{"id":17127,"date":"2021-09-29T12:52:06","date_gmt":"2021-09-29T07:22:06","guid":{"rendered":"https:\/\/www.varutra.com\/?p=17127"},"modified":"2022-12-02T12:04:06","modified_gmt":"2022-12-02T06:34:06","slug":"android-penetration-testing-with-drozer","status":"publish","type":"post","link":"https:\/\/www.varutra.com\/varutravrt3\/android-penetration-testing-with-drozer\/","title":{"rendered":"Android Penetration Testing with Drozer"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" width=\"1920\" height=\"1080\" src=\"https:\/\/varutra-1a3b6.kxcdn.com\/wp-content\/uploads\/2021\/09\/Android-Penetration-Testing-with-Drozer-1024x535.png\"  class=\"sh-overlay-item sh-table-cell ls-is-cached lazyloaded\" data-rel=\"lightcase\" title=\"Android Penetration Testing with Drozer - Varutra Consulting\"><\/p>\n<h3>Introduction to A<strong>ndroid Application Security Testing Framework &#8211; <\/strong><strong>Drozer:<\/strong><\/h3>\n<p><strong>Drozer is an android application security testing framework which is developed by FSecureLABS that makes it easy for a Pen-tester to check for potential vulnerabilities in the components of an application. It was in the past known as Mercury. It Works by playing the part of a local Android application and interfacing with the Dalvik Virtual Machine.<\/strong><\/p>\n<h3><strong>Features:<\/strong><\/h3>\n<ul>\n<li>Static Analysis<\/li>\n<li>Run time Manipulation<\/li>\n<li>Information Gathering<\/li>\n<li>Enumeration of Packages<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h3><strong>Requirements:<\/strong><\/h3>\n<ul>\n<li>7 (Modules <a href=\"https:\/\/pypi.python.org\/pypi\/protobuf\">Protobuf<\/a> 2.6 or greater, <a href=\"https:\/\/pypi.python.org\/pypi\/pyOpenSSL\">Pyopenssl<\/a> 16.2 or greater, <a href=\"https:\/\/pypi.python.org\/pypi\/Twisted\">Twisted<\/a> 10.2 or greater)<\/li>\n<li><a href=\"http:\/\/www.oracle.com\/technetwork\/java\/javase\/downloads\/java-archive-downloads-javase7-521261.html\">Java Development Kit 1.7<\/a><\/li>\n<li><a href=\"https:\/\/developer.android.com\/studio\/releases\/platform-tools.html\">Android Debug Bridge<\/a><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h3><strong>Installation:<\/strong><\/h3>\n<p>In this blog, I will illustrate the installation of Drozer in Kali Linux. It is a straightforward Installation.<\/p>\n<ol>\n<li>Go to the link- <a href=\"https:\/\/github.com\/mwrlabs\/drozer\/releases\">https:\/\/github.com\/mwrlabs\/drozer\/releases<\/a> download the drozer-2.4.4-py2-none-any.whl, navigate to the download directory and execute the command \u201cpip install drozer-2.4.4-py2-none-any.whl \u201d<\/li>\n<li>Drozer agent apk can be downloaded on the emulator or on a physical device from <a href=\"https:\/\/github.com\/mwrlabs\/drozer\/releases\/download\/2.3.4\/drozer-agent-2.3.4.apk\">https:\/\/github.com\/mwrlabs\/drozer\/releases\/download\/2.3.4\/drozer-agent-2.3.4.apk<\/a><\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<h3><strong>Android Application Testing with Drozer:<\/strong><\/h3>\n<ol>\n<li>Install the Drozer agent APK onto the device\/emulator by executing the command \u201cadb install agent.apk\u201d on a terminal.<\/li>\n<\/ol>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-17131 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/1.png\" alt=\"1\" width=\"608\" height=\"40\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/1.png 608w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/1-300x20.png 300w\" sizes=\"(max-width: 608px) 100vw, 608px\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-17130 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/1.1.png\" alt=\"1.1\" width=\"395\" height=\"371\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/1.1.png 395w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/1.1-300x282.png 300w\" sizes=\"(max-width: 395px) 100vw, 395px\" \/><\/p>\n<ol start=\"2\">\n<li>After, installing an agent on the phone click on the embedded server to turn on the server. The server will start on port 31415.<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<ol start=\"3\">\n<li>To connect drozer client running on the PC and the agent running on the emulator\/device we need to do port forward on port 31415 to make the connection between drozer client and drozer agent.<\/li>\n<\/ol>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-17132 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/3.png\" alt=\"3\" width=\"509\" height=\"32\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/3.png 509w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/3-300x19.png 300w\" sizes=\"(max-width: 509px) 100vw, 509px\" \/><\/p>\n<ol start=\"4\">\n<li>In order to run the drozer console in the terminal type command: drozer console connect<\/li>\n<\/ol>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-17133 size-full\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/4.png\" alt=\"drozer console connect\" width=\"535\" height=\"270\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/4.png 535w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/4-300x151.png 300w\" sizes=\"(max-width: 535px) 100vw, 535px\" \/><\/p>\n<ol start=\"5\">\n<li>In the drozer agent, the thread is started and the green sign indicated that both devices are connected.<\/li>\n<\/ol>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-17135 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/5.png\" alt=\"drozer agent\" width=\"388\" height=\"457\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/5.png 388w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/5-255x300.png 255w\" sizes=\"(max-width: 388px) 100vw, 388px\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-17134 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/5.1.png\" alt=\"drozer agent 1\" width=\"385\" height=\"371\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/5.1.png 385w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/5.1-300x289.png 300w\" sizes=\"(max-width: 385px) 100vw, 385px\" \/><\/p>\n<ol start=\"6\">\n<li>In the drozer console run the help command to list the commands in the drozer.<\/li>\n<\/ol>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-17136 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/6.png\" alt=\"6\" width=\"597\" height=\"230\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/6.png 597w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/6-300x116.png 300w\" sizes=\"(max-width: 597px) 100vw, 597px\" \/><\/p>\n<ol start=\"7\">\n<li>Drozer has many built-in modules. Type the list command in the drozer console to list out all the modules.<\/li>\n<\/ol>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-17137 size-full\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/7.png\" alt=\"command in the drozer console\" width=\"594\" height=\"407\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/7.png 594w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/7-300x206.png 300w\" sizes=\"(max-width: 594px) 100vw, 594px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p><strong>Information Gathering on Device:<\/strong><\/p>\n<p>Drozer has built-in modules to fetch the date and time of the device and some other information of the device also, run \u201crun information.datetime\u201d in the terminal.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-17139 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/Information-Gathering-on-Device.png\" alt=\"Information Gathering on Device\" width=\"606\" height=\"203\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/Information-Gathering-on-Device.png 606w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/Information-Gathering-on-Device-300x100.png 300w\" sizes=\"(max-width: 606px) 100vw, 606px\" \/><\/p>\n<h3><\/h3>\n<h3><strong>Information Gathering on Packages:<\/strong><\/h3>\n<ol>\n<li>To list out all the packages installed on the device run the command \u201crun app.packages.list\u201d<\/li>\n<\/ol>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-17152 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/Information-Gathering-on-Packages-1.png\" alt=\"\" width=\"608\" height=\"383\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/Information-Gathering-on-Packages-1.png 608w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/Information-Gathering-on-Packages-1-300x189.png 300w\" sizes=\"(max-width: 608px) 100vw, 608px\" \/><\/p>\n<ol start=\"2\">\n<li>To list the package of the specific application, run the command \u201crun app.package.list -f diva\u201d.<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-17141 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/run-the-command.png\" alt=\"run the command\" width=\"605\" height=\"58\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/run-the-command.png 605w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/run-the-command-300x29.png 300w\" sizes=\"(max-width: 605px) 100vw, 605px\" \/><\/p>\n<ol start=\"3\">\n<li>To view the information about the packages, run the following command run app.package.info -a jakhar.aseem.diva<\/li>\n<\/ol>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-17143 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/3-1.png\" alt=\"3\" width=\"608\" height=\"216\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/3-1.png 608w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/3-1-300x107.png 300w\" sizes=\"(max-width: 608px) 100vw, 608px\" \/><\/p>\n<p>&nbsp;<\/p>\n<h3><strong>Debuggable Packages:<\/strong><\/h3>\n<p>Run the following command to check the packages which are debuggable run app.package.debuggable.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-17144 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/Debuggable-Packages.png\" alt=\"Debuggable Packages\" width=\"612\" height=\"341\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/Debuggable-Packages.png 612w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/Debuggable-Packages-300x167.png 300w\" sizes=\"(max-width: 612px) 100vw, 612px\" \/><\/p>\n<h3><strong>Getting AndroidManifest.xml File from Drozer:<\/strong><\/h3>\n<p>Run The following command to get the androidmanifest.xml file.<\/p>\n<p>\u201crun app.package.manifestjakhar.aseem.diva\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-17148 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/Getting-AndroidManifest.xml-File-fromDrozer.png\" alt=\"Getting AndroidManifest.xml File fromDrozer\" width=\"608\" height=\"554\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/Getting-AndroidManifest.xml-File-fromDrozer.png 608w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/Getting-AndroidManifest.xml-File-fromDrozer-300x273.png 300w\" sizes=\"(max-width: 608px) 100vw, 608px\" \/><\/p>\n<h3><strong>Identifying the attack surface of the application:<\/strong><\/h3>\n<p>This feature of drozer will help us to identify the possible attack surface on the application. Android applications have mainly 4 essential components that can be exploited along with the debuggable flag. Run the following command to get the attack surface of any android application with a package name.<\/p>\n<p>\u201crun app.package.attacksurfacejakhar.aseem.diva\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-17151 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/Identifying-the-attack-surface-of-the-application.png\" alt=\"Identifying the attack surface of the application\" width=\"612\" height=\"188\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/Identifying-the-attack-surface-of-the-application.png 612w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/Identifying-the-attack-surface-of-the-application-300x92.png 300w\" sizes=\"(max-width: 612px) 100vw, 612px\" \/><\/p>\n<p><strong>Exploiting Activities:<\/strong><\/p>\n<ol>\n<li>In order to see the exported activities and information related to activities. Run the following command with the respective package name.<\/li>\n<\/ol>\n<p>\u201crun app.activity.info -a jakhar.aseem.diva\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-17145 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/Exploiting-Activities-1.png\" alt=\"Exploiting Activities 1\" width=\"616\" height=\"132\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/Exploiting-Activities-1.png 616w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/Exploiting-Activities-1-300x64.png 300w\" sizes=\"(max-width: 616px) 100vw, 616px\" \/><\/p>\n<ol start=\"2\">\n<li>Now to launch or invoke a particular activity run the following command.<\/li>\n<\/ol>\n<p>\u201crun app.activity.start \u2013component jakhar.aseem.divajakhar.aseem.diva.APICredsActivity\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-17140 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/Now-to-launch-or-invoke.png\" alt=\"Now to launch or invoke\" width=\"617\" height=\"67\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/Now-to-launch-or-invoke.png 617w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/Now-to-launch-or-invoke-300x33.png 300w\" sizes=\"(max-width: 617px) 100vw, 617px\" \/><\/p>\n<ol start=\"3\">\n<li>In the below screenshot it is shown that the activity is invoked which contains sensitive information.<\/li>\n<\/ol>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-17142 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/Vendor-API.png\" alt=\"Vendor API\" width=\"384\" height=\"449\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/Vendor-API.png 384w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/Vendor-API-257x300.png 257w\" sizes=\"(max-width: 384px) 100vw, 384px\" \/><\/p>\n<ol start=\"4\">\n<li>With the help of drozer we can also create custom intents to exploit the android components. We can use this \u201chelp app.activity.start\u201d command to get more information about the module.<\/li>\n<\/ol>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-17150 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/help-of-drozer.png\" alt=\"help of drozer\" width=\"616\" height=\"324\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/help-of-drozer.png 616w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/help-of-drozer-300x158.png 300w\" sizes=\"(max-width: 616px) 100vw, 616px\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-17149 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/help-of-drozer-2.png\" alt=\"help of drozer 2\" width=\"608\" height=\"257\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/help-of-drozer-2.png 608w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/help-of-drozer-2-300x127.png 300w\" sizes=\"(max-width: 608px) 100vw, 608px\" \/><\/p>\n<h3><\/h3>\n<h3><strong>Exploiting the exported content provider:<\/strong><\/h3>\n<ol>\n<li>To get more information about the exported content provider run the following command.<\/li>\n<\/ol>\n<p>\u201crun app.provider.info\u00a0 -a jakhar.aseem.diva\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-17147 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/Exploiting-the-exported-content-provider.png\" alt=\"Exploiting the exported content provider\" width=\"605\" height=\"162\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/Exploiting-the-exported-content-provider.png 605w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/Exploiting-the-exported-content-provider-300x80.png 300w\" sizes=\"(max-width: 605px) 100vw, 605px\" \/><\/p>\n<ol start=\"2\">\n<li>To fetch the data from the application\u2019s content provider. Use the drozer scanner module \u201c\u201crun scanner.provider.finduris\u201d which gives the accessible URI\u2019s.<\/li>\n<\/ol>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-17154 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/2.png\" alt=\"2\" width=\"608\" height=\"198\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/2.png 608w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/2-300x98.png 300w\" sizes=\"(max-width: 608px) 100vw, 608px\" \/><\/p>\n<ol start=\"3\">\n<li>To query the URI\u2019 from the content provider run the following command \u201crun app.provider.query\u201d with the accessible query.<\/li>\n<\/ol>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-17156 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/3-2.png\" alt=\"3\" width=\"608\" height=\"162\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/3-2.png 608w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/3-2-300x80.png 300w\" sizes=\"(max-width: 608px) 100vw, 608px\" \/><\/p>\n<ol start=\"4\">\n<li>We can also use drozer to scan for SQL injection in content provider using the scanner module for injection scanner.provider.injection as shown in the below screenshot.<\/li>\n<\/ol>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-17157 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/4-1.png\" alt=\"4\" width=\"606\" height=\"216\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/4-1.png 606w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/4-1-300x107.png 300w\" sizes=\"(max-width: 606px) 100vw, 606px\" \/><\/p>\n<ol start=\"5\">\n<li>To exploit this vulnerability, we can use the following command.<\/li>\n<\/ol>\n<p>\u201crun app.provider.query\u201d with the content URI as shown in the below screenshot.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-17158 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/5.1-1.png\" alt=\"5.1\" width=\"608\" height=\"39\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/5.1-1.png 608w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/5.1-1-300x19.png 300w\" sizes=\"(max-width: 608px) 100vw, 608px\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-17159 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/5.2.png\" alt=\"5.2\" width=\"608\" height=\"122\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/5.2.png 608w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/5.2-300x60.png 300w\" sizes=\"(max-width: 608px) 100vw, 608px\" \/><\/p>\n<ol start=\"6\">\n<li>Now to extract the data from the table we can use the same module with content URI and the SQL query as shown in the below screenshot.<\/li>\n<\/ol>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-17155 aligncenter\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/6-1.png\" alt=\"6\" width=\"608\" height=\"156\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/6-1.png 608w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/6-1-300x77.png 300w\" sizes=\"(max-width: 608px) 100vw, 608px\" \/><\/p>\n<h3><strong>Conclusion:<\/strong><\/h3>\n<p>In this blog, we looked at various use cases of drozer framework and how drozer can help in android vulnerability assessment and various attacks that pose serious security issues to the applications. We explored the attack surface on the application, exploited exported components of the application and performed <a href=\"https:\/\/www.varutra.com\/second-order-sql-injection-attack\/\">SQL injection<\/a>, etc. Thanks for reading.<\/p>\n<p>&nbsp;<\/p>\n<p>Author,<\/p>\n<p><strong>Piyush Sonkushre<\/strong><\/p>\n<p>Attack &amp; Pentest Team<\/p>\n<p>Varutra Consulting Pvt.Ltd.<\/p>","protected":false},"excerpt":{"rendered":"<p>Introduction to Android Application Security Testing Framework &#8211; Drozer: Drozer is an android application security testing framework which is developed by FSecureLABS that makes it&#8230;<\/p>\n","protected":false},"author":4,"featured_media":17162,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"inline_featured_image":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[51],"tags":[507,453,450,452,355],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO Pro 4.9.8 - aioseo.com -->\n\t<meta name=\"description\" content=\"Drozer is developed by FSecureLABS which is android application security testing framework used to check for vulnerabilities in Android applications.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"kalpblogger\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.varutra.com\/varutravrt3\/android-penetration-testing-with-drozer\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO Pro (AIOSEO) 4.9.8\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Varutra Consulting\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Drozer Framework For Android Application Security Testing\" \/>\n\t\t<meta property=\"og:description\" content=\"Drozer is developed by FSecureLABS which is android application security testing framework used to check for vulnerabilities in Android applications.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.varutra.com\/varutravrt3\/android-penetration-testing-with-drozer\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/Android-Penetration-Testing-with-Drozer.png\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/Android-Penetration-Testing-with-Drozer.png\" \/>\n\t\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t\t<meta property=\"og:image:height\" content=\"627\" \/>\n\t\t<meta property=\"article:section\" content=\"Android Security\" \/>\n\t\t<meta property=\"article:tag\" content=\"andoid application security\" \/>\n\t\t<meta property=\"article:tag\" content=\"android penetration testing\" \/>\n\t\t<meta property=\"article:tag\" content=\"android security\" \/>\n\t\t<meta property=\"article:tag\" content=\"drozer\" \/>\n\t\t<meta property=\"article:tag\" content=\"pentesting\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2021-09-29T07:22:06+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2022-12-02T06:34:06+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Drozer Framework For Android Application Security Testing\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Drozer is developed by FSecureLABS which is android application security testing framework used to check for vulnerabilities in Android applications.\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/Android-Penetration-Testing-with-Drozer.png\" \/>\n\t\t<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t\t<meta name=\"twitter:data1\" content=\"kalpblogger\" \/>\n\t\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/android-penetration-testing-with-drozer\\\/#article\",\"name\":\"Drozer Framework For Android Application Security Testing\",\"headline\":\"Android Penetration Testing with Drozer\",\"author\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/kalpblogger\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/wp-content\\\/uploads\\\/2021\\\/09\\\/Android-Penetration-Testing-with-Drozer.png\",\"width\":1200,\"height\":627,\"caption\":\"Android Penetration Testing with Drozer\"},\"datePublished\":\"2021-09-29T12:52:06+05:30\",\"dateModified\":\"2022-12-02T12:04:06+05:30\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/android-penetration-testing-with-drozer\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/android-penetration-testing-with-drozer\\\/#webpage\"},\"articleSection\":\"Android Security, Andoid Application Security, android penetration testing, android security, drozer, pentesting\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/android-penetration-testing-with-drozer\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/category\\\/android-security\\\/#listItem\",\"name\":\"Android Security\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/category\\\/android-security\\\/#listItem\",\"position\":2,\"name\":\"Android Security\",\"item\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/category\\\/android-security\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/android-penetration-testing-with-drozer\\\/#listItem\",\"name\":\"Android Penetration Testing with Drozer\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/android-penetration-testing-with-drozer\\\/#listItem\",\"position\":3,\"name\":\"Android Penetration Testing with Drozer\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/category\\\/android-security\\\/#listItem\",\"name\":\"Android Security\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#organization\",\"name\":\"Varutra\",\"description\":\"Secure your digital world with our Cybersecurity services.\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/wp-content\\\/uploads\\\/2021\\\/11\\\/Varutra-Found-e1612984024606.jpg\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/android-penetration-testing-with-drozer\\\/#organizationLogo\"},\"image\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/android-penetration-testing-with-drozer\\\/#organizationLogo\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/kalpblogger\\\/#author\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/kalpblogger\\\/\",\"name\":\"kalpblogger\",\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/5e96a9b330da7c941c1e39217a2fbe38?s=96&d=mm&r=g\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/android-penetration-testing-with-drozer\\\/#webpage\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/android-penetration-testing-with-drozer\\\/\",\"name\":\"Drozer Framework For Android Application Security Testing\",\"description\":\"Drozer is developed by FSecureLABS which is android application security testing framework used to check for vulnerabilities in Android applications.\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/android-penetration-testing-with-drozer\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/kalpblogger\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/kalpblogger\\\/#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/wp-content\\\/uploads\\\/2021\\\/09\\\/Android-Penetration-Testing-with-Drozer.png\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/android-penetration-testing-with-drozer\\\/#mainImage\",\"width\":1200,\"height\":627,\"caption\":\"Android Penetration Testing with Drozer\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/android-penetration-testing-with-drozer\\\/#mainImage\"},\"datePublished\":\"2021-09-29T12:52:06+05:30\",\"dateModified\":\"2022-12-02T12:04:06+05:30\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#website\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/\",\"name\":\"Varutra Consulting\",\"description\":\"Secure your digital world with our Cybersecurity services.\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO Pro -->\r\n\t\t<title>Drozer Framework For Android Application Security Testing<\/title>\n\n","aioseo_head_json":{"title":"Drozer Framework For Android Application Security Testing","description":"Drozer is developed by FSecureLABS which is android application security testing framework used to check for vulnerabilities in Android applications.","canonical_url":"https:\/\/www.varutra.com\/varutravrt3\/android-penetration-testing-with-drozer\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.varutra.com\/varutravrt3\/android-penetration-testing-with-drozer\/#article","name":"Drozer Framework For Android Application Security Testing","headline":"Android Penetration Testing with Drozer","author":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/author\/kalpblogger\/#author"},"publisher":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/Android-Penetration-Testing-with-Drozer.png","width":1200,"height":627,"caption":"Android Penetration Testing with Drozer"},"datePublished":"2021-09-29T12:52:06+05:30","dateModified":"2022-12-02T12:04:06+05:30","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/android-penetration-testing-with-drozer\/#webpage"},"isPartOf":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/android-penetration-testing-with-drozer\/#webpage"},"articleSection":"Android Security, Andoid Application Security, android penetration testing, android security, drozer, pentesting"},{"@type":"BreadcrumbList","@id":"https:\/\/www.varutra.com\/varutravrt3\/android-penetration-testing-with-drozer\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3#listItem","position":1,"name":"Home","item":"https:\/\/www.varutra.com\/varutravrt3","nextItem":{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3\/category\/android-security\/#listItem","name":"Android Security"}},{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3\/category\/android-security\/#listItem","position":2,"name":"Android Security","item":"https:\/\/www.varutra.com\/varutravrt3\/category\/android-security\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3\/android-penetration-testing-with-drozer\/#listItem","name":"Android Penetration Testing with Drozer"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3\/android-penetration-testing-with-drozer\/#listItem","position":3,"name":"Android Penetration Testing with Drozer","previousItem":{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3\/category\/android-security\/#listItem","name":"Android Security"}}]},{"@type":"Organization","@id":"https:\/\/www.varutra.com\/varutravrt3\/#organization","name":"Varutra","description":"Secure your digital world with our Cybersecurity services.","url":"https:\/\/www.varutra.com\/varutravrt3\/","logo":{"@type":"ImageObject","url":"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/11\/Varutra-Found-e1612984024606.jpg","@id":"https:\/\/www.varutra.com\/varutravrt3\/android-penetration-testing-with-drozer\/#organizationLogo"},"image":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/android-penetration-testing-with-drozer\/#organizationLogo"}},{"@type":"Person","@id":"https:\/\/www.varutra.com\/varutravrt3\/author\/kalpblogger\/#author","url":"https:\/\/www.varutra.com\/varutravrt3\/author\/kalpblogger\/","name":"kalpblogger","image":{"@type":"ImageObject","url":"https:\/\/secure.gravatar.com\/avatar\/5e96a9b330da7c941c1e39217a2fbe38?s=96&d=mm&r=g"}},{"@type":"WebPage","@id":"https:\/\/www.varutra.com\/varutravrt3\/android-penetration-testing-with-drozer\/#webpage","url":"https:\/\/www.varutra.com\/varutravrt3\/android-penetration-testing-with-drozer\/","name":"Drozer Framework For Android Application Security Testing","description":"Drozer is developed by FSecureLABS which is android application security testing framework used to check for vulnerabilities in Android applications.","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/#website"},"breadcrumb":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/android-penetration-testing-with-drozer\/#breadcrumblist"},"author":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/author\/kalpblogger\/#author"},"creator":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/author\/kalpblogger\/#author"},"image":{"@type":"ImageObject","url":"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2021\/09\/Android-Penetration-Testing-with-Drozer.png","@id":"https:\/\/www.varutra.com\/varutravrt3\/android-penetration-testing-with-drozer\/#mainImage","width":1200,"height":627,"caption":"Android Penetration Testing with Drozer"},"primaryImageOfPage":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/android-penetration-testing-with-drozer\/#mainImage"},"datePublished":"2021-09-29T12:52:06+05:30","dateModified":"2022-12-02T12:04:06+05:30"},{"@type":"WebSite","@id":"https:\/\/www.varutra.com\/varutravrt3\/#website","url":"https:\/\/www.varutra.com\/varutravrt3\/","name":"Varutra Consulting","description":"Secure your digital world with our Cybersecurity services.","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/#organization"}}]},"og:locale":"en_US","og:site_name":"Varutra Consulting","og:type":"article","og:title":"Drozer Framework For Android Application Security Testing","og:description":"Drozer is developed by FSecureLABS which is android application security testing framework used to check for vulnerabilities in Android applications.","og:url":"https:\/\/www.varutra.com\/varutravrt3\/android-penetration-testing-with-drozer\/","og:image":"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/Android-Penetration-Testing-with-Drozer.png","og:image:secure_url":"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/Android-Penetration-Testing-with-Drozer.png","og:image:width":"1200","og:image:height":"627","article:section":"Android Security","article:tag":["andoid application security","android penetration testing","android security","drozer","pentesting"],"article:published_time":"2021-09-29T07:22:06+00:00","article:modified_time":"2022-12-02T06:34:06+00:00","twitter:card":"summary_large_image","twitter:title":"Drozer Framework For Android Application Security Testing","twitter:description":"Drozer is developed by FSecureLABS which is android application security testing framework used to check for vulnerabilities in Android applications.","twitter:image":"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/Android-Penetration-Testing-with-Drozer.png","twitter:label1":"Written by","twitter:data1":"kalpblogger","twitter:label2":"Est. reading time","twitter:data2":"4 minutes"},"aioseo_meta_data":{"post_id":"17127","title":"Drozer Framework For Android Application Security Testing&nbsp;","description":"Drozer is developed by FSecureLABS which is android application security testing framework used to check for vulnerabilities in Android applications.","keywords":[],"keyphrases":{"focus":{"keyphrase":"Drozer","analysis":{"keyphraseInTitle":{"title":"Focus keyphrase in SEO title","description":"Focus keyphrase found in SEO title.","score":9,"maxScore":9,"error":0},"keyphraseInDescription":{"title":"Focus keyphrase in meta description","description":"Focus keyphrase found in meta description.","score":9,"maxScore":9,"error":0},"keyphraseLength":{"title":"Focus keyphrase length","description":"Good job!","score":9,"maxScore":9,"error":0,"length":1},"keyphraseInURL":{"title":"Focus keyphrase in URL","description":"Focus keyphrase used in the URL.","score":5,"maxScore":5,"error":0},"keyphraseInIntroduction":{"title":"Focus keyphrase in introduction","description":"Your Focus keyphrase does not appear in the first paragraph. Make sure the topic is clear immediately.","score":3,"maxScore":9,"error":1},"keyphraseInSubHeadings":{"title":"Focus keyphrase in Subheadings","description":"Use more focus keyphrases in your H2 and H3 subheadings!","score":3,"maxScore":9,"error":1},"keyphraseInImageAlt":{"title":"Focus keyphrase in image alt attributes","description":"Focus keyphrase found in image alt attribute(s).","score":9,"maxScore":9,"error":0}},"score":80},"additional":[{"keyphrase":"Android Application Security Testing","score":67,"analysis":{"keyphraseInDescription":{"title":"Keyphrase in meta description","description":"Keyphrase found in meta description.","score":9,"maxScore":9,"error":0},"keyphraseLength":{"title":"Keyphrase length","description":"Good job!","score":9,"maxScore":9,"error":0,"length":4},"keyphraseInIntroduction":{"title":"Keyphrase in introduction","description":"Your Keyphrase does not appear in the first paragraph. Make sure the topic is clear immediately.","score":3,"maxScore":9,"error":1},"keyphraseInImageAlt":{"title":"Keyphrase in image alt attributes","description":"Keyphrase not found in image alt attribute(s). Add an image with your Keyphrase as alt text.","score":3,"maxScore":9,"error":1}}},{"keyphrase":"Android Application Security","score":67,"analysis":{"keyphraseInDescription":{"title":"Keyphrase in meta description","description":"Keyphrase found in meta description.","score":9,"maxScore":9,"error":0},"keyphraseLength":{"title":"Keyphrase length","description":"Good job!","score":9,"maxScore":9,"error":0,"length":3},"keyphraseInIntroduction":{"title":"Keyphrase in introduction","description":"Your Keyphrase does not appear in the first paragraph. Make sure the topic is clear immediately.","score":3,"maxScore":9,"error":1},"keyphraseInImageAlt":{"title":"Keyphrase in image alt attributes","description":"Keyphrase not found in image alt attribute(s). Add an image with your Keyphrase as alt text.","score":3,"maxScore":9,"error":1}}},{"keyphrase":"Application Security Testing","score":67,"analysis":{"keyphraseInDescription":{"title":"Keyphrase in meta description","description":"Keyphrase found in meta description.","score":9,"maxScore":9,"error":0},"keyphraseLength":{"title":"Keyphrase length","description":"Good job!","score":9,"maxScore":9,"error":0,"length":3},"keyphraseInIntroduction":{"title":"Keyphrase in introduction","description":"Your Keyphrase does not appear in the first paragraph. Make sure the topic is clear immediately.","score":3,"maxScore":9,"error":1},"keyphraseInImageAlt":{"title":"Keyphrase in image alt attributes","description":"Keyphrase not found in image alt attribute(s). Add an image with your Keyphrase as alt text.","score":3,"maxScore":9,"error":1}}},{"keyphrase":"Application Security Testing Framework","score":67,"analysis":{"keyphraseInDescription":{"title":"Keyphrase in meta description","description":"Keyphrase found in meta description.","score":9,"maxScore":9,"error":0},"keyphraseLength":{"title":"Keyphrase length","description":"Good job!","score":9,"maxScore":9,"error":0,"length":4},"keyphraseInIntroduction":{"title":"Keyphrase in introduction","description":"Your Keyphrase does not appear in the first paragraph. Make sure the topic is clear immediately.","score":3,"maxScore":9,"error":1},"keyphraseInImageAlt":{"title":"Keyphrase in image alt attributes","description":"Keyphrase not found in image alt attribute(s). Add an image with your Keyphrase as alt text.","score":3,"maxScore":9,"error":1}}},{"keyphrase":"Security Testing","score":67,"analysis":{"keyphraseInDescription":{"title":"Keyphrase in meta description","description":"Keyphrase found in meta description.","score":9,"maxScore":9,"error":0},"keyphraseLength":{"title":"Keyphrase length","description":"Good job!","score":9,"maxScore":9,"error":0,"length":2},"keyphraseInIntroduction":{"title":"Keyphrase in introduction","description":"Your Keyphrase does not appear in the first paragraph. Make sure the topic is clear immediately.","score":3,"maxScore":9,"error":1},"keyphraseInImageAlt":{"title":"Keyphrase in image alt attributes","description":"Keyphrase not found in image alt attribute(s). Add an image with your Keyphrase as alt text.","score":3,"maxScore":9,"error":1}}},{"keyphrase":"Security Testing Framework","score":67,"analysis":{"keyphraseInDescription":{"title":"Keyphrase in meta description","description":"Keyphrase found in meta description.","score":9,"maxScore":9,"error":0},"keyphraseLength":{"title":"Keyphrase length","description":"Good job!","score":9,"maxScore":9,"error":0,"length":3},"keyphraseInIntroduction":{"title":"Keyphrase in introduction","description":"Your Keyphrase does not appear in the first paragraph. Make sure the topic is clear immediately.","score":3,"maxScore":9,"error":1},"keyphraseInImageAlt":{"title":"Keyphrase in image alt attributes","description":"Keyphrase not found in image alt attribute(s). Add an image with your Keyphrase as alt text.","score":3,"maxScore":9,"error":1}}}]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"featured","og_image_url":"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/09\/Android-Penetration-Testing-with-Drozer.png","og_image_width":"1200","og_image_height":"627","og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":"Android Security","og_article_tags":[],"twitter_use_og":true,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":"{\"article\":{\"articleType\":\"BlogPosting\"},\"course\":{\"name\":\"\",\"description\":\"\",\"provider\":\"\"},\"faq\":{\"pages\":[]},\"product\":{\"reviews\":[]},\"recipe\":{\"ingredients\":[],\"instructions\":[],\"keywords\":[]},\"software\":{\"reviews\":[],\"operatingSystems\":[]},\"webPage\":{\"webPageType\":\"WebPage\"}}","pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"limit_modified_date":false,"reviewed_by":null,"open_ai":null,"created":"2021-10-27 15:10:53","updated":"2026-05-24 09:58:48","ai":null,"breadcrumb_settings":null,"seo_analyzer_scan_date":"2026-05-22 13:12:05"},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.varutra.com\/varutravrt3\" title=\"Home\">Home<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.varutra.com\/varutravrt3\/category\/android-security\/\" title=\"Android Security\">Android Security<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\tAndroid Penetration Testing with Drozer\n<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/www.varutra.com\/varutravrt3"},{"label":"Android Security","link":"https:\/\/www.varutra.com\/varutravrt3\/category\/android-security\/"},{"label":"Android Penetration Testing with Drozer","link":"https:\/\/www.varutra.com\/varutravrt3\/android-penetration-testing-with-drozer\/"}],"post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/posts\/17127"}],"collection":[{"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/comments?post=17127"}],"version-history":[{"count":5,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/posts\/17127\/revisions"}],"predecessor-version":[{"id":20244,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/posts\/17127\/revisions\/20244"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/media\/17162"}],"wp:attachment":[{"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/media?parent=17127"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/categories?post=17127"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/tags?post=17127"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}