Skip to content

Identifies vulnerabilities in network_security_config.xml, AndroidManifest.xml and if Firebase URL are accessible publicly

Notifications You must be signed in to change notification settings

satishpatnayak/ScanAndroidXML

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

7 Commits
 
 
 
 
 
 
 
 
 
 

Repository files navigation

ScanAndroidXML

This tool analyzes Android app to find vulnerabilities in

  1. AndroidManifest.xml
  2. network_security_config.xml
  3. Firebase URLs from strings.xml.

This tool also shows Deeplinks used in Android app.

JDK and Python3 are required.

How to Install:
cd ScanAndroidXML
pip install -r requirements.txt

How to Run:
Move apk file into SacnAndroidXML directory python ScanAndroidXml.py <apk file>

This will print the results in terminal and generate results in html file.

Sample Results:
Results

https://twitter.com/satish_patnayak

About

Identifies vulnerabilities in network_security_config.xml, AndroidManifest.xml and if Firebase URL are accessible publicly

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages