A Bash wrapper for radamsa that can be used to fuzz exported activities and deep links.
-
radamsa https://gitlab.com/akihe/radamsa
-
Android Debug Bridge https://developer.android.com/studio/command-line/adb
-
The AndroidManifest.xml file from the target application. I provided a test AndroidManifest.xml from InjuredAndroid
-
A device connected to Android Debug Bridge
I kept this super simple for now.
For deeplinks
./deeplink-fuzz.sh deeplinks
or
bash deeplink-fuzz.sh deeplinks
For activities
./deeplink-fuzz.sh activities
or
bash deeplink-fuzz.sh activities
F.A.Q
Do I need to use the 💩 emoji to generate fuzzing data?
No this is a joke from a local CTF event called Bad Santa Hacking Adventure. :)