android-pentesting-tricks
Android pentesting playbook. Use when testing Android applications for SSL pinning bypass, exported component abuse, WebView vulnerabilities, intent redirection, root detection bypass, tapjacking, and backup extraction during authorized mobile security assessments.
By yaklang · 3,381 installs
npx skills add yaklang/hack-skills --skill android-pentesting-tricks
Source repository · Upstream listing
SKILL: Android Pentesting Tricks — Expert Attack Playbook
AI LOAD INSTRUCTION : Expert Android application security testing techniques. Covers SSL pinning bypass (Frida/Objection/LSPosed), component exposure, WebView exploitation, intent redirection, root detection bypass, and Play Integrity evasion. Base models miss Frida hook specifics and multi layer bypass chains.
0. RELATED ROUTING
Before going deep, consider loading:
[mobile ssl pinning bypass](../mobile ssl pinning bypass/SKILL.md) for in depth cross platform SSL pinning bypass techniques and framework specific hooks
[ios pentesting tricks](../ios pentesting tricks/SKILL.md) when also testing the iOS version of the same app
[api sec](../api sec/SKILL.md) for backend API security testing once traffic is intercepted
Advanced Reference
Also load [FRIDA SCRIPTS.md](./FRIDA SCRIPTS.md) when you need:
Ready to use Frida script templates for common Android testing tasks
Detailed hook points for OkHttp, Retrofit, Volley, WebView
Root detection bypass script collection
1. SSL PINNING BYPASS
1.1 Frida Universal Bypass
Hook Point Library/Class Coverage
X509TrustManager.checkServerTrusted Android SDK All standard HTTPS
OkHttpClient.Builder.sslSocketFactory OkHttp 3.x/4.x Square OkHttp
CertificatePinner.check OkHttp 3.x/4.x OkHttp pinning
HttpsURLConnection.setSSLSocketFactory Android SDK Legacy HTTPS
SSLContext.init Android SDK Custom SSL contexts
WebViewClient.onReceivedSslError WebView WebView SSL errors
TrustManagerFactory.getTrustManagers Android SDK Factory created TMs
1.2 Objection (Quick Method)
1.3 Network Security Config (Debug Builds)
If you can modify the APK or it's a debug build:
1.4 Magisk Module Approach
Module Method Scope
LSPosed + TrustMeAlready Hooks system wide TrustManager All apps
LSPosed + SSLUnpinning Targeted SSL bypass Per app
MagiskTrustUserCerts Moves user CA to system store All apps trusting system CAs
ConscryptTrustUserCerts Patches Conscrypt Newer Android (7+)
2. COMPONENT EXPOSURE
2.1 Exported Activities
2.2 Content Providers
Provider Type Attack Vector Impact
Database backed SQL injection via query() projection/selection Data leak, auth bypass
File backed Path traversal via URI Read arbitrary files
Parcelable Type confusion in custom Parcelable Code execution
2.3 Broadcast Receivers
2.4 Exported Services
3. WEBVIEW VULNERABILITIES
3.1 JavaScript Interface RCE (Pre API 17)
3.2 Modern WebView Attacks
Vulnerability Condition Exploit
setJavaScriptEnabled(true) + untrusted content JS enabled + attacker controls loaded URL XSS → bridge access
setAllowFileAccessFromFileURLs(true) file:// can read other file:// Load file:///data/data/com.target/...
setAllowUniversalAccessFromFileURLs(true) file:// can access any origin Exfiltrate via XHR to attacker
loadUrl(user controlled) User input in loadUrl javascript: scheme or file://
shouldOverrideUrlLoading bypass Incomplete URL validation Redirect to attacker controlled page
evaluateJavascript with tainted data User data in JS execution XSS in WebView context
3.3 Deep Link to WebView Chain
4. INTENT REDIRECTION
Exported activity receives an Intent and starts another (internal) activity using data from the received Intent.
Pattern Indicator Risk
getParcelableExtra → startActivity Intent in Intent Start non exported activities
getStringExtra("url") → startActivity(Intent.ACTION VIEW) URL forwarding Open arbitrary URLs
getStringExtra("class") → Class.forName → startActivity Dynamic class loading Start any activity by name
5. ROOT DETECTION BYPASS
5.1 Common Root Detection Checks
Check What It Detects Frida Bypass
su binary exists /system/xbin/su , /sbin/su Hook File.exists() → return false
Build tags contain "test keys" Build.TAGS Hook Build.TAGS → return "release keys"
Magisk Manager installed Package name check Hook PackageManager.getPackageInfo
Superuser.apk present Su management app Hook File.exists()
RootBeer library Multi check root detection Hook all RootBeer check methods
SafetyNet/Play Integrity Server side attestation Requires Magisk DenyList + module
Abnormal system properties ro.debuggable=1 , etc. Hook SystemProperties.get
5.2 Magisk DenyList (Previously MagiskHide)
6. PLAY INTEGRITY / SAFETYNET BYPASS
Level What It Checks Bypass Difficulty
Basic Integrity Not rooted, not emulator Easy (Magisk + DenyList)
Device Integrity Bootloader locked, verified boot Hard (requires locked bootloader)
Strong Integrity Hardware backed attestation Very hard (hardware TEE)
Techniques:
Magisk with Zygisk enabled + DenyList for target app
Play Integrity Fix (PIF) Magisk module: spoofs device fingerprint
Shamiko module: hides root from specific apps
Custom ROM with locked bootloader (Pixel specific tricks)
7. TAPJACKING (OVERLAY ATTACKS)
Android Version Protection Bypass
Pre 6.0 None Full overlay
6.0–11 filterTouchesWhenObscured (opt in) Apps not using it are vulnerable
12+ Untrusted touches blocked for overlay windows Partial overlays, timing based
8. BACKUP EXTRACTION
9. ADDITIONAL TRICKS
9.1 Debuggable App Exploitation
9.2 Drozer (Component Testing Framework)
9.3 Clipboard Sniffing
10. ANDROID PENTESTING DECISION TREE