移动网络安全测试软件,Scrounger:一款功能强大的移动端应用程序安全测试套件...

$scrounger-console

StartingScrounger console...

>help

Documentedcommands (type help ):

========================================

add_device  devices list     print  results set   unset

back        help    options  quit   run     show  use

>help list

Listsall available modules

>list ios

Module                                  CertaintyAuthor Description

------                                  --------------- -----------

analysis/ios/app_transport_security     90%      RDC    Checks if there are anyApplication Transport Security misconfigurations

analysis/ios/arc_support                90%       RDC   Checks if a binary was compiled with ARC support

analysis/ios/backups                    90%       RDC   Checks the application's files have the backup flag on

analysis/ios/clipboard_access           75%       RDC   Checks if the application disables clipboard access

analysis/ios/debugger_detection         75%       RDC   Checks if the applicationdetects debuggers

analysis/ios/excessive_permissions      90%      RDC    Checks if the applicationuses excessive permissions

analysis/ios/file_protection            90%       RDC   Checks the application's files specific protection flags

analysis/ios/full_analysis              100%      RDC   Runs all modules in analysis and writes a report into the outputdirectory

analysis/ios/insecure_channels          50%       RDC   Checks if the application uses insecure channels

analysis/ios/insecure_function_calls    75%      RDC    Checks if the applicationuses insecure function calls

analysis/ios/jailbreak_detection        60%       RDC   Checks if the application implements jailbreak detection

analysis/ios/logs                       60%      RDC    Checks if the applicationlogs to syslog

analysis/ios/passcode_detection         60%       RDC   Checks if the application checks for passcode being set

analysis/ios/pie_support                100%      RDC   Checks if the application was compiled with PIE support

analysis/ios/prepared_statements        60%       RDC   Checks if the application uses sqlite calls and if so checks if it alsouses prepared statements

analysis/ios/ssl_pinning                60%       RDC   Checks if the application implements SSL pinning

analysis/ios/stack_smashing             90%       RDC   Checks if a binary was compiled stack smashing protections

analysis/ios/third_party_keyboard       65%      RDC    Checks if an applicationchecks of third party keyboards

analysis/ios/unencrypted_communications80%       RDC    Checks if the application implementscommunicates over unencrypted channels

analysis/ios/unencrypted_keychain_data  70%      RDC    Checks if the applicationsaves unencrypted data in the keychain

analysis/ios/weak_crypto                60%       RDC   Checks if the application uses weak crypto

analysis/ios/weak_random                50%       RDC   Checks if a binary uses weak random functions

analysis/ios/weak_ssl_ciphers           50%       RDC   Checks if a binary uses weak SSL ciphers

misc/ios/app/archs                      100%      RDC   Gets the application's available architectures

misc/ios/app/data                       100%      RDC   Gets the application's data from the remote device

misc/ios/app/entitlements               100%      RDC   Gets the application's entitlements

misc/ios/app/flags                      100%      RDC   Gets the application's compilation flags

misc/ios/app/info                       100%      RDC   Pulls the Info.plist info from the device

misc/ios/app/start                      100%      RDC   Launches an application on the remote device

misc/ios/app/symbols                    100%      RDC   Gets the application's symbols out of an installed application on thedevice

misc/ios/class_dump                     100%      RDC   Dumps the classes out of a decrypted binary

misc/ios/decrypt_bin                   100%      RDC   Decrypts and pulls a binary application

misc/ios/install_binaries               100%      RDC   Installs iOS binaries required to run some checks

misc/ios/keychain_dump                  100%      RDC   Dumps contents from the connected device's keychain

misc/ios/local/app/archs                100%      RDC   Gets the application's available architectures

misc/ios/local/app/entitlements         100%      RDC   Gets the application's entitlements from a local binary and saves themto file

misc/ios/local/app/flags                100%      RDC   Gets the application's compilation flags using local tools. Will lookfor otool and jtool in the PATH.

misc/ios/local/app/info                 100%      RDC   Pulls the Info.plist info from the unzipped IPA file and saves an XMLfile with it's contents to the output folder

misc/ios/local/app/symbols              100%      RDC   Gets the application's symbols out of an installed application on thedevice

misc/ios/local/class_dump              100%      RDC   Dumps the classes out of a decrypted binary

misc/ios/pull_ipa                       100%      RDC   Pulls the IPA file from a remote device

misc/ios/unzip_ipa                      100%      RDC   Unzips the IPA file into the output directory

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值