Emulating Android library to decrypt strings (Qiling Framework)

Опубликовано: 06 Октябрь 2024
на канале: FatalSec
2,033
84

#android #mobilesecurity #emulation #qilingframework #reversengineering #pentest

In this video we are going to see how to extract encrypted strings present inside a native library of an android app which are used in performing various environmental checks on the device such as root detection, frida detection etc.

As nowadays most of the apps uses some kind of in-app protection to protect the app from being reverse engineered it is becoming difficult to perform analysis on them and that's where we can leverage the power of emulation. Using emulation, we can execute the binary without the need to run it on real device. We are going to write a script to emulate certain parts of the native library in order to extract the decrypted strings.

The sample application we have used in this video is available here on our Github repository: https://github.com/fatalSec/string_de...

If you do enjoy watching our videos and its helping in your reverse engineering, then do subscribe to our channel and share it with others this will motivate us to keep making new videos.

You can follow us on Twitter:   / secfatal   You can also join our community on Telegram: https://t.me/+74Fx_Za9XS41OGU1

If you like what we are doing and want to encourage us, then you can buy us a coffee: https://www.buymeacoffee.com/secfatalz