200<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.skullsecurity.org\/2017\/bsidessf-ctf-wrap-up\">BSidesSF CTF wrap-up<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/medium.com\/@itsc0rg1\/my-mobile-challenge-and-bsides-sf-ctf-f9fc4dfca60\">itsC0rg1&#8217;s mobile challenge and BSides SF CTF<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/ctfs\/write-ups-2017\/tree\/6a3df5bcece6f952cb60db4a3ae2ce97a189b62d\/insomnihack-teaser-2017\/mobile\/mindreader-250\">Insomni&#8217;hack Teaser 2017 : mindreader-250<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/gray-panda\/grayrepo\/tree\/1a0c2e033621af9900932252cda31c14a4fbbce8\/2017_labyREnth\/chal\/mob1_ezdroid\">2017_labyREnth: mob1_ezdroid<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/gray-panda\/grayrepo\/tree\/1a0c2e033621af9900932252cda31c14a4fbbce8\/2017_labyREnth\/chal\/mob2_routerlocker\">2017_labyREnth: mob2_routerlocker<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/gray-panda\/grayrepo\/tree\/6a0d2fce53b71135286fac3c323b712af08d6913\/2017_labyREnth\/chal\/mob3_showmewhatyougot\">2017_labyREnth: mob3_showmewhatyougot<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/gray-panda\/grayrepo\/tree\/ffbf17ec172f1624ba6607cc7756ed7b99d95b63\/2017_labyREnth\/chal\/mob4_androidpan\">2017_labyREnth: mob4_androidpan<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/gray-panda\/grayrepo\/tree\/1a0c2e033621af9900932252cda31c14a4fbbce8\/2017_labyREnth\/chal\/mob5_iotctf\">2017_labyREnth: mob5_iotctf<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"http:\/\/researchcenter.paloaltonetworks.com\/2016\/09\/unit42-labyrenth-capture-the-flag-ctf-mobile-track-solutions\/\">LabyREnth<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/gray-panda\/grayrepo\/tree\/f054b5d66af66ff684449dcb8e6c9e146213971b\/2016_labyREnth\/mob1_lastchance\">2016_labyREnth: mob1_lastchance<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/gray-panda\/grayrepo\/tree\/f054b5d66af66ff684449dcb8e6c9e146213971b\/2016_labyREnth\/mob2_cups\">2016_labyREnth: mob2_cups<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/gray-panda\/grayrepo\/tree\/f054b5d66af66ff684449dcb8e6c9e146213971b\/2016_labyREnth\/mob3_watt\">2016_labyREnth: mob3_watt<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/gray-panda\/grayrepo\/tree\/f054b5d66af66ff684449dcb8e6c9e146213971b\/2016_labyREnth\/mob4_swip3r\">2016_labyREnth: mob4_swip3r<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/gray-panda\/grayrepo\/tree\/f054b5d66af66ff684449dcb8e6c9e146213971b\/2016_labyREnth\/mob5_ioga\">2016_labyREnth: mob5_ioga<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/gray-panda\/grayrepo\/tree\/f054b5d66af66ff684449dcb8e6c9e146213971b\/2016_labyREnth\/mob6_ogmob\">2016_labyREnth: mob6_ogmob<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/gray-panda\/grayrepo\/tree\/76925522bb0ce3a9615f0022300d525a958bc260\/2016_holidayhackchallenge\/01\">Holiday hack challenge: Part 01<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/gray-panda\/grayrepo\/tree\/76925522bb0ce3a9615f0022300d525a958bc260\/2016_holidayhackchallenge\/02\">Holiday hack challenge: Part 02<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/gray-panda\/grayrepo\/tree\/76925522bb0ce3a9615f0022300d525a958bc260\/2016_holidayhackchallenge\/04a\">Holiday hack challenge: Part 04a<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/gray-panda\/grayrepo\/tree\/76925522bb0ce3a9615f0022300d525a958bc260\/2016_holidayhackchallenge\/04b\">Holiday hack challenge: Part 04b<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/gray-panda\/grayrepo\/tree\/76925522bb0ce3a9615f0022300d525a958bc260\/2016_holidayhackchallenge\/04c\">Holiday hack challenge: Part 04c<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/gray-panda\/grayrepo\/tree\/76925522bb0ce3a9615f0022300d525a958bc260\/2016_holidayhackchallenge\/04d\">Holiday hack challenge: Part 04d<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/gray-panda\/grayrepo\/tree\/76925522bb0ce3a9615f0022300d525a958bc260\/2016_holidayhackchallenge\/04e\">Holiday hack challenge: Part 04e<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/gray-panda\/grayrepo\/tree\/76925522bb0ce3a9615f0022300d525a958bc260\/2016_holidayhackchallenge\/04f\">Holiday hack challenge: Part 04f<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/gray-panda\/grayrepo\/tree\/76925522bb0ce3a9615f0022300d525a958bc260\/2016_holidayhackchallenge\/05\">Holiday hack challenge: Part 5<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/ctfs\/write-ups-2016\/tree\/master\/0ctf-2016\/mobile\">0ctf-2016<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/ctfs\/write-ups-2016\/tree\/39e9a0e2adca3a3d0d39a6ae24fa51196282aae4\/google-ctf-2016\/mobile\">Google-ctf-2016<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/security.claudio.pt\/post\/googlectf\/\">Google-ctf-2016: ill intentions 1<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/d3rezz\/Google-Capture-The-Flag-2016\">Google-ctf-2016: ill intentions 2<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/ctfs\/write-ups-2016\/tree\/c35549398f88d3755dc31a8fe995f15ef876ee18\/cyber-security-challenge-belgium-2016-qualifiers\/Mobile%20Security\">Cyber-security-challenge-belgium-2016-qualifiers<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/ctfs\/write-ups-2016\/tree\/274307f43140bb4a52e0729ecf1282628fb22f5b\/su-ctf-2016\/reverse\/android-app-100\">Su-ctf-2016 &#8212; android-app-100<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/ctfs\/write-ups-2016\/tree\/274307f43140bb4a52e0729ecf1282628fb22f5b\/hackcon-ctf-2016\/reversing\/you-cant-see-me-150\">Hackcon-ctf-2016 &#8212; you-cant-see-me-150<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"http:\/\/aukezwaan.nl\/write-ups\/rc3-ctf-2016-my-lil-droid-100-points\/\">RC3 CTF 2016: My Lil Droid<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/ctfs\/write-ups-2016\/tree\/39e9a0e2adca3a3d0d39a6ae24fa51196282aae4\/cyber-security-challenge-belgium-2016-qualifiers\/Mobile%20Security\/Dexter\">Cyber Security Challenge 2016: Dexter<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/ctfs\/write-ups-2016\/tree\/39e9a0e2adca3a3d0d39a6ae24fa51196282aae4\/cyber-security-challenge-belgium-2016-qualifiers\/Mobile%20Security\/Phishing-is-not-a-crime\">Cyber Security Challenge 2016: Phishing is not a crime<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/ctfs\/write-ups-2016\/tree\/39e9a0e2adca3a3d0d39a6ae24fa51196282aae4\/google-ctf-2016\/mobile\/little-bobby-application-250\">google-ctf-2016 : little-bobby-application-250<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/ctfs\/write-ups-2015\/tree\/9b3c290275718ff843c409842d738e6ef3e565fd\/rctf-quals-2015\/mobile\">Rctf-quals-2015<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/ctfs\/write-ups-2015\/tree\/9b3c290275718ff843c409842d738e6ef3e565fd\/insomni-hack-ctf-2015\/mobile\">Insomni-hack-ctf-2015<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/ctfs\/write-ups-2015\/tree\/9b3c290275718ff843c409842d738e6ef3e565fd\/0ctf-2015\/mobile\">0ctf-2015<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/ctfs\/write-ups-2015\/tree\/9b3c290275718ff843c409842d738e6ef3e565fd\/cyber-security-challenge-2015\/mobile-application-security\">Cyber-security-challenge-2015<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/ctfs\/write-ups-2015\/tree\/9b3c290275718ff843c409842d738e6ef3e565fd\/trend-micro-ctf-2015\/analysis\/offensive-200\">Trend-micro-ctf-2015: offensive-200<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/ctfs\/write-ups-2015\/tree\/9b3c290275718ff843c409842d738e6ef3e565fd\/codegate-ctf-2015\/reversing\/dodocrackme2\">codegate-ctf-2015: dodocrackme2<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/ctfs\/write-ups-2015\/tree\/9b3c290275718ff843c409842d738e6ef3e565fd\/seccon-quals-ctf-2015\/binary\/reverse-engineering-android-apk-1\">Seccon-quals-ctf-2015: reverse-engineering-android-apk-1<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/ctfs\/write-ups-2015\/tree\/9b3c290275718ff843c409842d738e6ef3e565fd\/seccon-quals-ctf-2015\/unknown\/reverse-engineering-android-apk-2\">Seccon-quals-ctf-2015 &#8212; reverse-engineering-android-apk-2<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/ctfs\/write-ups-2015\/tree\/9b3c290275718ff843c409842d738e6ef3e565fd\/pragyan-ctf-2015\/android\">Pragyan-ctf-2015<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/ctfs\/write-ups-2015\/tree\/9b3c290275718ff843c409842d738e6ef3e565fd\/volgactf-quals-2015\/web\/malware\">Volgactf-quals-2015<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/ctfs\/write-ups-2015\/tree\/9b3c290275718ff843c409842d738e6ef3e565fd\/opentoall-ctf-2015\/misc\/android-oh-no\">Opentoall-ctf-2015: android-oh-no<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/ctfs\/write-ups-2015\/tree\/9b3c290275718ff843c409842d738e6ef3e565fd\/32c3-ctf-2015\/reversing\/libdroid-150\">32c3-ctf-2015: libdroid-150<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/ctfs\/write-ups-2015\/tree\/9b3c290275718ff843c409842d738e6ef3e565fd\/polictf-2015\/reversing\/crack-me-if-you-can\">Polictf 2015: crack-me-if-you-can<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/ctfs\/write-ups-2015\/tree\/9b3c290275718ff843c409842d738e6ef3e565fd\/icectf-2015\/forensics\/husavik\">Icectf-2015: Husavik<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/ctfs\/write-ups-2014\/tree\/b02bcbb2737907dd0aa39c5d4df1d1e270958f54\/qiwi-ctf-2014\/not-so-one-time\">Qiwi-ctf-2014: not-so-one-time<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/ctfs\/write-ups-2014\/tree\/b02bcbb2737907dd0aa39c5d4df1d1e270958f54\/pico-ctf-2014\/forensics\/droid-app-80\">Fdfpico-ctf-2014: droid-app-80<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/ctfs\/write-ups-2014\/tree\/b02bcbb2737907dd0aa39c5d4df1d1e270958f54\/su-ctf-quals-2014\/commercial_application\">Su-ctf-quals-2014: commercial_application<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/ctfs\/write-ups-2014\/tree\/b02bcbb2737907dd0aa39c5d4df1d1e270958f54\/defkthon-ctf\/web-300\">defkthon-ctf 2014: web-300<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/ctfs\/write-ups-2014\/tree\/b02bcbb2737907dd0aa39c5d4df1d1e270958f54\/secuinside-ctf-prequal-2014\/wooyatalk\">secuinside-ctf-prequal-2014: wooyatalk<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/ctfs\/write-ups-2014\/tree\/b02bcbb2737907dd0aa39c5d4df1d1e270958f54\/qiwi-ctf-2014\/easydroid\">Qiwi-ctf-2014: easydroid<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/ctfs\/write-ups-2014\/tree\/b02bcbb2737907dd0aa39c5d4df1d1e270958f54\/qiwi-ctf-2014\/stolen-prototype\">Qiwi-ctf-2014: stolen-prototype<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/ctfs\/write-ups-2014\/tree\/b02bcbb2737907dd0aa39c5d4df1d1e270958f54\/tinyctf-2014\/ooooooh-what-does-this-button-do\">TinyCTF 2014: Ooooooh! What does this button do?<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/ctfs\/write-ups-2014\/tree\/b02bcbb2737907dd0aa39c5d4df1d1e270958f54\/31c3-ctf-2014\/pwn\/nokia-1337\">31c3-ctf-2014: Nokia 1337<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/ctfs\/write-ups-2014\/tree\/b02bcbb2737907dd0aa39c5d4df1d1e270958f54\/asis-ctf-finals-2014\/numdroid\">Asis-ctf-finals-2014: numdroid<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"http:\/\/shell-storm.org\/repo\/CTF\/PicoCTF-2014\/Forensics\/Droid%20App%20-%2080\/\">PicoCTF-2014: Droid App<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"http:\/\/shell-storm.org\/repo\/CTF\/NDH2k14-wargames\/crackme200-ChunkNorris\/\">NDH2k14-wargames: crackme200-ChunkNorris<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/ctfs\/write-ups-2013\/tree\/816de23a940856c10987b5047823de48a192c270\/hack-lu-ctf-2013\/internals\/Robot-Plans\">Hack.lu CTF 2013: Robot Plans<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/ctfs\/write-ups-2013\/tree\/816de23a940856c10987b5047823de48a192c270\/csaw-quals-2013\/web\/herpderper-300\">CSAW Quals CTF 2015: Herpderper<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"http:\/\/andromedactf.wordpress.com\/2013\/01\/02\/atast-ctf-2012-bin300chall5\/\">Atast CTF 2012 Bin 300<\/a><\/p>\n<\/li>\n<\/ul>\n<\/div>\n<\/details>\n<p><a class=\"anchor\" name=\"androidvideo\" id=\"androidvideo\"><\/a><\/p>\n<h3>\u0412\u0438\u0434\u0435\u043e<\/h3>\n<p>\u0411\u043e\u043b\u044c\u0448\u0430\u044f \u043f\u043e\u0434\u0431\u043e\u0440\u043a\u0430 \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0445 \u0432\u0438\u0434\u0435\u043e, \u043d\u0430\u0447\u0438\u043d\u0430\u044f \u043e\u0442 \u043e\u0431\u0443\u0447\u0430\u044e\u0449\u0438\u0445, \u0437\u0430\u043a\u0430\u043d\u0447\u0438\u0432\u0430\u044f \u0434\u043e\u043a\u043b\u0430\u0434\u0430\u043c\u0438 \u0441 \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0445 \u043a\u043e\u043d\u0444\u0435\u0440\u0435\u043d\u0446\u0438\u0439. \u0422\u0430\u043c, \u0433\u0434\u0435 \u044d\u0442\u043e \u0430\u043a\u0442\u0443\u0430\u043b\u044c\u043d\u043e, \u0441\u0440\u0430\u0437\u0443 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u044b \u0441\u0441\u044b\u043b\u043a\u0438 \u043d\u0430 \u043c\u0430\u0442\u0435\u0440\u0438\u0430\u043b\u044b (\u0441\u043b\u0430\u0439\u0434\u044b, \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 \u0438 \u0442.\u0434.).<\/p>\n<h4>Ru<\/h4>\n<details class=\"spoiler\">\n<summary>\u0421\u0441\u044b\u043b\u043a\u0438<\/summary>\n<div class=\"spoiler__content\">\n<ul>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=1AjWxpWMBBE\">Android Broadcast &#8212; \u0411\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u044c \u043c\u043e\u0431\u0438\u043b\u044c\u043d\u044b\u0445 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=zeU2wlcj_Bw\">\u0412\u043e\u043f\u0440\u043e\u0441\u044b \u043d\u043e\u0432\u0438\u0447\u043a\u043e\u0432 \u043e \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 Android<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=x1d1ZnxHUms&amp;list=PLGlZ_ld11os9X1FSi3GSLfBqpYfXXX6qr&amp;index=6\">\u041a\u0430\u043a \u0432\u0437\u043b\u0430\u043c\u044b\u0432\u0430\u044e\u0442 android-\u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f \u0438 \u0447\u0442\u043e \u043f\u043e\u0441\u043b\u0435 \u044d\u0442\u043e\u0433\u043e \u0431\u044b\u0432\u0430\u0435\u0442 (Workshop)<\/a><\/p>\n<ul>\n<li>\n<p><a href=\"https:\/\/github.com\/Fi5t\/workshop-devfest-2020\">\u041c\u0430\u0442\u0435\u0440\u0438\u0430\u043b\u044b \u0438 \u043a\u043e\u0434<\/a><\/p>\n<\/li>\n<\/ul>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=x_COvmEIyko\">Android Broadcast &#8212; \u0411\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u044c Android \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=LpOvHhpcVG4\">\u0425\u0440\u0430\u043d\u0435\u043d\u0438\u0435 \u043a\u043b\u044e\u0447\u0435\u0439 API \u0432 \u043d\u0430\u0442\u0438\u0432\u043d\u043e\u043c \u043a\u043e\u0434\u0435<\/a><\/p>\n<ul>\n<li>\n<p><a href=\"https:\/\/github.com\/Android-Guards\/storing-api-keys\">\u0420\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0439 \u0441 \u043f\u0440\u0438\u043c\u0435\u0440\u0430\u043c\u0438 \u0438\u0437 \u0432\u0438\u0434\u0435\u043e<\/a><\/p>\n<\/li>\n<\/ul>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=Xn6CSqJpf6I\">\u041a\u0430\u043a \u043f\u0440\u0438\u043a\u0440\u0443\u0442\u0438\u0442\u044c \u0438 \u043e\u0442\u043b\u043e\u043c\u0430\u0442\u044c SSL pinning. CetificatePinner &amp; NSC vs Reverse Engineer<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=oZEFUA-unDo\">\u041e\u0442\u043a\u0440\u044b\u0442\u0430\u044f \u043b\u0435\u043a\u0446\u0438\u044f: \u041e\u0441\u043d\u043e\u0432\u044b \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0439 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0434\u043b\u044f \u043c\u043e\u0431\u0438\u043b\u044c\u043d\u044b\u0445 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u043e\u0432<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=zdFeqJAlqa4\">\u0414\u0438\u043d\u0430\u043c\u0438\u0447\u0435\u0441\u043a\u0438\u0439 \u0430\u043d\u0430\u043b\u0438\u0437 \u043c\u043e\u0431\u0438\u043b\u044c\u043d\u044b\u0445 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/youtu.be\/2Mtdo84dI4M\">\u041f\u043e \u0441\u043b\u0435\u0434\u0430\u043c Google I\/O 2021: \u0411\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u044c \u0438 \u043f\u0440\u0438\u0432\u0430\u0442\u043d\u043e\u0441\u0442\u044c<\/a><\/p>\n<\/li>\n<\/ul>\n<\/div>\n<\/details>\n<h4>En<\/h4>\n<details class=\"spoiler\">\n<summary>\u0421\u0441\u044b\u043b\u043a\u0438<\/summary>\n<div class=\"spoiler__content\">\n<ul>\n<li>\n<p><a href=\"https:\/\/youtu.be\/U6qTcpCfuFc\">Securing the System: A Deep Dive into Reversing Android Pre-Installed Apps<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/playlist?list=PL3jdfxUyXxoyG6qEkaTMq0iWaaVps2SLa\">Android App Reverse Engineering Workshop<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/youtube.com\/watch?v=lmHkfKXuN4A\">Android Code Deobfuscation<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=zxkbyyl-9b8&amp;feature=youtu.be\">Android Security Symposium 2020. Day 1<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=k0doJkhc4So\">Android Security Symposium 2020. Day 2<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=uWT15hEM1dQ\">B3nac &#8212; Android application exploitation<\/a><\/p>\n<ul>\n<li>\n<p><a href=\"https:\/\/docs.google.com\/presentation\/d\/15bi5pndttfCzMEMw8GT2oCHCJvHx_a8YszkkSMtp_jE\/edit?usp=drivesdk\">\u0421\u043b\u0430\u0439\u0434\u044b Android application exploitation<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/B3nac\/InjuredAndroid\">\u041f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0435 Injured Android<\/a><\/p>\n<\/li>\n<\/ul>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=WwsE4Tljmy8\">Deep Link Route and Validation Bypasses<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=lg1sN8njSYs\">Exploiting Android deep links and exported components<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=PMKnPaGWxtg\">Mobile Hacking Workshop<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=iMNs8YAy6pk\">Hacking Android Apps with Frida<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=gCI8CIILP_0&amp;list=PLzJZrgVJE8BYZvsHFe2M3FjjTmjbcT6hH&amp;index=6\">Practical security for Android apps<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=LFJzT8rQeYo&amp;list=PLzJZrgVJE8BYZvsHFe2M3FjjTmjbcT6hH&amp;index=8\">Modern security for Android Developers<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=weiYq_UR19I&amp;list=PLzJZrgVJE8BYZvsHFe2M3FjjTmjbcT6hH&amp;index=7\">Modern Android Hacking<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=39fGj5v5s1g&amp;list=PLzJZrgVJE8BYZvsHFe2M3FjjTmjbcT6hH&amp;index=9\">Defending Your Users<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=a8Gh7d8GebA\">ANDROID APP SECURITY BASICS<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=qS5PkC-37io\">HACKING ANDROID WebViews<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=BijZmutY0CQ\">\u0426\u0438\u043a\u043b \u0432\u0438\u0434\u043e\u0441\u043e\u0432 \u043f\u043e Android Reverse Engineering<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=squuwVQiPgg\">Android Exploits 101 Workshop<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=hBVwr2ErQCw&amp;list=PLWz5rJ2EKKc_KamvEnBDJrBptAfQni7Ig&amp;index=17\">Best practices for making your app private by design<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=JqLcTFpXreg&amp;list=PLWz5rJ2EKKc_KamvEnBDJrBptAfQni7Ig&amp;index=19\">Android Memory Safety Tools<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=TAYtJfV2LuA&amp;list=PLWz5rJ2EKKc_KamvEnBDJrBptAfQni7Ig&amp;index=20\">The most interesting (and unexpected) submissions to the Android Security Bulletin<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=TyxL78e5Bag&amp;list=PLWz5rJ2EKKc_KamvEnBDJrBptAfQni7Ig&amp;index=25\">Introducing Play Integrity API: Protect your apps and games<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=jrnxYewex5w\">The Mobile Sec Special<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/playlist?list=PLGJe0xGh7cH2lszCZ7qwsqouEK23XCMGp\">Mobile App Pentesting<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=RawqXSslsQk\">Easy mobile penetration testing with Brida<\/a><\/p>\n<ul>\n<li>\n<p><a href=\"https:\/\/github.com\/federicodotta\/Brida\">Brida Github<\/a><\/p>\n<\/li>\n<\/ul>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=9JuBUpRPLRs\">The Worst Mobile Apps<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=KeWcZ-Dd6tA\">Learn modding Unity apps and games with Frida<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=BiMU2CalCqU\">Forging Golden Hammer Against Android App Protections by Georges-Bastien Michel<\/a><\/p>\n<ul>\n<li>\n<p><a href=\"https:\/\/github.com\/FrenchYeti\/unrasp\">\u0420\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0439 \u0441 \u043a\u043e\u0434\u043e\u043c \u0438 \u0441\u043b\u0430\u0439\u0434\u0430\u043c\u0438<\/a><\/p>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/div>\n<\/details>\n<p><a class=\"anchor\" name=\"androidpodcast\" id=\"androidpodcast\"><\/a><\/p>\n<h3>\u041f\u043e\u0434\u043a\u0430\u0441\u0442\u044b<\/h3>\n<p>\u0412 \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u0443\u044e \u043a\u0430\u0442\u0435\u0433\u043e\u0440\u0438\u044e \u0432\u044b\u0434\u0435\u043b\u0438\u043b \u043f\u043e\u0434\u043a\u0430\u0441\u0442\u044b. \u0412 \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043f\u043e Android \u043c\u043d\u0435 \u0434\u0430\u0436\u0435 \u0443\u0434\u0430\u043b\u043e\u0441\u044c \u043f\u0440\u0438\u043d\u044f\u0442\u044c \u0443\u0447\u0430\u0441\u0442\u0438\u0435.<\/p>\n<h4>Ru<\/h4>\n<details class=\"spoiler\">\n<summary>\u0421\u0441\u044b\u043b\u043a\u0438<\/summary>\n<div class=\"spoiler__content\">\n<ul>\n<li>\n<p><a href=\"https:\/\/podcasts.apple.com\/us\/podcast\/community-podcast-1-%D0%BF%D0%B0%D0%B2%D0%B5%D0%BB-%D0%B2%D0%B0%D1%81%D0%B8%D0%BB%D1%8C%D0%B5%D0%B2-bluethooth-nfc-%D0%B8\/id1552280775?i=1000507755864\">Community Podcast #1: \u041f\u0430\u0432\u0435\u043b \u0412\u0430\u0441\u0438\u043b\u044c\u0435\u0432 | Bluethooth, NFC \u0438 \u0414\u0438\u0444\u0444\u0438-\u0425\u044d\u043b\u043b\u043c\u0430\u043d \u043f\u043e\u0434 \u044d\u043b\u043b\u0438\u043f\u0442\u0438\u0447\u0435\u0441\u043a\u0438\u043c\u0438 \u043a\u0440\u0438\u0432\u044b\u043c\u0438<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/podcasts.apple.com\/us\/podcast\/community-podcast-2-%D1%81%D0%B5%D1%80%D0%B3%D0%B5%D0%B9-%D1%82%D0%BE%D1%88%D0%B8%D0%BD-bug-bounty-oversecured\/id1552280775?i=1000513089218\">Community Podcast #2: \u0421\u0435\u0440\u0433\u0435\u0439 \u0422\u043e\u0448\u0438\u043d | Bug Bounty, Oversecured \u0438 \u0436\u043e\u043f\u043e\u0447\u0430\u0441\u044b<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/podcasts.apple.com\/us\/podcast\/%D1%82%D1%80%D0%B0%D0%B2%D0%B8%D0%BC-%D0%B1%D0%B0%D0%B3%D0%B8-dast-%D0%BE%D0%BC-%D1%8D%D0%BF%D0%B8%D0%B7%D0%BE%D0%B4-3\/id1552280775?i=1000527141196\">\u0422\u0440\u0430\u0432\u0438\u043c \u0431\u0430\u0433\u0438 DAST-\u043e\u043c \u2014 \u042d\u043f\u0438\u0437\u043e\u0434 #3<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/youtu.be\/EGB8mstJlyA\">\u041c\u043e\u0431\u0438\u043b\u044c\u043d\u044b\u0439 SSDLC<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/podlodka.io\/85\">\u041f\u0435\u043d\u0442\u0435\u0441\u0442 \u043c\u043e\u0431\u0438\u043b\u044c\u043d\u044b\u0445 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439<\/a><\/p>\n<\/li>\n<\/ul>\n<\/div>\n<\/details>\n<h4>En<\/h4>\n<details class=\"spoiler\">\n<summary>\u0421\u0441\u044b\u043b\u043a\u0438<\/summary>\n<div class=\"spoiler__content\">\n<ul>\n<li>\n<p><a href=\"https:\/\/android-bytes-by-esper.captivate.fm\/episode\/ep11-safetynet-cat-and-mouse\">THE SECRETIVE ANDROID SAFETYNET<\/a><\/p>\n<\/li>\n<\/ul>\n<\/div>\n<\/details>\n<p><a class=\"anchor\" name=\"androidpapers\" id=\"androidpapers\"><\/a><\/p>\n<h3>\u0421\u0442\u0430\u0442\u044c\u0438<\/h3>\n<p>\u042d\u0442\u043e \u0441\u0430\u043c\u044b\u0439 \u0431\u043e\u043b\u044c\u0448\u043e\u0439 \u0440\u0430\u0437\u0434\u0435\u043b \u0438\u0437 \u0432\u0441\u0435\u0445. \u0417\u0434\u0435\u0441\u044c \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d\u044b \u0441\u0442\u0430\u0442\u044c\u0438 \u043f\u043e \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u043c \u0442\u0435\u043c\u0430\u043c, \u043a\u0430\u0441\u0430\u044e\u0449\u0438\u043c\u0441\u044f \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 Android. \u041e\u0442\u0434\u0435\u043b\u044c\u043d\u043e \u0441\u043e\u0431\u0440\u0430\u043d\u044b \u0432\u0441\u0435 \u0440\u0443\u0441\u0441\u043a\u043e\u044f\u0437\u044b\u0447\u043d\u044b\u0435 \u043c\u0430\u0442\u0435\u0440\u0438\u0430\u043b\u044b, \u0430 \u0442\u0430\u043a\u0436\u0435 \u0441\u0442\u0430\u0442\u044c\u0438 \u0441 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435\u043c Frida.<\/p>\n<h4>Ru<\/h4>\n<details class=\"spoiler\">\n<summary>\u0421\u0441\u044b\u043b\u043a\u0438<\/summary>\n<div class=\"spoiler__content\">\n<ul>\n<li>\n<p><a href=\"https:\/\/habr.com\/ru\/company\/swordfish_security\/blog\/565092\/\">\u0420\u0430\u0437\u0432\u0438\u0442\u0438\u0435 \u043c\u0435\u0445\u0430\u043d\u0438\u0437\u043c\u043e\u0432 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 Android (\u043e\u0442 \u0432\u0435\u0440\u0441\u0438\u0438 \u043a \u0432\u0435\u0440\u0441\u0438\u0438)<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/habr.com\/ru\/company\/vk\/blog\/417031\/\">\u0411\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u044c \u043c\u043e\u0431\u0438\u043b\u044c\u043d\u043e\u0433\u043e OAuth 2.0<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/xakep.ru\/2017\/08\/14\/android-task-hijacking\/\">Android Task Hijacking. \u0420\u0430\u0437\u0431\u0438\u0440\u0430\u0435\u043c \u0430\u043a\u0442\u0443\u0430\u043b\u044c\u043d\u0443\u044e \u0442\u0435\u0445\u043d\u0438\u043a\u0443 \u043f\u043e\u0434\u043c\u0435\u043d\u044b \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439 \u0432 Android<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/habr.com\/ru\/company\/pvs-studio\/blog\/418891\/\">\u041f\u0440\u043e\u0432\u0435\u0440\u0438\u043b\u0438 \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e PVS-Studio \u0438\u0441\u0445\u043e\u0434\u043d\u044b\u0435 \u043a\u043e\u0434\u044b Android, \u0438\u043b\u0438 \u043d\u0438\u043a\u0442\u043e \u043d\u0435 \u0438\u0434\u0435\u0430\u043b\u0435\u043d<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/medium.com\/mobileup\/%D0%BF%D0%BE%D0%B4%D0%BC%D0%B5%D0%BD%D1%8F%D0%B5%D0%BC-runtime-permissions-%D0%B2-android-17c58bad954f\">\u041f\u043e\u0434\u043c\u0435\u043d\u044f\u0435\u043c Runtime permissions \u0432 Android<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/habr.com\/ru\/post\/541190\/\">\u041a\u0430\u043a root-\u043f\u0440\u0430\u0432\u0430 \u0438 \u0430\u043b\u044c\u0442\u0435\u0440\u043d\u0430\u0442\u0438\u0432\u043d\u044b\u0435 \u043f\u0440\u043e\u0448\u0438\u0432\u043a\u0438 \u0434\u0435\u043b\u0430\u044e\u0442 \u0432\u0430\u0448 android \u0441\u043c\u0430\u0440\u0442\u0444\u043e\u043d \u0443\u044f\u0437\u0432\u0438\u043c\u044b\u043c<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/telegra.ph\/Drozer-ehmulyator-i-ehlfijskie-kostyli-08-20\">Drozer, \u044d\u043c\u0443\u043b\u044f\u0442\u043e\u0440 \u0438 \u044d\u043b\u044c\u0444\u0438\u0439\u0441\u043a\u0438\u0435 \u043a\u043e\u0441\u0442\u044b\u043b\u0438<\/a><\/p>\n<\/li>\n<\/ul>\n<\/div>\n<\/details>\n<h4>En<\/h4>\n<details class=\"spoiler\">\n<summary>\u0421\u0441\u044b\u043b\u043a\u0438<\/summary>\n<div class=\"spoiler__content\">\n<h4>Frida<\/h4>\n<ul>\n<li>\n<p><a href=\"https:\/\/www.fatalerrors.org\/a\/code-and-example.html\">Tiktok data acquisition Frida tutorial, Frida Java Hook detailed explanation: code and example. Part 1<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.fatalerrors.org\/a\/0d901j8.html\">Tiktok data acquisition Frida tutorial, Frida Java Hook detailed explanation: code and example. Part 2<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/11x256.github.io\/\">Frida. 11&#215;256&#8217;s Reverse Engineering blog<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/grepharder.github.io\/blog\/\">Blog about Frida. grepharder blog<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/neo-geo2.gitbook.io\/adventures-on-security\/\">Frida Scripting Guide<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/joshspicer.com\/android-frida-1\">Android Hacking with FRIDA<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/erev0s.com\/blog\/how-hook-android-native-methods-frida-noob-friendly\/\">How to hook Android Native methods with Frida (Noob Friendly)<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/neo-geo2.gitbook.io\/adventures-on-security\/frida-scripting-guide\/frida-scripting-guide\">Frida scripting guide for Java<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/yasoob.me\/posts\/reverse-engineering-nike-run-club-using-frida-android\/\">Reverse Engineering Nike Run Club Android App Using Frida<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.notsosecure.com\/pentesting-android-apps-using-frida\/\">Pentesting Android Apps Using Frida<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/medium.com\/@GowthamR1\/android-root-detection-bypass-using-objection-and-frida-scripts-d681d30659a7\">Android Root Detection Bypass Using Objection and Frida Scripts<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/drive.google.com\/file\/d\/1JccmMLi6YTnyRrp_rk6vzKrUX3oXK_Yw\/view\">Mobile Pentesting With Frida<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/Magpol\/fridafde\">How to use FRIDA to bruteforce Secure Startup with FDE-encryption on a Samsung G935F running Android 8<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/n00b.sh\/posts\/aes-killer-mobile-app-demo\/\">Decrypting Mobile App Traffic using AES Killer and Frida<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/kylesmile1103\/Learn-Frida\">Learn how to use Frida with Unity app<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.amazon.com\/Beginning-Frida-Learning-Android-JavaScript\/dp\/B094ZQ1HHC\">Beginning Frida: Learning Frida use on Linux and (just a bit on) Wintel and Android systems with Python and JavaScript (Frida. hooking, and other tools)<\/a><\/p>\n<\/li>\n<\/ul>\n<h4>\u0414\u0440\u0443\u0433\u0438\u0435<\/h4>\n<ul>\n<li>\n<p><a href=\"https:\/\/threader.app\/thread\/1129680329994907648\">\u041f\u043e\u0434\u0431\u043e\u0440\u043a\u0430 \u0434\u0438\u0441\u043a\u043b\u043e\u0437\u043e\u0432 \u0441 HackerOne<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.cobalt.io\/getting-started-with-android-application-security-6f20b76d795b\">\u041f\u043e\u0434\u0440\u043e\u0431\u043d\u0435\u0439\u0448\u0430\u044f \u0438\u043d\u0441\u0442\u0440\u0443\u043a\u0446\u0438\u044f \u043f\u043e \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0435 \u0440\u0430\u0431\u043e\u0447\u0435\u0433\u043e \u043e\u043a\u0440\u0443\u0436\u0435\u043d\u0438\u044f<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/valsamaras.medium.com\/android-security-workshop-5eadeb50fba\">Android Security Workshop<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.securelayer7.net\/static-analysis-of-android-application-tools-used-securelayer7\/\">OWASP Top 10: Static Analysis of Android Application &amp; Tools Used<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.oversecured.com\/Android-security-checklist-webview\/\">Android security checklist: WebView<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.oversecured.com\/Use-cryptography-in-mobile-apps-the-right-way\/\">Use cryptography in mobile apps the right way<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.oversecured.com\/Why-dynamic-code-loading-could-be-dangerous-for-your-apps-a-Google-example\/\">Why dynamic code loading could be dangerous for your apps: a Google example<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/dphoeniixx.medium.com\/arbitrary-code-execution-on-facebook-for-android-through-download-feature-fb6826e33e0f\">Arbitrary code execution on Facebook for Android through download feature<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.nuckingfoob.me\/android-webview-csp-iframe-sandbox-bypass\/index.html\">Android Webview Exploited<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.oversecured.com\/Gaining-access-to-arbitrary-Content-Providers\/\">Android: Gaining access to arbitrary* Content Providers<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.oversecured.com\/Exploiting-memory-corruption-vulnerabilities-on-Android\/\">Exploiting memory corruption vulnerabilities on Android<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.oversecured.com\/Two-weeks-of-securing-Samsung-devices-Part-1\/\">Two weeks of securing Samsung devices: Part 1<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.oversecured.com\/Two-weeks-of-securing-Samsung-devices-Part-2\/\">Two weeks of securing Samsung devices: Part 2<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.oversecured.com\/Evernote-Universal-XSS-theft-of-all-cookies-from-all-sites-and-more\/\">Evernote: Universal-XSS, theft of all cookies from all sites, and more<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.oversecured.com\/Interception-of-Android-implicit-intents\/\">Interception of Android implicit intents<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.oversecured.com\/Oversecured-detects-dangerous-vulnerabilities-in-the-TikTok-Android-app\/\">TikTok: three persistent arbitrary code executions and one theft of arbitrary files<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.oversecured.com\/Oversecured-automatically-discovers-persistent-code-execution-in-the-Google-Play-Core-Library\/\">Oversecured automatically discovers persistent code execution in the Google Play Core Library<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.oversecured.com\/Oversecured-automatically-discovers-persistent-code-execution-in-the-Google-Play-Core-Library\/\">Persistent arbitrary code execution in Android&#8217;s Google Play Core Library: details, explanation and the PoC &#8212; CVE-2020-8913<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.oversecured.com\/Android-Access-to-app-protected-components\/\">Android: Access to app protected components<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.oversecured.com\/Android-arbitrary-code-execution-via-third-party-package-contexts\/\">Android: arbitrary code execution via third-party package contexts<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.comparitech.com\/blog\/information-security\/firebase-misconfiguration-report\/\">24,000 Android apps expose user data through Firebase blunders<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.talosintelligence.com\/2020\/05\/the-wolf-is-back.html?m=1\">The wolf is back &#8212; Android malware modification<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/medium.com\/knowing-android\/modern-security-in-android-part-1-6282bcb71e6c\">Modern Security in Android. Part 1<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/medium.com\/knowing-android\/modern-security-in-android-part-2-743cd7c0941a\">Modern Security in Android. Part 2<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/medium.com\/knowing-android\/modern-security-in-android-part-3-bea8cc6f984f\">Modern Security in Android. Part 3<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.hacktivesecurity.com\/index.php\/2020\/04\/05\/android-ipc-part-1-introduction\/\">Android IPC: Part 1 \u2013 Introduction<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.hacktivesecurity.com\/index.php\/2020\/04\/26\/android-ipc-part-2-binder-and-service-manager-perspective\/\">Android IPC: Part 2 \u2013 Binder and Service Manager Perspective<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/thehackernews.com\/2020\/05\/stranhogg-android-vulnerability.html\">StrandHogg 2<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.usenix.org\/system\/files\/conference\/usenixsecurity15\/sec15-paper-ren-chuangang.pdf\">Towards Discovering and Understanding Task Hijacking in Android<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blogs.quickheal.com\/sure-right-aarogya-setu-app-phone\/\">Aarogya setu spyware analisys<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.quarkslab.com\/playing-around-with-the-fuchsia-operating-system.html\">Playing Around With The Fuchsia Operating System Security<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.nviso.eu\/2019\/08\/13\/intercepting-traffic-from-android-flutter-applications\/\">Intercepting traffic from Android Flutter applications<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.xda-developers.com\/safetynet-hardware-attestation-hide-root-magisk\/\">SafetyNet\u2019s dreaded hardware attestation<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/security.googleblog.com\/2020\/06\/system-hardening-in-android-11.html\">System hardening in Android 11<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/aeonlucid.com\/Snapchat-detection-on-Android\/\">Snapchat detection on Android<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.pnfsoftware.com\/blog\/reversing-android-protector-obfuscation\/\">Reversing an Android app Protector, Part 1 \u2013 Code Obfuscation &amp; RASP<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.pnfsoftware.com\/blog\/reversing-android-protector-encryption\/\">Reversing an Android app Protector, Part 2 \u2013 Assets and Code Encryption<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.pnfsoftware.com\/blog\/reversing-android-protector-virtualization\/\">Reversing an Android app Protector, Part 3 \u2013 Code Virtualization<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/securitylab.github.com\/research\/fuzzing_android_nfc\/\">Structured fuzzing Android&#8217;s NFC<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/googleprojectzero.blogspot.com\/2020\/07\/mms-exploit-part-1-introduction-to-qmage.html?m=1\">MMS Exploit Part 1: Introduction to the Samsung Qmage Codec and Remote Attack Surface<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.synacktiv.com\/en\/publications\/dji-android-go-4-application-security-analysis.html\">DJI ANDROID GO 4 APPLICATION SECURITY ANALYSIS<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/docs.google.com\/presentation\/d\/15bi5pndttfCzMEMw8GT2oCHCJvHx_a8YszkkSMtp_jE\/edit#slide=id.p1\">B3nac &#8212; Android application exploitation<\/a><\/p>\n<\/li>\n<li>\n<p>Dynamic analysis of apps inside Android Cloning apps<\/p>\n<ul>\n<li>\n<p><a href=\"https:\/\/darvincitech.wordpress.com\/2020\/07\/18\/all-your-crypto-keys-belongs-to-me-in-android-virtual-containers\/\">Part 1<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/darvincitech.wordpress.com\/2020\/10\/11\/virtual-dynamic-analysis-part-2\/\">Part 2<\/a><\/p>\n<\/li>\n<\/ul>\n<\/li>\n<li>\n<p>Tik-Tok App Analisys<\/p>\n<ul>\n<li>\n<p><a href=\"https:\/\/medium.com\/@fs0c131y\/tiktok-logs-logs-logs-e93e8162647a\">TikTok: Logs, Logs, Logs<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/medium.com\/@fs0c131y\/tiktok-what-is-an-app-log-da70193f875\">TikTok: What is an app log?<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/medium.com\/@fs0c131y\/tiktok-the-disinformation-is-everywhere-dc340f3ae86a\">TikTok: The disinformation is everywhere<\/a><\/p>\n<\/li>\n<\/ul>\n<\/li>\n<li>\n<p>Exploiting Android Messengers with WebRTC<\/p>\n<ul>\n<li>\n<p><a href=\"https:\/\/googleprojectzero.blogspot.com\/2020\/08\/exploiting-android-messengers-part-1.html\">Part 1<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/googleprojectzero.blogspot.com\/2020\/08\/exploiting-android-messengers-part-2.html\">Part 2<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/googleprojectzero.blogspot.com\/2020\/08\/exploiting-android-messengers-part-3.html\">Part 3<\/a><\/p>\n<\/li>\n<\/ul>\n<\/li>\n<li>\n<p><a href=\"https:\/\/medium.com\/bugbountywriteup\/android-pentesting-lab-4a6fe1a1d2e0\">Android Pentesting Labs &#8212; Step by Step guide for beginners<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/medium.com\/swlh\/an-android-hacking-primer-3390fef4e6a0\">An Android Hacking Primer<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/source.android.com\/security\">Secure an Android Device<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/developer.android.com\/training\/articles\/security-tips\">Security tips<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.owasp.org\/index.php\/OWASP_Mobile_Security_Testing_Guide\">OWASP Mobile Security Testing Guide<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/3xpl01tc0d3r.blogspot.com\/2019\/09\/security-testing-for-android-app-part1.html\">Security Testing for Android Cross Platform Application<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.0daylabs.com\/2019\/09\/18\/deep-dive-into-Android-security\/\">Dive deep into Android Application Security<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/mobile-security.gitbook.io\/mobile-security-testing-guide\/\">Mobile Security Testing Guide<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/sh4hin\/MobileApp-Pentest-Cheatsheet\">Mobile Application Penetration Testing Cheat Sheet<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.evilsocket.net\/2017\/04\/27\/Android-Applications-Reversing-101\/#.WQND0G3TTOM.reddit\">Android Applications Reversing 101<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/developer.box.com\/en\/guides\/security\/\">Android Security Guidelines<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/pentestlab.blog\/2017\/02\/12\/android-webview-vulnerabilities\/\">Android WebView Vulnerabilities<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.owasp.org\/index.php\/OWASP_Mobile_Top_10\">OWASP Mobile Top 10<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/resources.infosecinstitute.com\/practical-android-phone-forensics\/\">Practical Android Phone Forensics<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"http:\/\/www.vantagepoint.sg\/blog\/83-mobile-reverse-engineering-unleashed\">Mobile Reverse Engineering Unleashed<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/quark-engine\/quark-engine\">quark-engine &#8212; An Obfuscation-Neglect Android Malware Scoring System<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/medium.com\/@sarang6489\/root-detection-bypass-by-manual-code-manipulation-5478858f4ad1\">Root Detection Bypass By Manual Code Manipulation.<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"http:\/\/public.avast.com\/research\/VB2019-Garcia-etal.pdf\">GEOST BOTNET &#8212; the discovery story of a new Android banking trojan<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.mobileiron.com\/en\/blog\/magisk-android-rooting\">Magisk Systemless Root &#8212; Detection and Remediation<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/arxiv.org\/pdf\/1910.06192.pdf\">AndrODet: An adaptive Android obfuscation detector<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/hackernoon.com\/hands-on-mobile-api-security-get-rid-of-client-secrets-a79f111b6844\">Hands On Mobile API Security<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/nileshsapariya.blogspot.com\/2016\/11\/zero-to-hero-mobile-application-testing.html\">Zero to Hero &#8212; Mobile Application Testing &#8212; Android Platform<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/docs.google.com\/presentation\/d\/1pYB522E71hXrp4m3fL3E3fnAaOIboJKqpbyE5gSsOes\/edit\">Android Malware Adventures<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/nightowl131.github.io\/AAPG\/\">AAPG &#8212; Android application penetration testing guide<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.juanurs.com\/Bypassing-Android-Anti-Emulation-Part-I\/\">Bypassing Android Anti-Emulation<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.gosecure.net\/blog\/2020\/04\/06\/bypassing-xamarin-certificate-pinning-on-android\/\">Bypassing Xamarin Certificate Pinning<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.ropnop.com\/configuring-burp-suite-with-android-nougat\/\">Configuring Burp Suite With Android Nougat<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/httptoolkit.tech\/blog\/inspecting-android-http\/\">Inspecting Android HTTP with a fake VPN<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.cyberark.com\/resources\/threat-research-blog\/outlook-for-android-xss\">Outlook for Android XSS<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/alesandroortiz.com\/articles\/uxss-android-webview-cve-2020-6506\/\">Universal XSS in Android WebView<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.blackhat.com\/asia-20\/briefings\/schedule\/#track\/mobile\">Mobile Blackhat Asia 2020<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/security.googleblog.com\/2020\/09\/lockscreen-and-authentication.html?m=1\">Lockscreen and Authentication Improvements in Android 11<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/infosecwriteups.com\/firefox-and-how-a-website-could-steal-all-of-your-cookies-581fe4648e8d\">Firefox: How a website could steal all your cookies<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.longterm.io\/cve-2020-0423.html\">Exploiting a Single Instruction Race Condition in Binder<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/googleprojectzero.blogspot.com\/2020\/12\/an-ios-hacker-tries-android.html?m=1\">An iOS hacker tries Android<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/infosecwriteups.com\/hack-crypto-secrets-from-heap-memory-to-exploit-android-application-728097fcda3\">Hack crypto secrets from heap memory to exploit Android application<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/security.oppo.com\/en\/noticeDetail?notice_only_key=NOTICE-1351377961017942016\">A Special Attack Surface of the Android System (1): Evil Dialog Box<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/ash-king.co.uk\/blog\/Launching-internal-non-exported-deeplinks-on-Facebook\">Launching Internal &amp; Non-Exported Deeplinks On Facebook<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/rloura.wordpress.com\/2020\/12\/04\/reversing-flutter-for-android-wip\/\">Reverse engineering Flutter for Android<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/hackerone.com\/reports\/1115864\">Persistant Arbitrary code execution in mattermost android<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.oversecured.com\/Common-mistakes-when-using-permissions-in-Android\/\">Common mistakes when using permissions in Android<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/i.blackhat.com\/EU-21\/Wednesday\/EU-21-Jin-The-Art-of-Exploiting-UAF-by-Ret2bpf-in-Android-Kernel-wp.pdf\">The art of exploiting UAF by Ret2bpf in Android kernel<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/i.blackhat.com\/EU-21\/Wednesday\/EU-21-He-Re-route-Your-Intent-for-Privilege-Escalation-A-Universal-Way-to-Exploit-Android-PendingIntents-in-High-profile-and-System-Apps.pdf\">Re route Your Intent for Privilege Escalation (A Universal Way to Exploit Android PendingIntents in High profile and System Apps)<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/i.blackhat.com\/EU-21\/Thursday\/EU-21-Bin-A-Deep-Dive-into-Privacy-Dashboard-of-Top-Android-Vendors.pdf\">A Deep Dive into Privacy Dashboard of Top Android Vendors<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.hebunilhanli.com\/wonderland\/mobile-security\/android-component-security\/\">Android Component Security | The Four Horsemen<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/sensepost.com\/blog\/2021\/android-application-testing-using-windows-11-and-windows-subsystem-for-android\/\">Android Application Testing Using Windows 11 and Windows Subsystem for Android<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/reconshell.com\/awesome-android-security\/\">Android Awesome Security<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.elcomsoft.com\/2020\/04\/forensic-guide-to-imessage-whatsapp-telegram-signal-and-skype-data-acquisition\/\">Forensic guide to iMessage, WhatsApp, Telegram, Signal and Skype data acquisition<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/research.checkpoint.com\/2020\/mobile-as-attack-vector-using-mdm\/\">Malware uses Corporate MDM as attack vector<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/mobexler.com\/checklist.htm\">Mobexler Checklist<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/20\/f\/barcode-reader-apps-on-google-play-found-using-new-ad-fraud-technique.html\">Ad Fraud Spotted in Barcode Reader Malware Analysis<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.elcomsoft.com\/2020\/06\/researching-confide-messenger-encryption\/\">Researching Confide Messenger Encryption<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/hot3eed.github.io\/snap_part1_obfuscations.html\">Reverse Engineering Snapchat (Part I): Obfuscation Techniques<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/hot3eed.github.io\/2020\/06\/22\/snap_p2_deobfuscation.html\">Reverse Engineering Snapchat (Part II): Deobfuscating the Undeobfuscatable<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/abss.me\/posts\/fcm-takeover\/\">Firebase Cloud Messaging Service Takeover<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.allysonomalley.com\/2020\/01\/06\/saying-goodbye-to-my-favorite-5-minute-p1\/\">Saying Goodbye to my Favorite 5 Minute P1<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.tst.sh\/reverse-engineering-flutter-apps-part-1\/\">Reverse engineering Flutter apps (Part 1)<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/hitcon.org\/2020\/slides\/How%20I%20Hacked%20Facebook%20Again!.pdf\">How I Hacked facebook Again!<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/research.checkpoint.com\/2020\/instagram_rce-code-execution-vulnerability-in-instagram-app-for-android-and-ios\/\">Instagram_RCE: Code Execution Vulnerability in Instagram App for Android and iOS<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/infosecwriteups.com\/how-to-use-ghidra-to-reverse-engineer-mobile-application-c2c89dc5b9aa\">How to use Ghidra to Reverse Engineer Mobile Application<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/suam.wtf\/posts\/react-native-application-static-analysis-en\/\">React Native Application Static Analysis<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/medium.com\/@meshal_\/pentesting-non-proxy-aware-mobile-applications-65161f62a965\">Pentesting Non-Proxy Aware Mobile Applications Without Root\/Jailbreak<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/hackerone.com\/reports\/1377748\">2 click Remote Code execution in Evernote Android<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.esper.io\/android-13-deep-dive\/\">Android 13 deep dive: Every change up to DP2, thoroughly documented<\/a><\/p>\n<\/li>\n<\/ul>\n<\/div>\n<\/details>\n<p><a class=\"anchor\" name=\"%D0%B7%D0%B0%D0%BA%D0%BB%D1%8E%D1%87%D0%B5%D0%BD%D0%B8%D0%B5\" id=\"\u0437\u0430\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u0435\"><\/a><\/p>\n<h2>\u0417\u0430\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u0435<\/h2>\n<p>\u041d\u0430\u0438\u0431\u043e\u043b\u0435\u0435 \u0438\u043d\u0442\u0435\u0440\u0435\u0441\u043d\u044b\u0435 \u043c\u0430\u0442\u0435\u0440\u0438\u0430\u043b\u044b \u044f \u043f\u0443\u0431\u043b\u0438\u043a\u0443\u044e \u0432 \u0441\u0432\u043e\u0435\u043c Telegram-\u043a\u0430\u043d\u0430\u043b\u0435 <a href=\"https:\/\/t.me\/mobile_appsec_world\">Mobile AppSec World<\/a>. \u041d\u043e \u043d\u0435\u0440\u0435\u0434\u043a\u043e \u043f\u0440\u0438\u0445\u043e\u0434\u0438\u0442\u0441\u044f \u0438\u0441\u043a\u0430\u0442\u044c \u0432 \u0438\u0441\u0442\u043e\u0440\u0438\u0438 \u043a\u0430\u043d\u0430\u043b\u0430, \u0447\u0442\u043e\u0431\u044b \u043f\u043e\u0432\u0442\u043e\u0440\u043d\u043e \u043f\u0440\u043e\u0447\u0438\u0442\u0430\u0442\u044c \u0438\u043b\u0438 \u043e\u0442\u0432\u0435\u0442\u0438\u0442\u044c \u043d\u0430 \u0447\u0435\u0439-\u0442\u043e \u0432\u043e\u043f\u0440\u043e\u0441. \u042d\u0442\u043e \u043d\u0435 \u043e\u0447\u0435\u043d\u044c \u0443\u0434\u043e\u0431\u043d\u043e \u0438 \u0431\u044b\u0432\u0430\u0435\u0442 \u043d\u0435\u043f\u0440\u043e\u0441\u0442\u043e \u043d\u0430\u0439\u0442\u0438 \u043d\u0443\u0436\u043d\u044b\u0439 \u043f\u043e\u0441\u0442. \u0412 \u0441\u0432\u044f\u0437\u0438 \u0441 \u044d\u0442\u0438\u043c, \u044f \u0440\u0435\u0448\u0438\u043b \u043e\u0444\u043e\u0440\u043c\u0438\u0442\u044c \u0432\u0441\u0435 \u043c\u0430\u0442\u0435\u0440\u0438\u0430\u043b\u044b \u0432 \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0435\u0432 <a href=\"https:\/\/github.com\/Swordfish-Security\/awesome-android-security\">Awesome Android Security<\/a> \u0438 <a href=\"https:\/\/github.com\/Swordfish-Security\/awesome-ios-security\/\">Awesome iOS Security<\/a>. \u041a \u0441\u043e\u0436\u0430\u043b\u0435\u043d\u0438\u044e, \u043d\u0435\u043b\u044c\u0437\u044f \u0443\u0441\u043b\u0435\u0434\u0438\u0442\u044c \u0437\u0430 \u0432\u0441\u0435\u043c, \u0447\u0442\u043e \u043f\u0440\u043e\u0438\u0441\u0445\u043e\u0434\u0438\u0442 \u0432 \u043c\u0438\u0440\u0435. \u041f\u043e\u044d\u0442\u043e\u043c\u0443, \u0435\u0441\u043b\u0438 \u044f \u0447\u0442\u043e-\u0442\u043e \u043f\u0440\u043e\u043f\u0443\u0441\u0442\u0438\u043b \u0438 \u0443 \u0432\u0430\u0441 \u0435\u0441\u0442\u044c, \u0447\u0442\u043e \u0434\u043e\u0431\u0430\u0432\u0438\u0442\u044c, \u0441\u043c\u0435\u043b\u043e \u043e\u0442\u043f\u0440\u0430\u0432\u043b\u044f\u0439\u0442\u0435 Pull Request!<\/p>\n<p>\u041e\u0441\u043d\u043e\u0432\u043d\u0430\u044f \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u0442\u0430\u043a\u0438\u0445 \u043f\u043e\u0434\u0431\u043e\u0440\u043e\u043a &#8212; \u0432 \u0442\u043e\u043c, \u0447\u0442\u043e \u043e\u043d\u0438 \u043d\u0435 \u043e\u0431\u043d\u043e\u0432\u043b\u044f\u044e\u0442\u0441\u044f. \u041c\u043d\u0435 \u0445\u043e\u0442\u0435\u043b\u043e\u0441\u044c \u0431\u044b \u0438\u0437\u0431\u0435\u0436\u0430\u0442\u044c \u043f\u043e\u0434\u043e\u0431\u043d\u043e\u0439 \u0443\u0447\u0430\u0441\u0442\u0438, \u043f\u043e\u044d\u0442\u043e\u043c\u0443 \u0432\u0441\u0435 \u043c\u0430\u0442\u0435\u0440\u0438\u0430\u043b\u044b, \u0447\u0442\u043e \u044f \u043f\u0440\u043e\u0440\u0430\u0431\u0430\u0442\u044b\u0432\u0430\u044e, \u0431\u0443\u0434\u0443\u0442  \u043f\u043e\u044f\u0432\u043b\u044f\u0442\u044c\u0441\u044f \u0432 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u044f\u0445 \u0432 \u043a\u043e\u043d\u0446\u0435 \u043d\u0435\u0434\u0435\u043b\u0438. <\/p>\n<p>\u0422\u0430\u043a\u0436\u0435, \u044f \u043f\u043b\u0430\u043d\u0438\u0440\u0443\u044e \u0434\u0435\u043b\u0430\u0442\u044c \u043f\u043e\u0434\u0431\u043e\u0440\u043a\u0443 \u043c\u0430\u0442\u0435\u0440\u0438\u0430\u043b\u043e\u0432 \u0432 \u0440\u0435\u0436\u0438\u043c\u0435 \u043d\u043e\u0432\u043e\u0441\u0442\u0435\u0439, \u0447\u0442\u043e \u0431\u044b\u043b\u043e \u0438\u043d\u0442\u0435\u0440\u0435\u0441\u043d\u043e\u0433\u043e \u0437\u0430 \u043d\u0435\u0434\u0435\u043b\u044e \u0432 \u043c\u0438\u0440\u0435 \u043c\u043e\u0431\u0438\u043b\u044c\u043d\u043e\u0439 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438. \u041f\u043e\u0441\u043c\u043e\u0442\u0440\u0438\u043c, \u043d\u0430\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u0442\u0430\u043a\u043e\u0439 \u0444\u043e\u0440\u043c\u0430\u0442 \u043f\u043e\u043a\u0430\u0436\u0435\u0442\u0441\u044f \u0438\u043d\u0442\u0435\u0440\u0435\u0441\u043d\u044b\u043c \u0438 \u043f\u043e\u043b\u0435\u0437\u043d\u044b\u043c.<\/p>\n<p>\u0412\u0441\u0435\u043c \u0445\u043e\u0440\u043e\u0448\u0435\u0439 \u043d\u0435\u0434\u0435\u043b\u0438 \u0438 \u043f\u043e\u043b\u0435\u0437\u043d\u043e\u0433\u043e \u0447\u0442\u0435\u043d\u0438\u044f!<\/p>\n<\/p>\n<\/div>\n<\/div>\n<\/div>\n<p><!----><!----><\/div>\n<p><!----><!----><br \/> \u0441\u0441\u044b\u043b\u043a\u0430 \u043d\u0430 \u043e\u0440\u0438\u0433\u0438\u043d\u0430\u043b \u0441\u0442\u0430\u0442\u044c\u0438 <a href=\"https:\/\/habr.com\/ru\/articles\/660179\/\"> https:\/\/habr.com\/ru\/articles\/660179\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<div><!--[--><!--]--><\/div>\n<div id=\"post-content-body\">\n<div>\n<div class=\"article-formatted-body article-formatted-body article-formatted-body_version-2\">\n<div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\">\n<p>\u041f\u0440\u0438\u0432\u0435\u0442, \u0425\u0430\u0431\u0440!<\/p>\n<p>\u041c\u0435\u043d\u044f \u0437\u043e\u0432\u0443\u0442 \u042e\u0440\u0438\u0439 \u0428\u0430\u0431\u0430\u043b\u0438\u043d, \u044f \u043e\u0434\u0438\u043d \u0438\u0437 \u043e\u0441\u043d\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 &#171;\u0421\u0442\u0438\u043d\u0433\u0440\u0435\u0439 \u0422\u0435\u0445\u043d\u043e\u043b\u043e\u0434\u0436\u0438\u0437&#187; (\u0432\u0445\u043e\u0434\u0438\u0442 \u0432 \u0433\u0440\u0443\u043f\u043f\u0443 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0439 Swordfish Security), \u043c\u044b \u0440\u0430\u0437\u0440\u0430\u0431\u0430\u0442\u044b\u0432\u0430\u0435\u043c \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u0443 \u0430\u043d\u0430\u043b\u0438\u0437\u0430 \u0437\u0430\u0449\u0438\u0449\u0435\u043d\u043d\u043e\u0441\u0442\u0438 \u043c\u043e\u0431\u0438\u043b\u044c\u043d\u044b\u0445 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439 iOS \u0438 Android. <\/p>\n<p>\u041f\u043e \u0434\u043e\u043b\u0433\u0443 \u0441\u043b\u0443\u0436\u0431\u044b \u043c\u044b \u043f\u043e\u0434\u043f\u0438\u0441\u0430\u043d\u044b \u043d\u0430 \u0431\u043e\u043b\u044c\u0448\u043e\u0435 \u043a\u043e\u043b\u0438\u0447\u0435\u0441\u0442\u0432\u043e \u0440\u0435\u0441\u0443\u0440\u0441\u043e\u0432 \u0438 \u043f\u0440\u043e\u0440\u0430\u0431\u0430\u0442\u044b\u0432\u0430\u0435\u043c \u0432\u0441\u0435 \u0441\u0442\u0430\u0442\u044c\u0438 \u0438 \u043c\u0430\u0442\u0435\u0440\u0438\u0430\u043b\u044b, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043e\u0442\u043d\u043e\u0441\u044f\u0442\u0441\u044f \u043a \u0442\u0435\u043c\u0435 \u043c\u043e\u0431\u0438\u043b\u044c\u043d\u043e\u0439 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438. \u0421\u0430\u043c\u044b\u043c \u0433\u043b\u0430\u0432\u043d\u044b\u043c \u0438 \u0438\u043d\u0442\u0435\u0440\u0435\u0441\u043d\u044b\u043c \u043c\u044b \u0445\u043e\u0442\u0438\u043c \u043f\u043e\u0434\u0435\u043b\u0438\u0442\u044c\u0441\u044f \u0441 \u0432\u0430\u043c\u0438. \u041c\u0430\u0442\u0435\u0440\u0438\u0430\u043b \u0431\u0443\u0434\u0435\u0442 \u043f\u043e\u043b\u0435\u0437\u0435\u043d \u0432\u0441\u0435\u043c, \u043a\u0442\u043e \u0441\u043b\u0435\u0434\u0438\u0442 \u0437\u0430 \u043f\u043e\u044f\u0432\u043b\u0435\u043d\u0438\u0435\u043c \u043d\u043e\u0432\u043e\u0439 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u0438 \u043e \u0441\u043f\u043e\u0441\u043e\u0431\u0430\u0445 \u043f\u043e\u0438\u0441\u043a\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u043e \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u043a\u0435 \u043d\u043e\u0432\u044b\u0445 \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u043e\u0432, \u0438 \u0432 \u0446\u0435\u043b\u043e\u043c \u0438\u043d\u0442\u0435\u0440\u0435\u0441\u0443\u0435\u0442\u0441\u044f \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u044c\u044e \u043c\u043e\u0431\u0438\u043b\u044c\u043d\u044b\u0445 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439.<\/p>\n<figure class=\"full-width\"><figcaption><\/figcaption><\/figure>\n<h2>\u041e\u0433\u043b\u0430\u0432\u043b\u0435\u043d\u0438\u0435<\/h2>\n<ul>\n<li>\n<p><a href=\"#%D0%B2%D1%81%D1%82%D1%83%D0%BF%D0%BB%D0%B5%D0%BD%D0%B8%D0%B5\">\u0412\u0441\u0442\u0443\u043f\u043b\u0435\u043d\u0438\u0435<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"#ios\">iOS Security Awesome<\/a><\/p>\n<ul>\n<li>\n<p><a href=\"#iostools\">\u0418\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u044b \u0430\u043d\u0430\u043b\u0438\u0437\u0430<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"#iosdefencetools\">\u0418\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u044b \u0437\u0430\u0449\u0438\u0442\u044b<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"#iosctf\">\u0423\u044f\u0437\u0432\u0438\u043c\u044b\u0435 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"#iosvideo\">\u0412\u0438\u0434\u0435\u043e<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"#iospapers\">\u0421\u0442\u0430\u0442\u044c\u0438<\/a><\/p>\n<\/li>\n<\/ul>\n<\/li>\n<li>\n<p><a href=\"#android\">Android Security Awesome<\/a><\/p>\n<ul>\n<li>\n<p><a href=\"#androidtools\">\u0418\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u044b \u0430\u043d\u0430\u043b\u0438\u0437\u0430<\/a><\/p>\n<ul>\n<li>\n<p><a href=\"#androidtoolscommon\">\u041e\u0431\u0449\u0438\u0435<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"#androidtoolsdynamic\">\u0414\u0438\u043d\u0430\u043c\u0438\u0447\u0435\u0441\u043a\u0438\u0439 \u0430\u043d\u0430\u043b\u0438\u0437<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"#androidtoolsonline\">\u041e\u043d\u043b\u0430\u0439\u043d \u0430\u043d\u0430\u043b\u0438\u0437\u0430\u0442\u043e\u0440\u044b<\/a><\/p>\n<\/li>\n<\/ul>\n<\/li>\n<li>\n<p><a href=\"#androiddefencetools\">\u0418\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u044b \u0437\u0430\u0449\u0438\u0442\u044b<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"#androidvulnerableapps\">\u0423\u044f\u0437\u0432\u0438\u043c\u044b\u0435 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"#androidctf\">CTF<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"#androidctfwalk\">\u041f\u0440\u043e\u0445\u043e\u0436\u0434\u0435\u043d\u0438\u0435 CTF<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"#androidvideo\">\u0412\u0438\u0434\u0435\u043e<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"#androidpodcast\">\u041f\u043e\u0434\u043a\u0430\u0441\u0442\u044b<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"#androidpapers\">\u0421\u0442\u0430\u0442\u044c\u0438<\/a><\/p>\n<\/li>\n<\/ul>\n<\/li>\n<li>\n<p><a href=\"#%D0%B7%D0%B0%D0%BA%D0%BB%D1%8E%D1%87%D0%B5%D0%BD%D0%B8%D0%B5\">\u0417\u0430\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u0435<\/a><\/p>\n<\/li>\n<\/ul>\n<p><a class=\"anchor\" name=\"%D0%B2%D1%81%D1%82%D1%83%D0%BF%D0%BB%D0%B5%D0%BD%D0%B8%D0%B5\" id=\"\u0432\u0441\u0442\u0443\u043f\u043b\u0435\u043d\u0438\u0435\">\u0435\u043d\u0438\u0435&#187;><\/a><\/p>\n<h2>\u0412\u0441\u0442\u0443\u043f\u043b\u0435\u043d\u0438\u0435<\/h2>\n<p>\u0417\u0434\u0435\u0441\u044c \u0441\u043e\u0431\u0440\u0430\u043d\u044b \u043c\u0430\u0442\u0435\u0440\u0438\u0430\u043b\u044b, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043c\u043e\u0433\u0443\u0442 \u0431\u044b\u0442\u044c \u043f\u043e\u043b\u0435\u0437\u043d\u044b \u0441 \u043f\u0440\u0430\u043a\u0442\u0438\u0447\u0435\u0441\u043a\u043e\u0439 \u0442\u043e\u0447\u043a\u0438 \u0437\u0440\u0435\u043d\u0438\u044f. \u0418\u0437 \u043d\u0438\u0445 \u043c\u043e\u0436\u043d\u043e \u0443\u0437\u043d\u0430\u0442\u044c \u043e \u043d\u043e\u0432\u044b\u0445 \u0441\u043f\u043e\u0441\u043e\u0431\u0430\u0445 \u0430\u0442\u0430\u043a \u043d\u0430 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f, \u043f\u0440\u043e\u0447\u0438\u0442\u0430\u0442\u044c \u043e \u043d\u043e\u0432\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044f\u0445, \u0438\u0437\u0443\u0447\u0438\u0442\u044c, \u043a\u0430\u043a \u0440\u0430\u0431\u043e\u0442\u0430\u044e\u0442 \u043c\u0435\u0445\u0430\u043d\u0438\u0437\u043c\u044b \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0438 \u0442.\u0434. \u0414\u043b\u044f \u0443\u0434\u043e\u0431\u0441\u0442\u0432\u0430 \u0432\u0441\u0435 \u043c\u0430\u0442\u0435\u0440\u0438\u0430\u043b\u044b, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0435\u0441\u0442\u044c \u043d\u0430 \u0440\u0443\u0441\u0441\u043a\u043e\u043c \u044f\u0437\u044b\u043a\u0435, \u0432\u044b\u0434\u0435\u043b\u0435\u043d\u044b \u0432 \u043f\u043e\u0434\u043f\u0443\u043d\u043a\u0442\u044b. \u0414\u043b\u044f \u043f\u0440\u043e\u0441\u0442\u043e\u0442\u044b \u043d\u0430\u0432\u0438\u0433\u0430\u0446\u0438\u0438 \u0435\u0441\u0442\u044c \u043e\u0433\u043b\u0430\u0432\u043b\u0435\u043d\u0438\u0435, \u0432\u0441\u0435 \u0441\u0441\u044b\u043b\u043a\u0438 \u0441\u043f\u0440\u044f\u0442\u0430\u043d\u044b \u043f\u043e\u0434 \u0440\u0430\u0441\u043a\u0440\u044b\u0432\u0430\u044e\u0449\u0438\u0435\u0441\u044f \u044d\u043b\u0435\u043c\u0435\u043d\u0442\u044b.<\/p>\n<\/p>\n<p><a class=\"anchor\" name=\"ios\" id=\"ios\"><\/a><\/p>\n<h2>iOS Security Awesome<\/h2>\n<p>\u0412 \u044d\u0442\u043e\u0439 \u043f\u043e\u0434\u0431\u043e\u0440\u043a\u0435 &#8212; \u043c\u0430\u0442\u0435\u0440\u0438\u0430\u043b\u044b \u043f\u043e \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 iOS-\u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439, \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0435 \u0441\u0442\u0430\u0442\u044c\u0438, \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u043d\u0438\u044f, \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u044b \u0430\u043d\u0430\u043b\u0438\u0437\u0430 \u0438 \u043f\u043e\u043b\u0435\u0437\u043d\u044b\u0435 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0438 \u0434\u043b\u044f \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0435\u043d\u0438\u044f \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438. <\/p>\n<p><a class=\"anchor\" name=\"iostools\" id=\"iostools\"><\/a><\/p>\n<h3>\u0418\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u044b \u0430\u043d\u0430\u043b\u0438\u0437\u0430<\/h3>\n<p>\u0412\u0441\u0435, \u0447\u0442\u043e \u043c\u043e\u0436\u0435\u0442 \u043f\u0440\u0438\u0433\u043e\u0434\u0438\u0442\u044c\u0441\u044f \u043f\u0440\u0438 \u0430\u043d\u0430\u043b\u0438\u0437\u0435 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439: \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0435 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0438, \u043c\u043e\u0434\u0443\u043b\u0438 \u0434\u043b\u044f \u043f\u043e\u0438\u0441\u043a\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439, \u0446\u0435\u043b\u044b\u0435 \u0444\u0440\u0435\u0439\u043c\u0432\u043e\u0440\u043a\u0438 \u0438 \u0441\u0438\u0441\u0442\u0435\u043c\u044b.<\/p>\n<details class=\"spoiler\">\n<summary>\u0421\u0441\u044b\u043b\u043a\u0438<\/summary>\n<div class=\"spoiler__content\">\n<ul>\n<li>\n<p><a href=\"https:\/\/github.com\/ChiChou\/bagbak\">bagbak<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/Swordfish-Security\/awesome-ios-security\/blob\/main\">PassionFruit<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/Swordfish-Security\/awesome-ios-security\/blob\/main\">GrapeFruit<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/securing\/IOSSecuritySuite\">IOS Security Suite<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/ios.cfw.guide\/blocking-jailbreak-detection\/#tweaks\">Blocking Jailbreak Detection Tweaks<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/evilpenguin\/NetworkSniffer\">NetworkSniffer<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/0x36\/ghidra_kernelcache\/\">Ghidra iOS kernelcache framework for reverse engineering<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/AloneMonkey\/frida-ios-dump\">frida-ios-dump<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/stefanesser\/dumpdecrypted\">dumpdecrypted<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/DerekSelander\/yacd\">Yet Another Code Decrypter<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/hot3eed\/xpcspy\">xpcspy &#8212; Bidirectional XPC message interception and more<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/checkra.in\/\">checkra1n jailbreak<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/frida\/frida\/releases\">Frida<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/sensepost\/objection\">Objection &#8212; mobile exploration toolkit by Frida<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/BishopFox\/bfinject\">Bfinject<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"http:\/\/www.i-funbox.com\/\">iFunbox<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.libimobiledevice.org\/\">Libimobiledevice &#8212; library to communicate with the services of the Apple ios devices<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.veracode.com\/sites\/default\/files\/Resources\/Tools\/iRETTool.zip\">iRET (iOS Reverse Engineering Toolkit)<\/a>\u00a0<\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/portswigger.net\/burp\/communitydownload\">Burp Suite<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/cydia.saurik.com\/api\/latest\/3\">Cycript<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/abrignoni\/iLEAPP\">iLEAPP &#8212; iOS Logs, Events, And Preferences Parser<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/cutter.re\/\">Cutter &#8212; Free and Open Source RE Platform powered by radare2<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/shinvou\/decrypt0r\">decrypt0r &#8212; automatically download and decrypt SecureRom stuff<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/MobSF\/Mobile-Security-Framework-MobSF\">Mobile-Security-Framework MobSF<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/m0bilesecurity\/RMS-Runtime-Mobile-Security\">Runtime Mobile Security (RMS) &#8212; is a powerful web interface that helps you to manipulate Android and iOS Apps at Runtime<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/NorthwaveSecurity\/fridax\">fridax<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/mobexler.com\/\">MOBEXLER<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/h0nus\/QRGen\">Generate Malformed QRCodes<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/huntergregal\/scansploit\">Tool for Injecting Malicious Payloads Into Barcodes<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/lcamtuf.coredump.cx\/afl\/\">AFL &#8212; american fuzzy lop<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/m2sup3rn0va.github.io\/SiAAA\/\">Setup for i0S and Android Application Analysis<\/a>\u00a0<\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/Ebryx\/AES-Killer\">AES Killer (Burpsuite Plugin)<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/ptswarm\/reFlutter\">ReFlutter<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/lief-project\/LIEF\">Lief<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/mvt-project\/mvt\">Mobile Verification Toolkit<\/a><\/p>\n<\/li>\n<\/ul>\n<\/div>\n<\/details>\n<p><a class=\"anchor\" name=\"iosdefencetools\" id=\"iosdefencetools\"><\/a><\/p>\n<h3>\u0418\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u044b \u0437\u0430\u0449\u0438\u0442\u044b<\/h3>\n<p>\u0411\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0438, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043c\u043e\u0433\u0443\u0442 \u043f\u043e\u043c\u043e\u0447\u044c \u043f\u0440\u0438 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u043a\u0435 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f.<\/p>\n<details class=\"spoiler\">\n<summary>\u0421\u0441\u044b\u043b\u043a\u0438<\/summary>\n<div class=\"spoiler__content\">\n<ul>\n<li>\n<p><a href=\"https:\/\/github.com\/agens-no\/EllipticCurveKeyPair\">EllipticCurveKeyPair<\/a>\u00a0&#8212; \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0430 \u0434\u043b\u044f \u0443\u0434\u043e\u0431\u043d\u043e\u0439 \u0440\u0430\u0431\u043e\u0442\u044b \u0441 SecurityEnclave<\/p>\n<\/li>\n<\/ul>\n<\/div>\n<\/details>\n<p><a class=\"anchor\" name=\"iosctf\" id=\"iosctf\"><\/a><\/p>\n<h3>\u0423\u044f\u0437\u0432\u0438\u043c\u044b\u0435 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f<\/h3>\n<p>\u0417\u0434\u0435\u0441\u044c &#8212; \u043e \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0445 CTF \u0438 \u043e \u0442\u043e\u043c, \u043a\u0430\u043a \u0438\u0445 \u043f\u0440\u043e\u0445\u043e\u0434\u0438\u0442\u044c. \u0412\u0441\u0435 \u044d\u0442\u043e \u043f\u043e\u043c\u043e\u0436\u0435\u0442 \u043f\u043e\u043f\u0440\u0430\u043a\u0442\u0438\u043a\u043e\u0432\u0430\u0442\u044c\u0441\u044f \u0438 \u043f\u043e\u043d\u044f\u0442\u044c, \u043a\u0430\u043a\u0438\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043c\u043e\u0433\u0443\u0442 \u0431\u044b\u0442\u044c \u0432 iOS-\u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f\u0445 \u0438 \u043a\u0430\u043a \u0438\u0445 \u0438\u0441\u043a\u0430\u0442\u044c. \u041f\u043e\u043a\u0430 \u0447\u0442\u043e \u0438 \u0441\u0430\u043c\u0438 \u0437\u0430\u0434\u0430\u043d\u0438\u044f, \u0438 \u043f\u0440\u043e\u0445\u043e\u0436\u0434\u0435\u043d\u0438\u044f \u043e\u0431\u044a\u0435\u0434\u0438\u043d\u0438\u043b \u0432 \u043e\u0434\u0438\u043d \u043f\u0443\u043d\u043a\u0442. \u041a\u043e\u0433\u0434\u0430 \u0438\u0445 \u0441\u0442\u0430\u043d\u0435\u0442 \u0431\u043e\u043b\u044c\u0448\u0435, \u043c\u043e\u0436\u043d\u043e \u0431\u0443\u0434\u0435\u0442 \u0440\u0430\u0437\u0434\u0435\u043b\u0438\u0442\u044c (\u043a\u0430\u043a \u044d\u0442\u043e \u0441\u0434\u0435\u043b\u0430\u043d\u043e \u0434\u043b\u044f Android). <\/p>\n<details class=\"spoiler\">\n<summary>\u0421\u0441\u044b\u043b\u043a\u0438<\/summary>\n<div class=\"spoiler__content\">\n<ul>\n<li>\n<p><a href=\"https:\/\/github.com\/GeoSn0w\/Myriam\">Myriam iOS<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"http:\/\/securitycompass.github.io\/iPhoneLabs\/\">ExploitMe Mobile iPhone Labs<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/hankbao\/owasp-igoat\">Owasp: iGoat<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/prateek147\/DVIA\">Damn Vulnerable iOS App (DVIA)<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/prateek147\/DVIA-v2\">Damn Vulnerable iOS App (DVIA) v2<\/a><\/p>\n<ul>\n<li>\n<p><a href=\"https:\/\/philkeeble.com\/categories\/#ios\">DVIA Walkthrow<\/a><\/p>\n<\/li>\n<\/ul>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/OWASP\/OMTG-Hacking-Playground\">OWASP: OMTG-Hacking-Playground<\/a><\/p>\n<\/li>\n<li>\n<p>Magnet Virtual Summit 2020 CTF (iOS)<\/p>\n<ul>\n<li>\n<p><a href=\"https:\/\/www.stark4n6.com\/2020\/06\/magnet-virtual-summit-2020-ctf-ios.html\">writeup 1<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/dfir300.blogspot.com\/2020\/06\/mvs2020ctf-write-up-ios.html\">writeup 2<\/a><\/p>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/div>\n<\/details>\n<p><a class=\"anchor\" name=\"iosvideo\" id=\"iosvideo\"><\/a><\/p>\n<h3>\u0412\u0438\u0434\u0435\u043e<\/h3>\n<p>\u0417\u0434\u0435\u0441\u044c \u0441\u043e\u0431\u0440\u0430\u043d\u044b \u0432\u0441\u0435 \u0432\u0438\u0434\u0435\u043e, \u0438\u043c\u0435\u044e\u0449\u0438\u0435 \u043e\u0442\u043d\u043e\u0448\u0435\u043d\u0438\u0435 \u043a \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 iOS. \u041f\u043e\u043a\u0430 \u0447\u0442\u043e \u044f \u043d\u0430\u0448\u0435\u043b \u0442\u043e\u043b\u044c\u043a\u043e \u0430\u043d\u0433\u043b\u043e\u044f\u0437\u044b\u0447\u043d\u044b\u0435 \u043c\u0430\u0442\u0435\u0440\u0438\u0430\u043b\u044b, \u043d\u043e \u043d\u0430\u0434\u0435\u044e\u0441\u044c, \u0447\u0442\u043e \u0432 \u0434\u0430\u043b\u044c\u043d\u0435\u0439\u0448\u0435\u043c \u0434\u043e\u0431\u0430\u0432\u044f\u0442\u0441\u044f \u0438 \u043d\u0430 \u0440\u0443\u0441\u0441\u043a\u043e\u043c \u044f\u0437\u044b\u043a\u0435.<\/p>\n<h4>En<\/h4>\n<details class=\"spoiler\">\n<summary>\u0421\u0441\u044b\u043b\u043a\u0438<\/summary>\n<div class=\"spoiler__content\">\n<ul>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=2CKrw7ErzCY\">iOS Application Vulnerabilities and how to find them<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=8cOx7vfszZU&amp;feature=youtu.be\">Attacking iPhone XS Max<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=BLGFriOKz6U\">Behind the Scenes of iOS Security<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=07VqX4bbXTI\">Analyzing and Attacking Apple Kernel Drivers<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=bP5VP7vLLKo\">Remotely Compromising iOS via Wi-Fi and Escaping the Sandbox<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=7UNeUT_sRos\">Demystifying the Secure Enclave Processor<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=DJFxhShJ6Ns\">HackPac Hacking Pointer Authentication in iOS User Space<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=DNW6Im31lQo\">iOS 10 Kernel Heap Revisited<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=p512McKXukU\">Recreating An iOS 0-Day Jailbreak Out Of Apple&#8217;s Security Updates<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=b6LI6j_aJ9k\">Building Secure iOS Apps (you don\u2019t have to learn it the hard way!)<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=9JuBUpRPLRs\">The Worst Mobile Apps<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=KeWcZ-Dd6tA\">Learn modding Unity apps and games with Frida<\/a><\/p>\n<\/li>\n<\/ul>\n<\/div>\n<\/details>\n<p><a class=\"anchor\" name=\"iospapers\" id=\"iospapers\"><\/a><\/p>\n<h3>\u0421\u0442\u0430\u0442\u044c\u0438<\/h3>\n<p>\u0412 \u044d\u0442\u043e\u043c \u0431\u043b\u043e\u043a\u0435 &#8212; \u0440\u0430\u0437\u043d\u043e\u043e\u0431\u0440\u0430\u0437\u043d\u044b\u0435 \u0441\u0442\u0430\u0442\u044c\u0438 \u0438 \u043c\u0430\u0442\u0435\u0440\u0438\u0430\u043b\u044b \u043f\u043e iOS. \u0420\u0443\u0441\u0441\u043a\u043e\u044f\u0437\u044b\u0447\u043d\u044b\u0435 \u0438 \u0430\u043d\u0433\u043b\u043e\u044f\u0437\u044b\u0447\u043d\u044b\u0435 &#8212; \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u043e. \u0411\u043b\u043e\u043a \u0441\u043e \u0441\u0442\u0430\u0442\u044c\u044f\u043c\u0438, \u043e\u0442\u043d\u043e\u0441\u044f\u0449\u0438\u043c\u0438\u0441\u044f \u043a Frida, &#8212; \u0432 \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u043e\u043c \u0440\u0430\u0437\u0434\u0435\u043b\u0435, \u043f\u043e\u0441\u043a\u043e\u043b\u044c\u043a\u0443 \u0441\u0435\u0433\u043e\u0434\u043d\u044f \u044d\u0442\u043e, \u043d\u0430\u0432\u0435\u0440\u043d\u043e\u0435, \u0441\u0430\u043c\u044b\u0439 \u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u043d\u044b\u0439 \u0444\u0440\u0435\u0439\u043c\u0432\u043e\u0440\u043a \u0434\u043b\u044f \u0442\u0435\u0441\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f. \u041d\u0430\u0432\u0435\u0440\u043d\u044f\u043a\u0430 \u043f\u043e\u043b\u0435\u0437\u043d\u043e \u043f\u043e\u0441\u043c\u043e\u0442\u0440\u0435\u0442\u044c, \u043a\u0430\u043a \u043e\u043d \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u0442\u0441\u044f \u043d\u0430 \u0440\u0435\u0430\u043b\u044c\u043d\u044b\u0445 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f\u0445.<\/p>\n<h4>Ru<\/h4>\n<details class=\"spoiler\">\n<summary>\u0421\u0441\u044b\u043b\u043a\u0438<\/summary>\n<div class=\"spoiler__content\">\n<ul>\n<li>\n<p><a href=\"https:\/\/habr.com\/ru\/company\/pt\/blog\/155937\/\">\u0412\u0430\u0448 \u0444\u043e\u043d\u0430\u0440\u0438\u043a \u043c\u043e\u0436\u0435\u0442 \u043e\u0442\u043f\u0440\u0430\u0432\u043b\u044f\u0442\u044c SMS<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/habr.com\/ru\/post\/556582\/\">\u041f\u0440\u043e\u0446\u0435\u0441\u0441 \u0437\u0430\u0433\u0440\u0443\u0437\u043a\u0438 iPhone. \u0427\u0430\u0441\u0442\u044c 1: Boot ROM<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/habr.com\/ru\/post\/569034\/\">\u0413\u0430\u0439\u0434 \u043f\u043e \u0440\u0435\u0432\u0435\u0440\u0441\u0443 iOS \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f \u043d\u0430 \u043f\u0440\u0438\u043c\u0435\u0440\u0435 ExpressVPN<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/habr.com\/ru\/company\/jugru\/blog\/570220\/\">\u0412\u0437\u043b\u043e\u043c \u0438 \u0432\u043d\u0435\u0434\u0440\u0435\u043d\u0438\u0435 \u0441\u0432\u043e\u0435\u0433\u043e \u043a\u043e\u0434\u0430 \u0432 \u0447\u0443\u0436\u043e\u0435 iOS-\u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0435<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/habr.com\/ru\/company\/wrike\/blog\/544754\/\">\u0411\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u044c iOS-\u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439: \u0433\u0430\u0439\u0434 \u0434\u043b\u044f \u043d\u043e\u0432\u0438\u0447\u043a\u043e\u0432<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/habr.com\/ru\/company\/swordfish_security\/blog\/525772\/\">Just for fun: \u0421\u043a\u043e\u043b\u044c\u043a\u043e \u00ab\u0436\u0438\u0432\u0435\u0442\u00bb iOS \u0434\u043e Jailbreak<\/a><\/p>\n<\/li>\n<\/ul>\n<\/div>\n<\/details>\n<h4>En<\/h4>\n<details class=\"spoiler\">\n<summary>\u0421\u0441\u044b\u043b\u043a\u0438<\/summary>\n<div class=\"spoiler__content\">\n<h4>Frida<\/h4>\n<ul>\n<li>\n<p><a href=\"https:\/\/syrion.me\/blog\/ios-swift-antijailbreak-bypass-frida\/\">iOS Swift Anti-Jailbreak Bypass with Frida<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.romainthomas.fr\/post\/21-07-pokemongo-anti-frida-jailbreak-bypass\/\">Gotta Catch &#8216;Em All: Frida &amp; jailbreak detection<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.amazon.com\/Beginning-Frida-Learning-Android-JavaScript\/dp\/B094ZQ1HHC\">Beginning Frida: Learning Frida use on Linux and (just a bit on) Wintel and Android systems with Python and JavaScript (Frida. hooking, and other tools)<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/kylesmile1103\/Learn-Frida\">Learn how to use Frida with Unity app<\/a><\/p>\n<\/li>\n<\/ul>\n<h4>\u041f\u0440\u043e\u0447\u0435\u0435<\/h4>\n<ul>\n<li>\n<p><a href=\"https:\/\/github.com\/writeups\/iOS\">iOS Write ups<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/rentry.co\/newvw\">iOS Internals &amp; Security Testing<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/curvedlayer.com\/2020\/08\/09\/ios-simulator-plugin-simctl.html\">Hacking iOS Simulator with simctl and dynamic libraries<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/siguza.github.io\/psychicpaper\/\">Psychic Paper<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/wojciechregula.blog\/post\/stealing-your-sms-messages-with-ios-0day\/\">Stealing your SMS messages with iOS 0day<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/bhavukjain.com\/blog\/2020\/05\/30\/zeroday-signin-with-apple\/\">Zero-day in Sign in with Apple<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.synacktiv.com\/en\/publications\/return-of-the-ios-sandbox-escape-lightspeeds-back-in-the-race.html\">Return of the ios sandbox escape: lightspeeds back in the race<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/this-pin-can-be-easily-guessed.github.io\/\">PIN Selection on Smartphones<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/googleprojectzero.blogspot.com\/2020\/06\/a-survey-of-recent-ios-kernel-exploits.html\">A survey of recent iOS kernel exploits<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.elcomsoft.com\/2020\/06\/apple-two-factor-authentication-sms-vs-trusted-devices\/\">Apple Two-Factor Authentication: SMS vs. Trusted Devices<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.nviso.eu\/2020\/06\/12\/intercepting-flutter-traffic-on-ios\/\">Intercepting Flutter traffic on iOS<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/aeonlucid.com\/Snapchat-detection-on-iOS\/\">Snapchat detection on iOS<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/secfault-security.com\/blog\/chain3.html\">Writing an iOS Kernel Exploit from Scratch<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.elcomsoft.com\/2020\/07\/4-ways-to-handle-iphone-backup-passwords\/\">The Four Ways to Deal with iPhone Backup Passwords<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.elcomsoft.com\/2020\/08\/extracting-and-decrypting-ios-keychain-physical-logical-and-cloud-options-explored\/\">Extracting and Decrypting iOS Keychain: Physical, Logical and Cloud Options Explored<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/googleprojectzero.blogspot.com\/2020\/07\/one-byte-to-rule-them-all.html\">iOS Kernel Explotation &#8212; One Byte to rule them all<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.infoq.com\/presentations\/ios-security\/\">Modern iOS Application Security<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.bugcrowd.com\/resources\/webinars\/reverse-engineering-ios-mobile-apps\/\">Reverse Engineering iOS Mobile Apps<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/media.ccc.de\/v\/36c3-10806-ktrw_the_journey_to_build_a_debuggable_iphone\">KTRW: The journey to build a debuggable iPhone<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/media.ccc.de\/v\/36c3-11238-the_one_weird_trick_securerom_hates\">The One Weird Trick SecureROM Hates<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/media.ccc.de\/v\/36c3-11034-tales_of_old_untethering_ios_11\">Tales of old: untethering iOS 11-Spoiler: Apple is bad at patching<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/media.ccc.de\/v\/36c3-10497-messenger_hacking_remotely_compromising_an_iphone_through_imessage\">Messenger Hacking: Remotely Compromising an iPhone through iMessage<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/vimeo.com\/231806976\">Reverse Engineering the iOS Simulator\u2019s SpringBoard<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/ansjdnakjdnajkd\/iOS\">Most usable tools for iOS penetration testing<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/0xmachos\/iOS-Security-Guides\">iOS-Security-Guides<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/i.blackhat.com\/eu-19\/Thursday\/eu-19-Yen-Trust-In-Apples-Secret-Garden-Exploring-Reversing-Apples-Continuity-Protocol-3.pdf\">Trust in Apple&#8217;s Secret Garden: Exploring &amp; Reversing Apple&#8217;s Continuity Protocol-Slides<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/manuals.info.apple.com\/MANUALS\/1000\/MA1902\/en_US\/apple-platform-security-guide.pdf\">Apple Platform Security<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/2013.appsecusa.org\/2013\/wp-content\/uploads\/2013\/12\/viaForensics-AppSecUSA-Nov-2013.pdf\">Mobile security, forensics &amp; malware analysis with Santoku Linux<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.redteam.pl\/2020\/08\/stealing-local-files-using-safari-web.html?m=1\">Stealing local files using Safari Web Share API<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/muirey03.blogspot.com\/2020\/09\/cve-2020-9964-ios-infoleak.html?m=1\">CVE-2020-9964 &#8212; An iOS infoleak<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/raw.githubusercontent.com\/windknown\/presentations\/master\/Attack_Secure_Boot_of_SEP.pdf\">Attack Secure Boot of SEP<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.elcomsoft.com\/2020\/09\/ios-14-forensics-what-has-changed-since-ios-13-7\/\">iOS 14 Forensics: What Has Changed Since iOS 13.7<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/samcurry.net\/hacking-apple\/\">We Hacked Apple for 3 Months: Here\u2019s What We Found<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/medium.com\/@ali.pourhadi\/fun-with-xpc-153fd772d409\">Fun with XPC<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.cyclon3.com\/bypass-facebook-ssl-certificate-pinning-for-ios\">Bypass Facebook SSL Certificate Pinning for iOS<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.cyclon3.com\/bypass-instagram-ssl-certificate-pinning-for-ios\">Bypass Instagram SSL Certificate Pinning for iOS<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/bellis1000.medium.com\/aslr-the-ios-kernel-how-virtual-address-spaces-are-randomised-d76d14dc7ebb\">ASLR &amp; the iOS Kernel \u2014 How virtual address spaces are randomised<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/ansjdnakjdnajkd\/iOS\">iOS\/macOS penetration testing cheatsheet<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/m1racles.com\/\">M1ssing Register Access Controls Leak EL0 State<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/worthdoingbadly.com\/macappsios\/\">Jailbroken iOS can&#8217;t run macOS apps. I spent a week to find out why.<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.chichou.me\/2021\/06\/20\/quick-analysis-wifid\/\">Quick Analysis for the SSID Format String Bug<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/threatpost.com\/unpatched-iphone-bug-remote-takeover\/167922\/\">Unpatched iPhone Bug Allows Remote Device Takeover<\/a><\/p>\n<\/li>\n<li>\n<p>Reverse Engineering Starling Bank<\/p>\n<ul>\n<li>\n<p><a href=\"https:\/\/hot3eed.github.io\/2020\/07\/30\/starling_p1_obfuscations.html\">Part I: Obfuscation Techniques<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/hot3eed.github.io\/2020\/08\/02\/starling_p2_detections_mitigations.html\">Part II: Jailbreak &amp; Debugger Detection, Weaknesses &amp; Mitigations<\/a><\/p>\n<\/li>\n<\/ul>\n<\/li>\n<li>\n<p><a href=\"https:\/\/xperylab.medium.com\/protonmail-forensic-decryption-of-ios-app-8e9ae9f50953\">ProtonMail : forensic decryption of iOS App<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/alephsecurity\/xnu-qemu-arm64\">iOS on QEMU<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/twitter.com\/ddouhine\/status\/1430881952559685633?s=28\">Proxying is not the only way to monitor network traffic on your iOS mobile apps<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.elcomsoft.com\/2020\/04\/forensic-guide-to-imessage-whatsapp-telegram-signal-and-skype-data-acquisition\/\">Forensic guide to iMessage, WhatsApp, Telegram, Signal and Skype data acquisition<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/research.checkpoint.com\/2020\/mobile-as-attack-vector-using-mdm\/\">Malware uses Corporate MDM as attack vector<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/mobexler.com\/checklist.htm\">Mobexler Checklist<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/20\/f\/barcode-reader-apps-on-google-play-found-using-new-ad-fraud-technique.html\">Ad Fraud Spotted in Barcode Reader Malware Analysis<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.elcomsoft.com\/2020\/06\/researching-confide-messenger-encryption\/\">Researching Confide Messenger Encryption<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/hot3eed.github.io\/snap_part1_obfuscations.html\">Reverse Engineering Snapchat (Part I): Obfuscation Techniques<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/hot3eed.github.io\/2020\/06\/22\/snap_p2_deobfuscation.html\">Reverse Engineering Snapchat (Part II): Deobfuscating the Undeobfuscatable<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/abss.me\/posts\/fcm-takeover\/\">Firebase Cloud Messaging Service Takeover<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.allysonomalley.com\/2020\/01\/06\/saying-goodbye-to-my-favorite-5-minute-p1\/\">Saying Goodbye to my Favorite 5 Minute P1<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.tst.sh\/reverse-engineering-flutter-apps-part-1\/\">Reverse engineering Flutter apps (Part 1)<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/hitcon.org\/2020\/slides\/How%20I%20Hacked%20Facebook%20Again!.pdf\">How I Hacked facebook Again!<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/research.checkpoint.com\/2020\/instagram_rce-code-execution-vulnerability-in-instagram-app-for-android-and-ios\/\">Instagram_RCE: Code Execution Vulnerability in Instagram App for Android and iOS<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/infosecwriteups.com\/how-to-use-ghidra-to-reverse-engineer-mobile-application-c2c89dc5b9aa\">How to use Ghidra to Reverse Engineer Mobile Application<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/suam.wtf\/posts\/react-native-application-static-analysis-en\/\">React Native Application Static Analysis<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/medium.com\/@meshal_\/pentesting-non-proxy-aware-mobile-applications-65161f62a965\">Pentesting Non-Proxy Aware Mobile Applications Without Root\/Jailbreak<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"http:\/\/phrack.org\/issues\/70\/12.html#article\">CVE-2021-30737 &#8212; Vulnerability Overview<\/a><\/p>\n<ul>\n<li>\n<p><a href=\"https:\/\/googleprojectzero.blogspot.com\/2022\/04\/cve-2021-30737-xerubs-2021-ios-asn1.html\">CVE-2021-30737, @xerub&#8217;s 2021 iOS ASN.1 Vulnerability<\/a><\/p>\n<\/li>\n<\/ul>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/OWASP\/owasp-mstg\/\">OWASP MSTG<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/mega.nz\/folder\/spoGDToC#zjYFlRAU7S06u5jSaQnvYw\">Full Mobile Hacking Course<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/academy.nowsecure.com\/\">NowSecure Academy<\/a><\/p>\n<\/li>\n<\/ul>\n<\/div>\n<\/details>\n<p><a class=\"anchor\" name=\"android\" id=\"android\"><\/a><\/p>\n<h2>Android Security Awesome<\/h2>\n<p>\u0412 \u0434\u0430\u043d\u043d\u043e\u043c \u0440\u0430\u0437\u0434\u0435\u043b\u0435 \u0441\u043e\u0431\u0440\u0430\u043d\u044b \u043c\u0430\u0442\u0435\u0440\u0438\u0430\u043b\u044b \u043f\u043e \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 Android-\u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439, \u0432\u043a\u043b\u044e\u0447\u0430\u044f \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0435 \u0441\u0442\u0430\u0442\u044c\u0438, \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u043d\u0438\u044f, \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u044b \u0430\u043d\u0430\u043b\u0438\u0437\u0430 \u0438 \u043f\u043e\u043b\u0435\u0437\u043d\u044b\u0435 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0438 \u0434\u043b\u044f \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0435\u043d\u0438\u044f \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439. <\/p>\n<p><a class=\"anchor\" name=\"androidtools\" id=\"androidtools\"><\/a><\/p>\n<h3>\u0418\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u044b \u0430\u043d\u0430\u043b\u0438\u0437\u0430<\/h3>\n<p>\u042d\u0442\u043e\u0442 \u0431\u043b\u043e\u043a \u0440\u0430\u0437\u0431\u0438\u0442 \u043d\u0430 \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u0447\u0430\u0441\u0442\u0435\u0439. \u0421\u043d\u0430\u0447\u0430\u043b\u0430 \u043c\u043e\u0436\u043d\u043e \u0443\u0432\u0438\u0434\u0435\u0442\u044c \u043e\u0431\u0449\u0438\u0435 \u0440\u0435\u0448\u0435\u043d\u0438\u044f \u0434\u043b\u044f \u0430\u043d\u0430\u043b\u0438\u0437\u0430 \u0438 \u043f\u043e\u0438\u0441\u043a\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439. \u041d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0438\u0437 \u043d\u0438\u0445 \u043f\u0435\u0440\u0435\u0441\u0435\u043a\u0430\u044e\u0442\u0441\u044f \u0441 \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u0430\u043c\u0438 \u0434\u043b\u044f iOS, \u043f\u043e\u0442\u043e\u043c\u0443 \u0447\u0442\u043e \u0441\u0440\u0435\u0434\u0438 \u043d\u0438\u0445 \u0432\u0441\u0442\u0440\u0435\u0447\u0430\u044e\u0442\u0441\u044f \u0443\u043d\u0438\u0432\u0435\u0440\u0441\u0430\u043b\u044c\u043d\u044b\u0435 \u0444\u0440\u0435\u0439\u043c\u0432\u043e\u0440\u043a\u0438 (\u043d\u043e \u0442\u0430\u043a\u0438\u0445 \u043d\u0435\u043c\u043d\u043e\u0433\u043e).<\/p>\n<p> \u041f\u043e\u0441\u043b\u0435 \u0438\u0434\u0443\u0442 \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u044b, \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u044b\u0435 \u0434\u043b\u044f \u0434\u0438\u043d\u0430\u043c\u0438\u0447\u0435\u0441\u043a\u043e\u0433\u043e \u0430\u043d\u0430\u043b\u0438\u0437\u0430 (\u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u043e \u0437\u0430\u043f\u0443\u0441\u043a\u0430\u0442\u044c \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0435 \u043d\u0430 \u0440\u0435\u0430\u043b\u044c\u043d\u043e\u043c \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0435 \u0438\u043b\u0438 \u044d\u043c\u0443\u043b\u044f\u0442\u043e\u0440\u0435). <\/p>\n<p>\u041d\u0443 \u0438 \u043f\u043e\u0441\u043b\u0435\u0434\u043d\u0438\u043c \u043f\u0443\u043d\u043a\u0442\u043e\u043c &#8212; \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u044b, \u0434\u043e\u0441\u0442\u0443\u043f\u043d\u044b\u0435 online, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f \u043a\u043e\u0442\u043e\u0440\u044b\u0435, \u043c\u043e\u0436\u043d\u043e \u0437\u0430\u0433\u0440\u0443\u0437\u0438\u0442\u044c \u0444\u0430\u0439\u043b \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f \u0438 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0447\u0435\u0440\u0435\u0437 \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u043e\u0435 \u0432\u0440\u0435\u043c\u044f \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442.<\/p>\n<p><a class=\"anchor\" name=\"androidtoolscommon\" id=\"androidtoolscommon\"><\/a><\/p>\n<h4>\u041e\u0431\u0449\u0438\u0435<\/h4>\n<details class=\"spoiler\">\n<summary>\u0421\u0441\u044b\u043b\u043a\u0438<\/summary>\n<div class=\"spoiler__content\">\n<ul>\n<li>\n<p><a href=\"https:\/\/beta.pithus.org\/\">Pithus<\/a>\u00a0(<a href=\"https:\/\/github.com\/Pithus\/bazaar\">github<\/a>) &#8212; free and open-source platform to analyze Android applications<\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/idanr1986\/cuckoodroid-2.0\">CuckooDroid 2.0 &#8212; Automated Android Malware Analysis<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/quark-engine\/quark-engine\">QARK &#8212; An Obfuscation-Neglect Android Malware Scoring System<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/linkedin\/qark\">QARK \u2013 Quick Android Review Kit<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/play.google.com\/store\/apps\/details?id=org.proxydroid&amp;hl=ru\">ProxyDroid<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/ASHWIN990\/ADB-Toolkit\">ADB Toolkit<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/darvincisec\/InjectFakeSecurityProvider\">InjectFakeSecurityProvider<\/a>\u00a0&#8212; print the key, key size, algorithm parameters, keystore password in logcat<\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/Ch0pin\/medusa\">MEDUSA<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/JakeWharton\/diffuse\">diffuse<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/daniellockyer\/apkdiff\">ApkDiff<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/charles2gan\/GDA-android-reversing-Tool\">GDA(GJoy Dex Analyzer)<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/evilpenguin\/APKProxyHelper\">APKProxyHelper<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/APKLab\/APKLab\">APKLab<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/m2sup3rn0va\/RASEv1\">RASE &#8212; Persistent Rooting Android Studio Emulator<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/ElderDrivers\/EdXposed\">EdXposed Framework<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/enovella\/fridroid-unpacker\">fridroid-unpacker<\/a>\u00a0&#8212; Defeat Java packers via Frida instrumentation<\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/devkekops\/checkkarlmarx\">CheckKarlMarx<\/a>\u00a0&#8212; Security \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 \u0434\u043b\u044f \u0440\u0435\u043b\u0438\u0437\u043d\u044b\u0445 \u0441\u0431\u043e\u0440\u043e\u043a<\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/windy-purple\/parserDex\/blob\/master\/%E5%AD%97%E7%AC%A6%E4%B8%B2%E8%A7%A3%E6%9E%90\/parserDexStrings.py\">parserDex<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/androguard\/androguard\">Androguard<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"http:\/\/pag.arguslab.org\/argus-saf\">Amandroid \u2013 A Static Analysis Framework<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/maaaaz\/androwarn\/\">Androwarn \u2013 Yet Another Static Code Analyzer<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/sonyxperiadev\/ApkAnalyser\">APK Analyzer \u2013 Static and Virtual Analysis Tool<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/honeynet\/apkinspector\/\">APK Inspector \u2013 A Powerful GUI Tool<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/hahwul\/droid-hunter\">Droid Hunter \u2013 Android application vulnerability analysis and Android pentest tool<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/google\/error-prone\">Error Prone \u2013 Static Analysis Tool<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"http:\/\/findbugs.sourceforge.net\/downloads.html\">Findbugs \u2013 Find Bugs in Java Programs<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/find-sec-bugs\/find-sec-bugs\/\">Find Security Bugs \u2013 A SpotBugs plugin for security audits of Java web applications.<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/secure-software-engineering\/FlowDroid\">Flow Droid \u2013 Static Data Flow Tracker<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/JesusFreke\/smali\">Smali\/Baksmali \u2013 Assembler\/Disassembler for the dex format<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/github.com\/EugenioDelfa\/Smali-CFGs\">Smali-CFGs \u2013 Smali Control Flow Graph\u2019s<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/www.cs.washington.edu\/sparta\">SPARTA \u2013 Static Program Analysis for Reliable<\/a><\/p>\n<\/li>\n<\/ul>\n<\/div>\n<\/details>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-410310","post","type-post","status-publish","format-standard","hentry"],"_links":{"self":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts\/410310","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=410310"}],"version-history":[{"count":0,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts\/410310\/revisions"}],"wp:attachment":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=410310"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=410310"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=410310"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}