Minggu, 02 Februari 2014

Hacking Apps for Android devices



Now days, smartphones and tablets are most the popular gadgets. If we see recent stats, global PC sale has also been decreasing for the past few months. The reason behind this is that people utilize tablets for most of their work. And there is no need to explain that Android is ruling global smartphone and tablet markets. Android is most popular mobile OS with more than 60% market share.

So, companies are now focusing on bringing their software as a mobile app for Android. These apps include office apps, photo editing apps, instant messaging apps and penetration testing apps. If you have an Android smartphone, you can start your next penetration testing project from your Android phone. There are few android apps that can turn your Android device into a hacking device. Although, these apps have so many limitations and can only be used for few specific tasks. You can never get the same experience as you get with your PC. But smaller jobs can be performed. Apps for penetration testers are not available widely, but hackers can enjoy this platform in a better way. There are many Wi-Fi hacking and sniffing apps available.

As we already said that Android is ruling smartphone and tablet markets, developers are also creating more apps for Android devices. This is the reason why the Android market has millions of apps. Like websites, apps also need penetration testing to check for various vulnerabilities. Security testing for Android apps will need to have a penetration testing environment on your Android device.

Note:

  1. Most of the apps work on Rooted Android devices. So root your Android device first. If you are not sure how to do it, learn how to by, reading one of the many sites available to help with this process.
  2. You will lose your device’s warranty if you root it, so think twice before proceeding.
  3. These apps can also harm your Android device. So please try these apps at your own risk.
In this detailed post, we will see various apps for web application penetration testing, network penetration testing, sniffing, networking hacking and Android apps penetration testing.

Android apps for Penetration testing :


1. dSploit
 
dSploit is a nice Android network penetration testing suit. It comes with all-in-one network analysis capabilities. Like most of the other penetration testing tools, it also comes for free. So, you can download and use this app on your Android device and perform network security testing. It has various pre-complied modules to use. The app is designed to be very fast, handy and easy to use, it’s just point and click.
dSploit supports all Android devices running on Android 2.3 Gingerbread or higher, and you also need to root your device. If you are newbie, we will never recommend you to use the app if you don’t know how to root your Android device. After rooting your device, you need to install BusyBox Installer. 
Download BusyBox from Google Play Store 
Then download the app from the link given below.
dSploit source code is available on github 
These are the available modules in the app.
  1. RouterPWN
  2. Trace
  3. Port Scanner
  4. Inspector
  5. Vulnerability Finder
  6. Login Cracker
  7. Packet Forger
  8. Man In The Middle (MITM)
2. Network Spoofer
 Network Spoofer is another nice app that lets you change the website on other people’s computer from your Android phone. Download the Network Spoofer app and then log onto the Wi-Fi network. Choose a spoof to use with the app then tap on start. This app is considered as a malicious hacking tool by network administrators. So, don’t try on unauthorized networks. This is not a penetration testing app. It’s just to demonstrate how vulnerable the home network is. Download this app from sourceforge 

3. Network Discovery
 Network Discovery is a free app for the Android device. The good thing is that the app doesn’t need a rooted device. This app has a simple and easy to use interface. It views all the networks and devices connected to your Wi-Fi network. The application identifies the OS and manufacturer of the device. Thus the app helps in information gathering on the connected Wi-Fi network. Download app from Google Play

4. DroidSheep [Root]
 DroidSheep is a session hijacking tool for Android devices. This is an app for security analysis in wireless networks. It can capture Facebook, Twitter, and LinkedIn, Gmail or other website accounts easily. You can hijack any active web account on your network with just a tap by using the DroidSheep app. It can hijack any web account. This app demonstrates the harm of using any public Wi-Fi.
Download this app from here

5. DroidSheep Guard
 DroidSheep Guard is another Android app that also developed Droidsheep. This app does not require a rooted device. This app monitors Android devices’ ARP-table and tries to detect ARP-Spoofing attack on the network performed by DroidSheep, FaceNiff and other software.
Download DroidSheep Guard from Google Play

6. WPScan
 WpScan is the WordPress vulnerability scanner for Android devices. This nice app is used to scan a WordPress based website and find all the security vulnerabilities it has. WPScan also has a desktop version of the app that is much powerful than the Android app. We know that WordPress is one of the most popular CMS and is being used by millions of websites. The Android version of the app comes with few nice features. The app was released on Google Play but Google removed the app. The full source code of the app is available from Github. One thing to note that WPScan Android app is not related to the desktop version of WPScan. So, never think it as an official WPScan app.

7. WebSecurify
 WebSecurify is a powerful web vulnerability scanner. It’s available for all popular desktops and mobile platforms. It has a powerful crawler to crawl websites and then attack it using pre-defined patterns. We have already covered it in detail in our previous article. You can read the older article for better understanding.

8. Network Mapper
 Network Mapper is a fast scanner for network admins. It can easily scan your network and export the report as CVS to your Gmail. It lists all devices in your LAN along with details. Generally, the app is used to find Open ports of various servers like FTP servers, SSH servers, SMB servers etc. on your network. The tool works really fast and gives effective results.
Download Network Mapper from Google Play Store

9. Router Bruteforce ADS 2
 If you are connected to a wi-Fi network and you want to access the router of the network, you can use Router Bruteforce ADS 2 app. This app performs Bruteforce attack to get the valid password of the router. It has a list of default passwords that it tries on the router. Most of the time, the app cracks the password. But you cannot be 100% sure in Bruteforce attack. It comes with a sample txt file which contains 398 default passwords used in different routers. You can add more passwords in the list. But there is one limitation. This app only works with dictionary file of less than 5 MB. And try it only when you have good Wi-Fi signal. This is an experiment app and the developer also warns users to try at own risk.
Download Router Bruteforce ADS 2 from Google Play

10. AppUse – Android Pentest Platform Unified Standalone Environment
 

AppUse Virtual Machine is developed by AppSec Labs. It’s a freely available mobile application security testing platform for Android apps. This android penetration testing platform contains custom made tools by AppSec Labs. This penetration testing platform is for those who are going to start penetration testing of Android applications. All you need is to download the AppUse Virtual Machine and then load the app for testing. The app comes with most of the configuration. So, you do not need to install simulators, testing tools, no need for SSL certifications of Proxy. Thus, the tool gives ideal user experience. In other words, you can say that AppUse Virtual Machine is Backtrack for Android apps. As we know that world is moving towards apps, AppUse VM has a good scope in future. We see how Android users face attacks and these cyber-attacks are growing. So, it is important for all Android app developers to test their apps for various kinds of vulnerabilities. Download AppUse Virtual machine

Source : http://resources.infosecinstitute.com
Thanks for visit my blog
Regards,

Eko A. Anggriawan
ekospinach ITpreneur

Rp172,9 MILIAR Untuk Beasiswa Kaltim Cemerlang 2014



Kepemimpinan Gubernur Kaltim Awang Faroek Ishak bersama wakilnya Mukmin Faisyal telah dilantik pada 17 Desember 2013 lalu akan tetap mengucurkan program Beasiswa Kaltim Cemerlang untuk periode 2014-2018. “Program Beasiswa Kaltim Cemerlang yang sudah digulirkan pada periode 2009-2013 akan tetap dilanjutkan dalam periode 2014-2018 karena program ini untuk meningkatkan mutu pendidikan,” ujar Kepala Dinas Pendidikan Provinsi Kalimantan Timur (Kaltim) H Musyahrim. Program Kaltim Cemerlang yang berarti cerdas, merata dengan prestasi gemilang, merupakan upaya Pemprov Kaltim memberikan beasiswa bagi pelajar dan mahasiswa bukan hanya untuk warga Kaltim, tetapi juga untuk warga Kalimantan Utara (Kaltara), provinsi baru hasil pemekaran dari Kaltim. 

Guna pemerataan penerima beasiswa, maka dalam Rencana Pembangunan Jangka Menengah Daerah (RPJMD) Kaltim 2014-2018, sistem pendaftaran untuk memperoleh beasiswa mendapat revisi, yakni yang sebelumnya semua pendaftarannya dilakukan melalui internet, maka ke depan untuk kawasan perbatasan dan daerah terpencil dilakukan secara manual. Untuk daerah perkotaan, pendaftaran guna mendapatkan beasiswa tetap dilakukan secara online, tetapi di kawasan perbatasan dan daerah terpencil yang belum mendapatkan akses internet, maka dilakukan kerja sama dengan dinas pendidikan di kabupaten untuk mendata pelajar dan mahasiswa yang akan mendapatkan beasiswa. Beasiswa Kaltim Cemerlang diberikan kepada pelajar berprestasi dan tidak mampu, termasuk kepada mahasiswa berprestasi dan tidak mampu di semua program studi sehingga terjadi pemerataan penyalurannya. Selain menyalurkan beasiswa, pihaknya juga tetap mengembangkan sekolah unggulan yang tersebar di kabupaten dan kota, pasalnya sekolah unggulan untuk memberikan pelayanan kepada siswa unggul. Hal ini perlu dilakukan karena perkembangan pendidikan bagi siswa unggul tidak akan maksimal jika hanya dididik setara dengan standar pendidikan yang ada, pasalnya dalam pendidikan di sekolah umum dilakukan penyamarataan.

Pengembangan sekolah unggulan bukan berarti mengecilkan kualitas pendidikan pada sekolah konvensional atau sekolah  umum. Sekolah konvensional kualitasnya bagus, tetapi tidak cocok untuk siswa unggul. Bagi siswa yang tingkat kecerdasannya umum tetap bersekolah di sekolah konvensional, tetapi bagi siswa unggul sebaiknya dididk di sekolah unggulan.

Pada 2014 Pemprov Kaltim mengalokasikan anggaran sangat fantastis untuk beasiswa, yakni mencapai Rp172,9 miliar yang diperuntukkan bagi 52.667 pelajar dan mahasiswa baik berupa beasiswa prestasi maupun beasiswa tidak mampu. “Beasiswa Kaltim Cemerlang dari Pemprov Kaltim pada 2014 ini mengalami kenaikan ketimbang tahun sebelumnya, yakni pada 2013 diberikan kepada 31.116 penerima dengan total beasiswa senilai Rp149 miliar,” ujar Kepala Dinas Pendidikan Kaltim H Musyahrim. Alokasi beasiswa dan stimulan yang sebesar Rp172,9 miliar itu terdiri Beasiswa Kaltim Cemerlang sebesar Rp125 miliar untuk 50.000 penerima, pemberian penghargaan bagi siswa berprestasi, yakni siswa SMAN 10, Mitra Pasiad dan Studi Luar Negeri sebanyak Rp26,17 miliar bagi 697 orang. Kemudian untuk beasiswa kualifikasi guru sampai menyesaiikan strata satu dan strata dua (S1 dan S2) senilai Rp19,93 miliar untuk 1.480 orang, dan beasiswa Tutor Pendidikan Anak Usia Dini (PAUD) senilai Rp1,83 miliar bagi 490 orang.

Dia juga mengatakan bahwa dalam penyaluran beasiswa di tahun 2013 dan tahun-tahun sebelumnya telah dilakukan evaluasi, sehingga dalam penyaluran beasiswa mulai 2014 dan seterusnya akan lebih baik. Evaluasi dilakukan agar penerimanya lebih tetap sasaran dan bermanfaat, sehingga mulai 2014 akan dilakukan dengan memberikan kuota tertentu di setiap  perguruan tinggi negeri dan swasta, atau proses seleksi dan usulan dilakukan pemerintah kabupaten dan kota di Kaltim dan Kaltara. Diterapkannya sistem tersebut diharapkan masing-masing kabupaten dan kota, perguruan tinggi, dan sekolah dapat menentukan kuota mereka, siapa yang berhak menerima. 

Meski begitu, Pemprov Kaltim tetap akan mengelola penerimaan beasiswa yang telah diprogramkan, seperti untuk mahasiswa di Institut Teknologi Kalimantan (ITK) di Balikpapan dan mahasiswa di Institut Seni dan Budaya Indonesia (ISBI) di Kabupaten Kutai Kartanegara. Saat ini semua mahasiswa ITK masih melakukan kuliah di Institut Teknologi Sepuluh Nopember (ITS) Surabaya, sedangkan mahasiswa ISBI masih menumpang kuliah di Institut Seni Indonesia (ISI) Yogyakarta, tetapi jika Kampus ITK dan ISBI sudah terbangun, maka mereka akan pindah ke Kaltim.
ekospinach ITpreneur