0:00 Music 0:07 Let's talk about analysis of mobile application. 0:12 So mobile application usually has some interesting vector of analysis. 0:18 Let me show you how to analyze mobile applications nowadays. 0:24 That is super easy. 0:27 So you have something like this. 0:33 You just browse your APK. 0:36 APK is iPhone. 0:40 I mean Android. 0:42 And APK is for iPhone. 0:44 I will take iPhone. 0:46 And I will start scanning. 0:48 So what it does in the background? 0:50 It is taking the IPA. 0:53 Right. 0:54 And it is extracting it. 0:56 This is archive. 0:58 And that IPA is extracted and all the useful information which is possible to parse, you just get here. 1:08 So you can see the application information, everything about this application. 1:16 You can see size. 1:18 You can see permissions. 1:19 So that specific application is trying to connect to basically your camera location and face ID. 1:30 So now you have some more context about what that application does. 1:35 You can see the list of frameworks which are used. 1:38 And additionally, you can see the files which were extracted. 1:44 So it's called my banking app application. 1:50 So what is the problem with mobile application for iPhone is that it is usually compiled for C sharp, not C sharp, Swift. 2:06 And Swift is very similar to 2:12 like C and that family, and it is compiling like really badly, and it is hard to decompile it. 2:20 What is easy to decompile is APK because it is usually Java based. 2:25 And I will show you the difference. 2:27 So let's go to see vulnerabilities. 2:31 So there are a list of different vulnerabilities. 2:35 And issues connected to, for example, we can check this one. 2:42 When we click findings and we try to, let me close the stuff. 2:51 So basically we can see that our system 2:56 is using OpenSSL version 1. 3:00 11180, which is vulnerable to this CV. 3:08 So what is the idea behind this stuff? 3:12 By default, we already understand that this application is vulnerable because it has those two CVs. 3:21 What it means that we need to contact developer and say, 3:29 look, you need to patch this old library and update it because it has this CVE and you can just go Google it and you will find what is going on. 3:44 Additionally, for some reason, 3:48 There is 444444 inside this application. 3:51 So if you have mobile application, maybe you have the iPhone or maybe you have Android. 3:58 It doesn't really matter because they both will be... 4:04 Analyzed using two methods. 4:06 One method is static analysis. 4:08 Second method is basically dynamic analysis. 4:11 Currently, we talk about static analysis. 4:14 So iPhone and Android, they both are packages. 4:22 So IPA and APK are chive. 4:26 And that archive is... 4:30 going to be basically extracted and all the files from the archive will be analyzed. 4:37 So again, I am uploading the file. 4:42 It can be like Telegram app. 4:44 It can be any app which is run on your phone. 4:47 Doesn't matter. 4:48 So you just... 4:49 Have this IPA or APK, any developer who is asking for audit, he can provide you this information. 4:59 If you don't want to get permission to do audit, which is completely legal, to be honest, you can do this audit completely legally without permission. 5:10 You can take the... 5:13 Emulation for Android installed on your computer and download the application on the emulator. 5:21 Or there are different tools which can allow you to connect to Google Market and download APK. 5:28 So APK is just application format. 5:31 The same goes for iPhone. 5:33 You can have the iPhone, which is rooted, jailbroken. 5:39 And if it is rooted and jailbroken, you can just copy it from your phone to your computer. 5:45 And after you can run such audit. 5:47 So what that audit is going to do? 5:50 That audit is basically trying to find secrets which were left accidentally by developers. 6:00 So what developers can leave in this application, right? 6:07 They can leave emails. 6:09 They can leave some interesting files, endpoints. 6:14 Let's see endpoints, right? 6:16 So here we can see a list of... 6:20 Different endpoints and one of them is Stack Overflow. 6:25 For some reason we have like a link to the Stack Overflow. 6:31 Interesting. 6:33 Let's view source. 6:39 You can learn more about adding permission in Stack Overflow. 6:43 So for some reason, it is just inside our application. 6:47 Somebody is discussing the Stack Overflow website. 6:51 Let's see this one. 6:54 So I think this is harmless stuff. 6:59 Right, so we just found some harmless stuff inside the application, but this is example of how you can like password, right? 7:12 For example, you can try to find password, password allowed. 7:18 Set password rules. 7:23 So you can just navigate. 7:26 Secret rules, right? 7:30 Do not pass this trick. 7:32 Do not pass this or you will be fired. 7:36 So, yeah. 7:38 This is some kind of, you know, secret. 7:44 Which you should not pass because you will be fired. 7:48 What is the joke around that stuff is that when you create some secrets 7:54 to encode data in database, you need to generate random password or you need to create some password. 8:05 But when you do not do anything, 8:09 People is using this one. 8:11 It means that you didn't change it. 8:15 So you got the point that they are using secret, which is saying secret, do not pass this or you will be fired. 8:22 So guy just, you know, did it on purpose or whatever, missed it. 8:30 So this is just an example of how you can easily analyze the iPhone. 8:35 Application real quick. 8:38 If it will find some API keys, you can just send them for audit. 8:45 And what are the API keys which you can find? 8:49 You can find the most valuable are API keys for Amazon, and you can just access the Amazon. 8:57 Like, let's imagine the developer is creating some kind of application. 9:04 And inside that application, he is storing some data, you know, connection to database. 9:13 So you will be able to find. 9:16 In the endpoints, this database, after you will double click on that specific endpoint, you will go to view in source. 9:25 And inside the source, you will see that the guy is connecting somewhere, that the guy is using external database, that the guy is using the keys, that the guy is doing whatever crazy stuff he can do. 9:37 So he assumes that his application is black. 9:43 He assumes that nobody will be able to extract the strings and read the content of his application. 9:52 But at least maybe 10% of no-buy applications. 9:59 Because I will tell you one of research which I was doing. 10:04 So maybe like five years ago, we downloaded full Google Market. 10:11 Like everything what was on Google Market, all the applications, maybe like 12,000, I don't exactly remember, like big amount of applications. 10:18 So we downloaded all of them. 10:20 And we were extracting only one string. 10:24 We were looking for the open databases, which are Firebase. 10:30 So I will show you what is Firebase and why do I even talk about that stuff. 10:39 And how is it connected to mobile application? 10:41 So let me show you. 10:46 Firebase. 10:49 Yeah. 10:50 So look at those numbers. 10:54 So this is least of the, it's not going to finish. 11:01 This is least of open databases. 11:05 Which we were able to extract automatically. 11:09 So if we will have the malicious intent to harm, the harm will be done great. 11:22 So look, again, 11:25 We have 7,000 databases. 11:30 7,500 databases. 11:32 And here we have passports, password, phone, pin code, secret, token, username, and much more. 11:41 Full name. 11:43 So whatever you want. 11:45 You want to see full names? 11:48 This is the database for the full names. 11:51 You wanted to, for example, see some messages. 11:55 This database is about those messages. 11:58 Maybe this is some kind of Fox driver. 12:01 Maybe like discussion between drivers and people. 12:06 The idea here is that Firebase is the database which can allow you to 12:14 you know, to store data or read data. 12:19 And usually it is using this API key. 12:22 And usually it is allowing the user to write only. 12:28 So you implement this database and you are saying, look, this is our database. 12:34 You can only write there. 12:36 And guy is just writing there and he blindly doing this. 12:41 He doesn't know what is going on. 12:43 So he just sending his data to the database. 12:46 But developers can accidentally click read and write, not only write. 12:54 So the guy will be able to read. 12:57 This database. 12:58 And you can see that like 7,000 databases 13:07 with completely different stuff, you know, some of them are empty, they are open but empty, but this one is crazy. 13:17 This is, look, look how many emails 13:23 Passwords are here. 13:26 So just to be clear, nobody was downloading those letters. 13:31 Nobody was doing anything. 13:32 This is just automatic analysis. 13:35 But can you imagine the amount of harm which can be done if it will be downloaded and just posted in the internet? 13:45 So this is just one of many examples. 13:50 About that stuff.
0:00 Music 0:07 Let's talk about analysis of mobile application. 0:12 So mobile application usually has some interesting vector of analysis. 0:18 Let me show you how to analyze mobile applications nowadays. 0:24 That is super easy. 0:27 So you have something like this. 0:33 You just browse your APK. 0:36 APK is iPhone. 0:40 I mean Android. 0:42 And APK is for iPhone. 0:44 I will take iPhone. 0:46 And I will start scanning. 0:48 So what it does in the background? 0:50 It is taking the IPA. 0:53 Right. 0:54 And it is extracting it. 0:56 This is archive. 0:58 And that IPA is extracted and all the useful information which is possible to parse, you just get here. 1:08 So you can see the application information, everything about this application. 1:16 You can see size. 1:18 You can see permissions. 1:19 So that specific application is trying to connect to basically your camera location and face ID. 1:30 So now you have some more context about what that application does. 1:35 You can see the list of frameworks which are used. 1:38 And additionally, you can see the files which were extracted. 1:44 So it's called my banking app application. 1:50 So what is the problem with mobile application for iPhone is that it is usually compiled for C sharp, not C sharp, Swift. 2:06 And Swift is very similar to 2:12 like C and that family, and it is compiling like really badly, and it is hard to decompile it. 2:20 What is easy to decompile is APK because it is usually Java based. 2:25 And I will show you the difference. 2:27 So let's go to see vulnerabilities. 2:31 So there are a list of different vulnerabilities. 2:35 And issues connected to, for example, we can check this one. 2:42 When we click findings and we try to, let me close the stuff. 2:51 So basically we can see that our system 2:56 is using OpenSSL version 1. 3:00 11180, which is vulnerable to this CV. 3:08 So what is the idea behind this stuff? 3:12 By default, we already understand that this application is vulnerable because it has those two CVs. 3:21 What it means that we need to contact developer and say, 3:29 look, you need to patch this old library and update it because it has this CVE and you can just go Google it and you will find what is going on. 3:44 Additionally, for some reason, 3:48 There is 444444 inside this application. 3:51 So if you have mobile application, maybe you have the iPhone or maybe you have Android. 3:58 It doesn't really matter because they both will be... 4:04 Analyzed using two methods. 4:06 One method is static analysis. 4:08 Second method is basically dynamic analysis. 4:11 Currently, we talk about static analysis. 4:14 So iPhone and Android, they both are packages. 4:22 So IPA and APK are chive. 4:26 And that archive is... 4:30 going to be basically extracted and all the files from the archive will be analyzed. 4:37 So again, I am uploading the file. 4:42 It can be like Telegram app. 4:44 It can be any app which is run on your phone. 4:47 Doesn't matter. 4:48 So you just... 4:49 Have this IPA or APK, any developer who is asking for audit, he can provide you this information. 4:59 If you don't want to get permission to do audit, which is completely legal, to be honest, you can do this audit completely legally without permission. 5:10 You can take the... 5:13 Emulation for Android installed on your computer and download the application on the emulator. 5:21 Or there are different tools which can allow you to connect to Google Market and download APK. 5:28 So APK is just application format. 5:31 The same goes for iPhone. 5:33 You can have the iPhone, which is rooted, jailbroken. 5:39 And if it is rooted and jailbroken, you can just copy it from your phone to your computer. 5:45 And after you can run such audit. 5:47 So what that audit is going to do? 5:50 That audit is basically trying to find secrets which were left accidentally by developers. 6:00 So what developers can leave in this application, right? 6:07 They can leave emails. 6:09 They can leave some interesting files, endpoints. 6:14 Let's see endpoints, right? 6:16 So here we can see a list of... 6:20 Different endpoints and one of them is Stack Overflow. 6:25 For some reason we have like a link to the Stack Overflow. 6:31 Interesting. 6:33 Let's view source. 6:39 You can learn more about adding permission in Stack Overflow. 6:43 So for some reason, it is just inside our application. 6:47 Somebody is discussing the Stack Overflow website. 6:51 Let's see this one. 6:54 So I think this is harmless stuff. 6:59 Right, so we just found some harmless stuff inside the application, but this is example of how you can like password, right? 7:12 For example, you can try to find password, password allowed. 7:18 Set password rules. 7:23 So you can just navigate. 7:26 Secret rules, right? 7:30 Do not pass this trick. 7:32 Do not pass this or you will be fired. 7:36 So, yeah. 7:38 This is some kind of, you know, secret. 7:44 Which you should not pass because you will be fired. 7:48 What is the joke around that stuff is that when you create some secrets 7:54 to encode data in database, you need to generate random password or you need to create some password. 8:05 But when you do not do anything, 8:09 People is using this one. 8:11 It means that you didn't change it. 8:15 So you got the point that they are using secret, which is saying secret, do not pass this or you will be fired. 8:22 So guy just, you know, did it on purpose or whatever, missed it. 8:30 So this is just an example of how you can easily analyze the iPhone. 8:35 Application real quick. 8:38 If it will find some API keys, you can just send them for audit. 8:45 And what are the API keys which you can find? 8:49 You can find the most valuable are API keys for Amazon, and you can just access the Amazon. 8:57 Like, let's imagine the developer is creating some kind of application. 9:04 And inside that application, he is storing some data, you know, connection to database. 9:13 So you will be able to find. 9:16 In the endpoints, this database, after you will double click on that specific endpoint, you will go to view in source. 9:25 And inside the source, you will see that the guy is connecting somewhere, that the guy is using external database, that the guy is using the keys, that the guy is doing whatever crazy stuff he can do. 9:37 So he assumes that his application is black. 9:43 He assumes that nobody will be able to extract the strings and read the content of his application. 9:52 But at least maybe 10% of no-buy applications. 9:59 Because I will tell you one of research which I was doing. 10:04 So maybe like five years ago, we downloaded full Google Market. 10:11 Like everything what was on Google Market, all the applications, maybe like 12,000, I don't exactly remember, like big amount of applications. 10:18 So we downloaded all of them. 10:20 And we were extracting only one string. 10:24 We were looking for the open databases, which are Firebase. 10:30 So I will show you what is Firebase and why do I even talk about that stuff. 10:39 And how is it connected to mobile application? 10:41 So let me show you. 10:46 Firebase. 10:49 Yeah. 10:50 So look at those numbers. 10:54 So this is least of the, it's not going to finish. 11:01 This is least of open databases. 11:05 Which we were able to extract automatically. 11:09 So if we will have the malicious intent to harm, the harm will be done great. 11:22 So look, again, 11:25 We have 7,000 databases. 11:30 7,500 databases. 11:32 And here we have passports, password, phone, pin code, secret, token, username, and much more. 11:41 Full name. 11:43 So whatever you want. 11:45 You want to see full names? 11:48 This is the database for the full names. 11:51 You wanted to, for example, see some messages. 11:55 This database is about those messages. 11:58 Maybe this is some kind of Fox driver. 12:01 Maybe like discussion between drivers and people. 12:06 The idea here is that Firebase is the database which can allow you to 12:14 you know, to store data or read data. 12:19 And usually it is using this API key. 12:22 And usually it is allowing the user to write only. 12:28 So you implement this database and you are saying, look, this is our database. 12:34 You can only write there. 12:36 And guy is just writing there and he blindly doing this. 12:41 He doesn't know what is going on. 12:43 So he just sending his data to the database. 12:46 But developers can accidentally click read and write, not only write. 12:54 So the guy will be able to read. 12:57 This database. 12:58 And you can see that like 7,000 databases 13:07 with completely different stuff, you know, some of them are empty, they are open but empty, but this one is crazy. 13:17 This is, look, look how many emails 13:23 Passwords are here. 13:26 So just to be clear, nobody was downloading those letters. 13:31 Nobody was doing anything. 13:32 This is just automatic analysis. 13:35 But can you imagine the amount of harm which can be done if it will be downloaded and just posted in the internet? 13:45 So this is just one of many examples. 13:50 About that stuff.