BinderFuzzy - Pentest Android Services
An App intended for fuzzing the Binder interface and System Services of Android.
New in version 1.0
* initial release
BinderFuzzy is a fuzzer that can generate binder events in order to pentest system services running on the Android operating system (https://developer.android.com/reference/android/os/Binder, https://source.android.com/devices/architecture/hidl/binder-ipc). You can validate if system services have correct error handling or transfer binder objects / tokens of other services in order to validate if the target system service validates binder arguments.
This Project covers following features:
* Browse managers and binder interfaces.
* Execute Fuzzy tasks
* Configure argument lists for each parameter of the method to fuzz
* Read logs of recent tasks
* Use python3 cli (optional) to execute fuzzer from desktop.
* Define fuzzer script and execute via cli
Enjoy our App!
This Project covers following features:
* Browse managers and binder interfaces.
* Execute Fuzzy tasks
* Configure argument lists for each parameter of the method to fuzz
* Read logs of recent tasks
* Use python3 cli (optional) to execute fuzzer from desktop.
* Define fuzzer script and execute via cli
Enjoy our App!
- Author: ChickenHook
- License: Apache License 2.0
- Video
- Issue Tracker
- Source Code
- Changelog
- Build Metadata
Donate
Versions
Although APK downloads are available below to give you the choice, you should be aware that by installing that way you will not receive update notifications and it's a less secure way to download. We recommend that you install the F-Droid client and use that.
Download F-Droid-
arm64-v8a
armeabi-v7a
x86
x86_64
This version requires Android 4.4 or newer.
It is built by F-Droid and guaranteed to correspond to this source tarball.
Download APK 3.6 MiB PGP Signature | Build Log