Login Register






How to hack iPhones, Blackberrys, & Androids. filter_list
Author
Message
How to hack iPhones, Blackberrys, & Androids. #1
Hacking iPhone, Blackberry, or Android!


Using the smartphone-pentest-framework for Backtrack.

I am not the founder of this hack. For more help with this, PM me, or visit the links below!

Youtube (Video)
Bulbsecurity (Text)

Not sure what this does, or how it works?
Works a lot like your regular RAT. You configure an Xampp server on your computer and as soon as someone installs your app you can control them from your own device. You read all their messages, & even gain shell access! Cool right? Ready to learn how?


Lets get started

Here's what you'll need:
Quote:Backtrack 5 r3 (using backtrack for this example as SPF is pre-installed)
Portforwarding (if you are using this outside of your own network)
Xampp for linux (guide to installing this will be in the tutorial)
A phone (for this example I will be using my Android Phone)

*NOTE: I am writing this tutorial specifically for Android, it is very similar to Blackberry & iPhone. If you need help, just PM me.(:

Install Xaamp.

Open up a terminal window and type:
Code:
wget http://www.apachefriends.org/download.php?xampp-linux-1.7.3a.tar.gz

Once xampp has finished downloading, go to your home directory and you should have a file called "download.php?xampp-linux-1.7.3a.tar.gz" rename it to something like "xampp.tar.gz".

After you rename the file, open a new terminal window & run the following command:
Code:
tar xvfz xampp.tar.gz -C /opt

Now, I'll assume you have all have basic Linux knowledge, so Xaamp should now be installed. Now to configure it.

Configuring Xaamp.

Use terminal commands:
Code:
/opt/lampp/lampp start
&
Code:
/opt/lampp/lampp stop
to start and stop Xaamp. I am hoping you know which does which. Tongue

Once Xampp is started, head to "localhost" in the browser of your choice and select your language. Now navigate to "Phpmyadmin" and create a new database called "framework".

Next add a new user by going to the "privileges" tab then "add a new user" Use whatever username and password you want and select "local" from the hosts list.
Make sure you "Check All" global privileges, then click go.

Now delete the htdocs folder in "/opt/lampp/"

Configuring SPF files.

First, find your spf configuration file. The destination is quoted below;
Quote:/pentest/exploits/smartphone-pentest-framework/frameworkconsole/config

Now we need to replace some information. Follow the guide below:
Code:
#IPADDRESS FOR WEBSERVER - Your local/public ip. #IP ADDRESS TO LISTEN ON FOR SHELLS - Your local/public ip. #IP ADDRESS OF SQLSERVER 127.0.0.1 IF LOCALHOST - Change to 127.0.0.1 #USERNAME OF THE MYSQL USER TO USE - The username you made in phpmyadmin #PASSWORD OF THE MYSQL USER TO USE - The password of the user you set

Configuring SPF:
Open up the smartphone-pentest-framework window by going to applications>backtrack>exploitation tools>wireless exploitation tools>gsm exploitation>Smartphone-pentest-framework
Select option 4 then select option 2.

Input your phone number, then input a 7 digit control key to connect to your victims and then enter the path you want your app to located on your webserver (I will be using /). Now don't expect anything to happen just yet, you need to configure your phone with SPF.

Locate the file;
Quote:/pentest/exploits/smartphone-pentest-framework/FrameworkAndroidApp/bin/FrameworkAndroidApp.apk
and move it over to your phone by uploading it to dropbox or just connecting your phone to your computer.
Install it then open it up. Put in the details you filled out a moment ago in SPF and your IP the web-server is setup on and press setup.

Attacking your victims(Mwahahahahaha):

Open up smartphone-pentest-framework and select option 6 then pick between the direct download (Sends a text to the victim from your mobile number with a download link) or client side shell (uses a browser exploit in android phones to give you shell access).

If you select option 1 you must move the file
Quote:/pentest/exploits/smartphone-pentest-framework/AndroidAgent/bin/AndroidAgent.apk
To your root directory.

Once you get a victim, just open up smartphone-pentest-framework again, select option 1, fill in the details and you can then control the victim from your mobile phone.


Congratulations! You're now a mobile hacker! (: This is a great skill to know if you're a PI, or just need to spy on someone. Also great for mobile marketing!

If anyone needs help with this, feel free to PM me or email me!

Say "Thanks" if you liked this tutorial. (:

Reply

How to hack iPhones, Blackberrys, & Androids. #2
Hacking iPhone, Blackberry, or Android!


Using the smartphone-pentest-framework for Backtrack.

I am not the founder of this hack. For more help with this, PM me, or visit the links below!

Youtube (Video)
Bulbsecurity (Text)

Not sure what this does, or how it works?
Works a lot like your regular RAT. You configure an Xampp server on your computer and as soon as someone installs your app you can control them from your own device. You read all their messages, & even gain shell access! Cool right? Ready to learn how?


Lets get started

Here's what you'll need:
Quote:Backtrack 5 r3 (using backtrack for this example as SPF is pre-installed)
Portforwarding (if you are using this outside of your own network)
Xampp for linux (guide to installing this will be in the tutorial)
A phone (for this example I will be using my Android Phone)

*NOTE: I am writing this tutorial specifically for Android, it is very similar to Blackberry & iPhone. If you need help, just PM me.(:

Install Xaamp.

Open up a terminal window and type:
Code:
wget http://www.apachefriends.org/download.php?xampp-linux-1.7.3a.tar.gz

Once xampp has finished downloading, go to your home directory and you should have a file called "download.php?xampp-linux-1.7.3a.tar.gz" rename it to something like "xampp.tar.gz".

After you rename the file, open a new terminal window & run the following command:
Code:
tar xvfz xampp.tar.gz -C /opt

Now, I'll assume you have all have basic Linux knowledge, so Xaamp should now be installed. Now to configure it.

Configuring Xaamp.

Use terminal commands:
Code:
/opt/lampp/lampp start
&
Code:
/opt/lampp/lampp stop
to start and stop Xaamp. I am hoping you know which does which. Tongue

Once Xampp is started, head to "localhost" in the browser of your choice and select your language. Now navigate to "Phpmyadmin" and create a new database called "framework".

Next add a new user by going to the "privileges" tab then "add a new user" Use whatever username and password you want and select "local" from the hosts list.
Make sure you "Check All" global privileges, then click go.

Now delete the htdocs folder in "/opt/lampp/"

Configuring SPF files.

First, find your spf configuration file. The destination is quoted below;
Quote:/pentest/exploits/smartphone-pentest-framework/frameworkconsole/config

Now we need to replace some information. Follow the guide below:
Code:
#IPADDRESS FOR WEBSERVER - Your local/public ip. #IP ADDRESS TO LISTEN ON FOR SHELLS - Your local/public ip. #IP ADDRESS OF SQLSERVER 127.0.0.1 IF LOCALHOST - Change to 127.0.0.1 #USERNAME OF THE MYSQL USER TO USE - The username you made in phpmyadmin #PASSWORD OF THE MYSQL USER TO USE - The password of the user you set

Configuring SPF:
Open up the smartphone-pentest-framework window by going to applications>backtrack>exploitation tools>wireless exploitation tools>gsm exploitation>Smartphone-pentest-framework
Select option 4 then select option 2.

Input your phone number, then input a 7 digit control key to connect to your victims and then enter the path you want your app to located on your webserver (I will be using /). Now don't expect anything to happen just yet, you need to configure your phone with SPF.

Locate the file;
Quote:/pentest/exploits/smartphone-pentest-framework/FrameworkAndroidApp/bin/FrameworkAndroidApp.apk
and move it over to your phone by uploading it to dropbox or just connecting your phone to your computer.
Install it then open it up. Put in the details you filled out a moment ago in SPF and your IP the web-server is setup on and press setup.

Attacking your victims(Mwahahahahaha):

Open up smartphone-pentest-framework and select option 6 then pick between the direct download (Sends a text to the victim from your mobile number with a download link) or client side shell (uses a browser exploit in android phones to give you shell access).

If you select option 1 you must move the file
Quote:/pentest/exploits/smartphone-pentest-framework/AndroidAgent/bin/AndroidAgent.apk
To your root directory.

Once you get a victim, just open up smartphone-pentest-framework again, select option 1, fill in the details and you can then control the victim from your mobile phone.


Congratulations! You're now a mobile hacker! (: This is a great skill to know if you're a PI, or just need to spy on someone. Also great for mobile marketing!

If anyone needs help with this, feel free to PM me or email me!

Say "Thanks" if you liked this tutorial. (:

Reply

RE: How to hack iPhones, Blackberrys, & Androids. #3
thanks u are a genius

Reply

RE: How to hack iPhones, Blackberrys, & Androids. #4
This will be diffecult with Jailbroken iPhones.

Just because if the default root# & root mobile passwords have been changed by user.
If you have an Jailbroken iDevice in your network with default unchanged password "alpine" you don't even have to do a pentenst.
Search your network for the target iDevice SSH into the device use "alpine" as password and you have root acces to the device.

BTW: most jailbreakers don't even change their password Smile

Reply

RE: How to hack iPhones, Blackberrys, & Androids. #5
may perform work but if you have little knowledge about this, but it is a good method.

Reply

RE: How to hack iPhones, Blackberrys, & Androids. #6
thats awsome

Reply

RE: How to hack iPhones, Blackberrys, & Androids. #7
Thanks man exactly what I've looked for! But I haven't understood why I need a android phone.. Do I need it just for sending the download-link to my victim?

Reply