26
Hack Wireless from Mobile Phone usingZANTI --mobile pentesting toolkit-- ~ Written by puupuu@deb~lab ~ I am blogger ! www.kyawzinhein.net

zAnti Android Wireless Pentesting guide ().pdf

Embed Size (px)

Citation preview

Page 1: zAnti Android  Wireless Pentesting  guide  ().pdf

Hack Wireless from Mobile Phone

usingZANTI

--mobile pentesting toolkit--

~

Written by

puupuu@deb~lab

~

I am blogger !

www.kyawzinhein.net

Page 2: zAnti Android  Wireless Pentesting  guide  ().pdf

Requirement....

1.Aroid Phone or Tablet

2.Internet Connection

3.zAnti mobile pentesting toolkit

Page 3: zAnti Android  Wireless Pentesting  guide  ().pdf

zANTI α€€α€–α€Όα€„α€•α€«αŠ Root Access ေတာငးရင Allow α€±α€•α€Έα€•α€«αŠ

Page 4: zAnti Android  Wireless Pentesting  guide  ().pdf

α€•α€Όα€„α€œα€¬α€›α€„ ရတEmail Address α€α€…α€α€‘α€Šα€•α€«αŠ

accept Zimpremium's EULA α€€α€‘α€™α€”α€»α€α€…α€±α€•α€Έα€•α€«αŠ

ျပးရင Start Now ကႏပပါ။

Page 5: zAnti Android  Wireless Pentesting  guide  ().pdf

Skipt α€€α‚α€•α€•α€«αŠ

Page 6: zAnti Android  Wireless Pentesting  guide  ().pdf

α€‘α€α€„α€Έα€…α€œα€Šα€•α€«α€™α€š α€±α€α€α€±α€…α€¬α€„α€•α€«αŠ :P

α€œα€„α€Έα€™α€±α€€α€¬α€„α€Έα€›α€„α€±α€α€¬ ၾကာမေပါ ၊

Page 7: zAnti Android  Wireless Pentesting  guide  ().pdf

α€‘α€α€„α€Έα€œα€Šα€œ α€α€»α€•α€†α€’α€œα€±α€•αšα€œα€¬α€™α€š ၊

α€Šα€¬α€˜α€€α€‘α€±α€•αšα€†α€Έα€€ Skipα€€α‚α€•α€•α€«αŠ

Page 8: zAnti Android  Wireless Pentesting  guide  ().pdf

I am fully authorized to perform

penetration testing on network.

α€€α€‘α€™α€”α€»α€α€…α€•α€«αŠ

Finish ကႏပပါ

Page 9: zAnti Android  Wireless Pentesting  guide  ().pdf

α€˜α€šα€˜α€€α€€ ZANTI α€€α‚α€•αŠ

Page 10: zAnti Android  Wireless Pentesting  guide  ().pdf

zTether α€€α‚α€•α€•α€«αŠ

Page 11: zAnti Android  Wireless Pentesting  guide  ().pdf

Tether Control α€‘α€±α€›α€¬α€€α€•α€«α€œα€™α€™α€šαŠ ဒထက tool ေတြက

ထျကမးဖα€₯α€Έα€±α€»α€•α€¬α€›α€™α€šα€†α€›α€„

Page 12: zAnti Android  Wireless Pentesting  guide  ().pdf

1. Logged Request

ဆတာက viticam ဆက network traffic α€±α€α€Όα€‘α€€α€”α€œα€Έα€€α€»α€•α€±α€•α€Έα€™α€šα€±α€”α€›α€¬α€•α€«αŠ

2. Logged Images

ဆတာက viticam α€±α€α€Όα€»α€€α€Šα€±α€”α€ website ေတြ messenger ေတြက α€•α€±α€α€Όα€€α€»α€•α€±α€•α€Έα€™α€šα€±α€”α€›α€¬α€•α€«αŠ

3.zPackage Editor

ဆတာမာကေတာ HTTP request တစခခငးဆက α€»α€•α€„α€†α€„α‚α€„α€™α€¬α€•α€«αŠ

4.SSL Stript

ဆတာကေတာ https α€œα€„α€Έα€€ http α€»α€–α€…α€±α€‘α€¬α€„α€œα€•α€±α€•α€Έ

α€α€¬α€•α€«αŠ α€’α€±α€€α€¬α€„α€€α€‘α€“α€€α€€α€•α€«α€α€š ၊ α€˜α€¬α€œ ဆ https ကြနနကရငက ကၽြနေတာတ αΎα€€α€¬α€Έα€»α€–α€α€šα€œ α€™α€›α€•α€«α€˜α€ΈαŠα€’α€«α€±αΎα€€α€¬α€„ viticam α€€ https access မရေထာင α€œα€•α€‘α€¬α€Έα€•α€«α€™ viticam

Page 13: zAnti Android  Wireless Pentesting  guide  ().pdf

α€›α€‘α€„α€α€¬α€”α€€α€€α€Όα€”α€šα€€α€€ αΎα€€α€¬α€Έα€»α€–α€α€šα€œ α€›α€•α€«α€™α€šαŠ

5.Redirect HTTP

ဒါကေတာ α€›α€Έα€›α€„α€Έα€•α€«α€α€š ။ viticam α€€ www.bing.comα€€ browser α€€α€±α€”α€žα€Όα€¬α€Έα€α€šα€†α€›α€„www.bing.comကမေရာကပ α€€α€šα€±α€›α€¬α€€α€±α€…α€α€„α€α€±α€”α€›α€¬ eg.www.kyawzinhein.netα€€α€±α€›α€¬α€€α€žα€Όα€¬α€Έα€±α€‘α€¬α€„

α€œα€•α€α€¬α€•α€«αŠ www.bing.comα€α€„α€™α€Ÿα€€α€˜α€Έα€±α€”α€¬ α€žα€˜α€šα€œα€•α€…α€¬

ကပ request α€œα€•α€œα€• α€±α€»α€™α€¬α€€α€’α€‚α€žα€¬α€Έ blog α€€α€•α€±α€›α€¬α€€α€•α€«α€™α€šα‹

6.Replace Image

α€”α€¬α€™α€Šα€‘α€α€„α€Έα€• α€•α€‘α€…α€¬α€Έα€‘α€Έα€α€¬α€•α€«αŠ α€₯ပမာ www.xvideos.comα€™α€¬α€‚α€œα€α€šα€†α€•α€«α€… α€‘α€™α€¬α€±α€•αšα€±α€”α€ 18+ videos ေတြပရ ပေတြေနရာ

မာ α€‘α€…α€¬α€Έα€‘α€Έα€œα€€α€α€• α€α€…α€•α€α€Šα€Έα€€α€žα€Όα€¬α€Έα€±α€•αšα€±α€”α€™α€¬α€•α€«αŠ

Page 14: zAnti Android  Wireless Pentesting  guide  ().pdf

viticamα€†α€™α€¬α€α€€α€žα€™α€•α€±α€α€Όα€‘α€€α€”α€œα€Έα€€

α€žα€„α€‘α€…α€¬α€Έα€‘α€Έα€œα€€α€ (eg.၀ကပဆ) α€α€€α€•α€±α€α€ΌαΎα€€α€Έα€±α€•αšα€±α€”α€™α€¬α€•α€«αŠ

α€˜α€šα€•α€™α€† α€žα€„α€α€„α€‘α€¬α€Έα€α€α€€α€•αΎα€€α€Έ α€•α€±α€•αšα€±α€”α€™α€¬α€•α€«αŠ

7.Capture Download

viticam α€€α€˜α€¬α€•α€±α€’α€«α€„α€Έα€œα€’α€†α€Όα€†α€Ό α€žα€„α€–α€”α€Έα€™α€”α€™α€›α€‘α€€α€•α€« α€α€…α€α€«α€α€Šα€Έ

α€±α€’α€«α€„α€Έα€œα€’α€€α€Έα€šα€±α€•α€Έα€™α€¬α€»α€–α€…α€•α€«α€α€šαŠ

8.Intercept Download

α€’α€«α€œα€Šα€Έ replace image α€œα€•α€«α€• ၊ viticam α€˜α€¬α€•α€±α€’α€«α€„α€Έα€œα€’α€†α€Όα€†α€Ό

α€žα€„ ထစားထးထားတ α€–α€„α€€α€•α€†α€Όα€žα€Όα€¬α€Έα€•α€«α€œα€™α€™α€š ၊

eg . downတာက 18+ထစားထးထားတာက anime :P

α€‚α€Όα€™α€Έα€±α€œα€žα€α€Šα€ΈαŠ

Page 15: zAnti Android  Wireless Pentesting  guide  ().pdf

9.Insert HTML

α€’α€«α€€α€±α€α€¬α€™α€žα€Έα€α€€α€›α€„α€±α€α€¬ αΎα€€α€€α€™α€¬α€™α€Ÿα€€α€˜α€Έ script injection α€œα€•α€α€¬α€•α€« ၊ www.bing.comα€€α€žα€Όα€¬α€Έα€α€šα€†α€•α€«α€… α€€α€šα€€

<script>alert(''Hacked by PuuPuu”)<script>ဆျပး inject α€œα€•α€‘α€¬α€Έα€›α€„ viticam ဆမာ Hacked By PuuPuu α€†α€»α€•α€Έα€žα€Όα€¬α€Έα€±α€•αšα€±α€”α€™α€¬α€•α€« ၊

Page 16: zAnti Android  Wireless Pentesting  guide  ().pdf

How To Hack in Real World……

1. α€œα€…α€Šα€€α€¬α€Έα€›α€¬α€±α€”α€›α€¬α€α€…α€α€€α€žα€Όα€¬α€Έα€•α€«αŠ

2. Tether Control ကဖြငပါ ၊ ၀ငဖင hotspot α€α€…α€α€œα‚Šα€„α€•α€«α€™α€šαŠ

3. α€žα€„α€±α€‘α€¬α€„α€‘α€¬α€Έα€hotspotα€‘α€€α€α€„α€œα€¬α€α€žα€€ hack α‚α€„α€•α€«α€α€šαŠ

Tether Control α€€ On α€•α€«αŠ

Page 17: zAnti Android  Wireless Pentesting  guide  ().pdf

ထခဆရင α€„α€«α€Έα€™α€¬α€Έα€α€α€α€œα€€α€•α€«α€»α€• α€žα€¬α€Έα€±α€€α€¬α€„α€€ α€±α€…α€¬α€„α€•α€«αŠ မပပါန

α€α€„α€–α€„α€‘α€œα€€α€¬α€Έα€›α€α€„α€Έ α€žα€Έα€α€¬

α€€α½α€Όα€”α€±α€α€¬α€α€…α€±α€šα€¬α€€α€α€Šα€Έα€™α€Ÿα€€α€•α€«α€˜α€Έ မားမား၀ငေစခငရငေတာ

Free Internet Access ဆျပး Access Point SSID: α€™α€¬α€±α€›α€Έα€œα€€α€±α€•α€«

α€€ α€α€…α€±α€šα€¬α€€α€α€„α€œα€¬α€»α€•α€•α€‘α€¬α€Έ ကၽြနေတာ α€»α€•α€™α€š ၊ ေထာကမာ show

Page 18: zAnti Android  Wireless Pentesting  guide  ().pdf

Logged Request α€‘α€€α€α€„α€œα€€α€•α€«αŠ

Logged Request ဆတာက α€‘α€±α€•αšα€™α€¬α€±α€»α€•α€¬α€α€žα€œα€•

network traffic α€±α€α€Όα€‘α€€α€”α€œα€Έα€€α€»α€•α€±α€•α€Έα€™α€šα€±α€”α€›α€¬α€•α€«αŠ

Page 19: zAnti Android  Wireless Pentesting  guide  ().pdf

Logged Host ဆတာကေတြ α€•α€«α€™α€š α€’α€‘α€™α€¬α€˜α€¬α€±α€α€Όα€€α€±α€α€Ό α€›α€™α€œα€†α€›α€„

Viticam ေတြဆက Request α€œα€•α€±α€”α€ host ေတြကေတြ α€›α€•α€«α€™α€šαŠ

α€₯ပမာ viticam α€€ www.google.comα€œ browser

α€€α€±α€”α€›α€€α€œα€€α€™α€šα€†α€›α€„ ဒထမာ www.google.comα€†α€»α€•α€Έα€œα€¬α€±α€•αšα€™α€¬α€•α€«αŠ 

Link ေတြထမားၾကးေတြ α€œ viticam α€€ browser

α€™α€¬α€±α€œα€¬α€€α€›α€€α€±α€”α€α€šα€™α€‘α€„α€•α€«α€” viticam α€› α€–α€”α€ΈαŠα€€α€Όα€”α€•α€α€¬ ေတြမာ

α€žα€Όα€„α€Έα€‘α€¬α€Έα€ app ေတြ software ေတြကေန request

α€œα€•α€±α€”α€α€¬α€»α€–α€…α€•α€«α€α€šαŠ α€€α€šα€α€„α€–α€”α€Έα‚α€…α€œα€Έα€” α€…α€™α€ΈαΎα€€α€Šα€•α€« ပျပး

α€”α€¬α€Έα€œα€Šα€œα€Όα€šα€™α€¬α€•α€«αŠ

--------------------------------------------------------------------------

Page 20: zAnti Android  Wireless Pentesting  guide  ().pdf

Password Hacking…..

Gmail α€€α€₯ပမာ α€±α€•α€Έα€»α€•α€Έα€±α€»α€•α€¬α€•α€«α€™α€š α€’α€”α€Šα€Έα€œα€™α€Έα€€ Gmail α€™α€Ÿα€€α€•α€«α€˜α€Έ ၊

α€˜α€šα€œ Login Process မးကမဆ α€›α€€α€žα€Όα€„α€Έα€œα€€α€

username & password ကၾကားျဖတျပး α€›α€šα‚α€„α€™α€¬α€»α€–α€…α€•α€«α€α€š ၊

eg : Viticam α€€ www.gmail.comမာ login α€α€„α€œα€€α€•α€«α€α€šαŠ  

email α€” password α€€α€‘α€Šα€•α€«α€α€šαŠ Login α€α€„α€œα€€α€•α€«α€α€šαŠ ဒါဆ

Logged Host မာ α€’α€œα€±α€•αšα€œα€¬α€•α€«α€™α€šαŠ

ထ၀ါေရာငန α€»α€•α€‘α€¬α€Έα€•α€«α€α€š ၊ 5 request, 1 passwords ပါ

Page 21: zAnti Android  Wireless Pentesting  guide  ().pdf

 

ထ၀ါန α€»α€•α€‘α€¬α€Έα€α€¬α€€α‚α€•α€œα€€α€›α€„

username:password α€‘α€Όα€€α€œα€¬α€•α€«α€™α€šαŠ

α€±α€‘α€¬α€€α€™α€¬αΎα€€α€Šα€•α€«

Page 22: zAnti Android  Wireless Pentesting  guide  ().pdf

ထမာျမငရျပေနာ α€šα€‡α€¬α€”α€™α€Έα€€ [email protected]

ပကစ၀ကက thisispassword

ကဗာ α€˜α€šα€±α€œα€¬α€€α€œα€Όα€šα€œ

ေနာကထပ Sessions ဆတ Tab ထကေန viticam ၀ငထားတ Forum

ေတြန α€žloginα€»α€•α€Έα€žα€Έα€±α€”α€ website ထစရတာေတြက user,pass α€™α€œα€•

α€α€„αΎα€€α€Šα‚α€„α€•α€«α€α€šαŠ ကနတာကေတာ α€€α€Όα€€α€šαΎα€€α€Šα€±α€•α€«α€—α€¬

Page 23: zAnti Android  Wireless Pentesting  guide  ().pdf

Logged Image....

 

ဒါကေတာ viticam αΎα€€α€Šα€±α€”α€α€•α€±α€α€Όα€€ α€šαΎα€€α€Šα€α€¬α€±α€•α€«αŠ

α€₯ပမာ α€žα€€ website α€α€…α€αΎα€€α€Šα€±α€”α€α€šα€†α€›α€„

ထ website မာရတပေတြ α€’α€‘α€™α€¬α€±α€•αšα€œα€¬α€œα€™α€™α€šαŠ

ထာက Logged Image α€œα€•α€α€šα€±α€•α€«α€—α€¬αŠ

Page 24: zAnti Android  Wireless Pentesting  guide  ().pdf

zPacket Editor.....

α€’α€«α€€α€˜α€šα€œα€žα€Έα€œα€Šα€Έα€†α€±α€α€¬

α€žα€€α€–α€Όα€„α€‘α€¬α€Έα€™α€š ဆရင viticam α€€ www.xvideos.com

α€€ request α€œα€•α€α€šα€†α€•α€«α€… Zpacket Editor α€‘α€™α€¬α€±α€•αšα€œα€¬α€•α€«α€™α€šαŠ

α€€α€šα€€ α€α€Όα€„α€»α€•α€œα€€α€™ viticam α€˜α€€α€™α€¬

xvideos.com α€α€€α€œα€¬α€™α€¬α€•α€«αŠ

α€α€…α€α€žα€α€‘α€¬α€Έα€›α€™α€¬α€€ α€€α€šα€€ α€α€Όα€„α€œα€Šα€Έα€™α€»α€•

α€˜α€¬α€™α€œα€Šα€Έα€™α€œα€•α€˜α€Έα€†α€›α€„ viticam α€˜α€€α€™α€¬www.xvideos.comဆျပး

α€‘α€α€„α€Έα€•α€œα€Šα€±α€”α€™α€¬α€•α€« α€˜α€¬α€™α€€α€œα€¬α€™α€¬α€™α€Ÿα€€α€•α€«α€˜α€Έ

Page 25: zAnti Android  Wireless Pentesting  guide  ().pdf

SSL Stript.....

SSL Stript ကေတာ α€™α€»α€–α€…α€™α€±α€”On α€±α€•α€Έα€›α€•α€«α€™α€šαŠSSL ဆတာက Safe Secue

Layer α€€α€±α€»α€•α€¬α€α€¬α€•α€«αŠα€α€…α€”α€Šα€Έα€‘α€¬α€Έα€»α€–α€„α€†α€›α€„ https α€€α€±α€»α€•α€¬α€α€¬α€•α€«αŠ

ကၽြနေတာတ α€€ webpage α€±α€α€Όα€€αΏα€€α€Šα€α€‘α€α€«https α€” αΎα€€α€Šα€™α€šα€†α€›α€„

ေတာရတနရ αΎα€€α€¬α€»α€–α€α€›α€šα€– α€α€€α€α€±α€…α€•α€«α€α€šαŠSSL Stript α€€

On ေပးျခငးထားျဖင viticam α€˜α€€α€™α€¬ https α€€α€žα€Έα€œ မရေထာင

α€»α€•α€œα€•α€œα€€α€α€¬α€»α€–α€…α€•α€«α€α€šαŠα€’α€«α€™α€žα€¬α€œα€„α€€α½α€Όα€”α€±α€α€¬α€ ၾကားျဖတ

α€α€Έα€šαΎα€€α€Šα€œ α€›α€™α€¬α€•α€«αŠ

Page 26: zAnti Android  Wireless Pentesting  guide  ().pdf

ထစဆးဖတျပးျပဆေတာ ဖရး၀ငဖငေတြ

α€™α€α€„α€žα€„α€˜α€Έα€†α€α€¬α€žα€±α€œα€¬α€€α€»α€•α€±α€•α€«α€—α€¬

α€˜α€¬α€•α€»α€–α€…α€»α€–α€… Educational Purpose Only α€»α€–α€…α€œ α€»α€–α€…α€±α€•αšα€œα€¬α€žα€™ Risk

α€±α€α€Όα€€α€α€¬α€α€”α€™α€šα€•α€«α€±αΎα€€α€¬α€„α€Έ

Written by

puupuu@deb~lab

~

I am blogger !

www.kyawzinhein.net

α€±α€»α€™α€¬α€€α€’α€‚α€žα€¬α€Έ