You are on page 1of 2

Platform Interaction

PLATFORM-
Static :
1. Android permission : Check permissions to make sure that the app really needs them
and remove unnecessary permissions.
a. Cek Android.Manifest.xml bagian uses:permission

b. Cek aapt d permissions

c. adb shell dumpsys package sg.vp.owasp_mobile.omtg_android | grep


permission

d. List permission yang dangerous :


READ_CALENDAR
WRITE_CALENDAR
READ_CALL_LOG
WRITE_CALL_LOG
PROCESS_OUTGOING_CALLS
CAMERA
READ_CONTACTS
WRITE_CONTACTS
GET_ACCOUNTS
ACCESS_FINE_LOCATION
ACCESS_COARSE_LOCATION
RECORD_AUDIO
READ_PHONE_STATE
READ_PHONE_NUMBERS
CALL_PHONE
ANSWER_PHONE_CALLS
ADD_VOICEMAIL
USE_SIP
BODY_SENSORS
SEND_SMS
RECEIVE_SMS
READ_SMS
RECEIVE_WAP_PUSH
RECEIVE_MMS
READ_EXTERNAL_STORAGE
WRITE_EXTERNAL_STORAGE

Dynamic :
1. Drozer : run app.package.info -a packagename

You might also like