Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ApkAnalyser运行问题和可能的漏洞 #12

Closed
Cl0udG0d opened this issue Dec 1, 2023 · 2 comments
Closed

ApkAnalyser运行问题和可能的漏洞 #12

Cl0udG0d opened this issue Dec 1, 2023 · 2 comments

Comments

@Cl0udG0d
Copy link

Cl0udG0d commented Dec 1, 2023

作者大大 问题如下

Q1

apkutils新版本已经不支持初始化的时候传入apkpath
image

https://github.com/kin9-0rz/apkutils/blob/master/apkutils/apk.py

image

我把版本降到 0.10.1 才可以运行 ,建议添加 requirements.txt

@Cl0udG0d
Copy link
Author

Cl0udG0d commented Dec 1, 2023

Q2

可能是灯下黑,在验证APK文件名的时候没有校验,可能会导致命令执行,合并到其他扫描工具里面做扫描的时候就会出现问题

image

我这里用的easyroot.apk,更新文件名为 source && whoami &&.apk

使用

python test.py "source && whoami &&.apk"

(这里的python文件我本地文件名改成了test.py,因为一开始没运行起来

image

@TheKingOfDuck
Copy link
Owner

Q1: 自己改下不就完了,这脚本我学生时代写完就用过一次,之后再没用过,现在看它写的像坨💩一样。
Q2:多少有点蛋疼,emmmm,怎么说呢,就这垃圾脚本还集成到别的项目里面去?我自己都不用。。。所以就这管他叫漏洞我是很无语的,建议多挖点有意义的洞,少关注这种有的没的。

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants