BinderFuzzy - Pentest Android Services

BinderFuzzy - Pentest Android Services

An App intended for fuzzing the Binder interface and System Services of Android.

ChickenHook Security

Screenshots

Screenshot of BinderFuzzy - Pentest Android Services Screenshot of BinderFuzzy - Pentest Android Services Screenshot of BinderFuzzy - Pentest Android Services Screenshot of BinderFuzzy - Pentest Android Services Screenshot of BinderFuzzy - Pentest Android Services Screenshot of BinderFuzzy - Pentest Android Services

Description

BinderFuzzy is a fuzzer that can generate binder events in order to pentest system services running on the Android operating system (https://developer.android.com/reference/android/os/Binder, https://source.android.com/devices/architecture/hidl/binder-ipc). You can validate if system services have correct error handling or transfer binder objects / tokens of other services in order to validate if the target system service validates binder arguments.

This Project covers following features:

* Browse managers and binder interfaces.
* Execute Fuzzy tasks
* Configure argument lists for each parameter of the method to fuzz
* Read logs of recent tasks
* Use python3 cli (optional) to execute fuzzer from desktop.
* Define fuzzer script and execute via cli

Enjoy our App!

What’s new (1.0)

* initial release

Versions

Version Date Size Requires Android Download
1.0 current
1d21b8068bacd206…
2021-01-09 3.6 MB API 19

Permissions

What the app asks the system for. Android only grants sensitive access after you confirm it.

  • Internet accessSend and receive data over the internet.
  • MANAGE_ACTIVITY_STACKS

Comments