移动端渗透测试
io.github.SnailSploit/Claude-Red/offensive-mobile
移动(Android + iOS)应用渗透测试方法论。涵盖静态分析(Android 用 apktool/jadx,iOS 用 class-dump/Hopper/IDA)、Frida 与 Objection 动态插桩、SSL pinning 绕过策略、root/越狱检测绕过、deep-link / URL scheme 滥用、导出组件攻击(Android 的 activity、service、provider、receiver;iOS 的 XPC、URL scheme、universal link)、不安全数据存储(SharedPrefs、KeyStore 误用、NSUserDefaults、Keychain ACL 绕过)、IPC / Intent 重定向、WebView 漏洞(JavaScriptInterface、file:// 访问)、Firebase/AWS/Azure 配置错误泄露、移动端 API 测试、生物识别/Face ID/Touch ID 绕过、应用克隆与运行时打补丁,以及移动恶意软件/RAT 分析基础能力。用于移动端渗透、漏洞赏金移动方向排查或应用商店侦察。