AVD - Android ๊ฐ€์ƒ ๋””๋ฐ”์ด์Šค

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ

์ด ์ฝ˜ํ…์ธ  ์ž‘์„ฑ์— ๋„์›€์„ ์ฃผ์‹  @offsecjay๊ป˜ ์ง„์‹ฌ์œผ๋กœ ๊ฐ์‚ฌ๋“œ๋ฆฝ๋‹ˆ๋‹ค.

AVD๋ž€

Android Studio๋Š” APK๋ฅผ ํ…Œ์ŠคํŠธํ•˜๋Š” ๋ฐ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋Š” Android ๊ฐ€์ƒ ๋จธ์‹ ์„ ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ๊ฒŒ ํ•ด์ค๋‹ˆ๋‹ค. ์ด๋ฅผ ์‚ฌ์šฉํ•˜๋ ค๋ฉด ๋‹ค์Œ์ด ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค:

Windows์—์„œ๋Š”(์ œ ๊ฒฝ์šฐ) Android Studio๋ฅผ ์„ค์น˜ํ•œ ํ›„ SDK Tools๊ฐ€ ์„ค์น˜๋œ ๊ฒฝ๋กœ๋Š”: C:\Users\<UserName>\AppData\Local\Android\Sdk\tools

mac์—์„œ๋Š” SDK tools๋ฅผ ๋‹ค์šด๋กœ๋“œํ•˜๊ณ  PATH์— ์ถ”๊ฐ€ํ•˜๋ ค๋ฉด ๋‹ค์Œ์„ ์‹คํ–‰ํ•˜์„ธ์š”:

brew tap homebrew/cask
brew install --cask android-sdk

๋˜๋Š” Android Studio GUI์—์„œ https://stackoverflow.com/questions/46402772/failed-to-install-android-sdk-java-lang-noclassdeffounderror-javax-xml-bind-a์— ํ‘œ์‹œ๋œ ๊ฒƒ์ฒ˜๋Ÿผ ~/Library/Android/sdk/cmdline-tools/latest/bin/, ~/Library/Android/sdk/platform-tools/ ๋ฐ ~/Library/Android/sdk/emulator/์— ์„ค์น˜๋ฉ๋‹ˆ๋‹ค

Java ๋ฌธ์ œ์˜ ๊ฒฝ์šฐ:

export JAVA_HOME=/Applications/Android\ Studio.app/Contents/jbr/Contents/Home

GUI

๊ฐ€์ƒ ๋จธ์‹  ์ค€๋น„

If you installed Android Studio, you can just open the main project view and access: Tools โ€“> AVD Manager.

๊ทธ๋Ÿฐ ๋‹ค์Œ, _Create Virtual Device_๋ฅผ ํด๋ฆญํ•˜์„ธ์š”

_select ์‚ฌ์šฉํ•˜๋ ค๋Š” ํœด๋Œ€ํฐ์„ ์„ ํƒํ•˜๊ณ  Next. ๋ฅผ ํด๋ฆญํ•˜์„ธ์š”

Warning

Play Store๊ฐ€ ์„ค์น˜๋œ ํฐ์ด ํ•„์š”ํ•˜๋ฉด Play Store ์•„์ด์ฝ˜์ด ์žˆ๋Š” ๊ธฐ๊ธฐ๋ฅผ ์„ ํƒํ•˜์„ธ์š”!

ํ˜„์žฌ ํ™”๋ฉด์—์„œ ํฐ์ด ์‹คํ–‰ํ•  Android image๋ฅผ ์„ ํƒํ•˜๊ณ  ๋‹ค์šด๋กœ๋“œํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค:

ํ•ด๋‹น ์ด๋ฏธ์ง€๋ฅผ ์„ ํƒํ•˜๊ณ , ๋‹ค์šด๋กœ๋“œ๋˜์–ด ์žˆ์ง€ ์•Š๋‹ค๋ฉด ์ด๋ฆ„ ์˜†์˜ Download ์‹ฌ๋ณผ์„ ํด๋ฆญํ•˜์„ธ์š” (์ด๋ฏธ์ง€๊ฐ€ ๋‹ค์šด๋กœ๋“œ๋  ๋•Œ๊นŒ์ง€ ๊ธฐ๋‹ค๋ฆฌ์„ธ์š”).
์ด๋ฏธ์ง€๊ฐ€ ๋‹ค์šด๋กœ๋“œ๋˜๋ฉด, Next ์™€ Finish ๋ฅผ ์„ ํƒํ•˜์„ธ์š”.

๊ฐ€์ƒ ๋จธ์‹ ์ด ์ƒ์„ฑ๋ฉ๋‹ˆ๋‹ค. ์ด์ œ AVD manager์— ์ ‘๊ทผํ•  ๋•Œ๋งˆ๋‹ค ์ด ๊ฐ€์ƒ ๋จธ์‹ ์ด ํ‘œ์‹œ๋ฉ๋‹ˆ๋‹ค.

๊ฐ€์ƒ ๋จธ์‹  ์‹คํ–‰

์‹คํ–‰ํ•˜๋ ค๋ฉด ๋‹จ์ˆœํžˆ Start button ์„ ๋ˆ„๋ฅด์„ธ์š”.

๋ช…๋ น์ค„ ๋„๊ตฌ

Warning

For macOS you can find the avdmanager tool in /Users/<username>/Library/Android/sdk/tools/bin/avdmanager and the emulator in /Users/<username>/Library/Android/sdk/emulator/emulator if you have them installed.

๋จผ์ € ์–ด๋–ค ํฐ์„ ์‚ฌ์šฉํ• ์ง€ ๊ฒฐ์ •ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค, ๊ฐ€๋Šฅํ•œ ํฐ ๋ชฉ๋ก์„ ๋ณด๋ ค๋ฉด ๋‹ค์Œ์„ ์‹คํ–‰ํ•˜์„ธ์š”:

C:\Users\<UserName>\AppData\Local\Android\Sdk\tools\bin\avdmanager.bat list device

d: 0 or "automotive_1024p_landscape"
Name: Automotive (1024p landscape)
OEM : Google
Tag : android-automotive-playstore
---------
id: 1 or "Galaxy Nexus"
Name: Galaxy Nexus
OEM : Google
---------
id: 2 or "desktop_large"
Name: Large Desktop
OEM : Google
Tag : android-desktop
---------
id: 3 or "desktop_medium"
Name: Medium Desktop
OEM : Google
Tag : android-desktop
---------
id: 4 or "Nexus 10"
Name: Nexus 10
OEM : Google
[...]

์‚ฌ์šฉํ•˜๋ ค๋Š” ๋””๋ฐ”์ด์Šค์˜ ์ด๋ฆ„์„ ์ •ํ–ˆ์œผ๋ฉด, ํ•ด๋‹น ๋””๋ฐ”์ด์Šค์—์„œ ์‹คํ–‰ํ•  Android ์ด๋ฏธ์ง€๋ฅผ ๊ฒฐ์ •ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.\ ๋ชจ๋“  ์˜ต์…˜์„ sdkmanager๋กœ ํ™•์ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค:

C:\Users\<UserName>\AppData\Local\Android\Sdk\tools\bin\sdkmanager.bat --list

๊ทธ๋ฆฌ๊ณ  ์‚ฌ์šฉํ•˜๋ ค๋Š” ํ•ญ๋ชฉ(๋˜๋Š” ๋ชจ๋‘)๋ฅผ download ํ•˜์„ธ์š”:

C:\Users\<UserName>\AppData\Local\Android\Sdk\tools\bin\sdkmanager.bat "platforms;android-28" "system-images;android-28;google_apis;x86_64"

์‚ฌ์šฉํ•˜๋ ค๋Š” Android ์ด๋ฏธ์ง€๋ฅผ ๋‹ค์šด๋กœ๋“œํ•œ ํ›„ ๋‹ค์Œ๊ณผ ๊ฐ™์ด ๋‹ค์šด๋กœ๋“œ๋œ ๋ชจ๋“  Android ์ด๋ฏธ์ง€๋ฅผ ๋‚˜์—ดํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค:

C:\Users\<UserName>\AppData\Local\Android\Sdk\tools\bin\avdmanager.bat list target
----------
id: 1 or "android-28"
Name: Android API 28
Type: Platform
API level: 28
Revision: 6
----------
id: 2 or "android-29"
Name: Android API 29
Type: Platform
API level: 29
Revision: 4

์ด์ œ ์‚ฌ์šฉํ•  ๊ธฐ๊ธฐ๋ฅผ ๊ฒฐ์ •ํ•˜๊ณ  Android ์ด๋ฏธ์ง€๋ฅผ ๋‹ค์šด๋กœ๋“œํ–ˆ์œผ๋ฏ€๋กœ, ๋‹ค์Œ ๋ช…๋ น์œผ๋กœ ๊ฐ€์ƒ ๋จธ์‹ ์„ ์ƒ์„ฑํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค:

C:\Users\<UserName>\AppData\Local\Android\Sdk\tools\bin\avdmanager.bat -v create avd -k "system-images;android-28;google_apis;x86_64" -n "AVD9" -d "Nexus 5X"

์ด์ „ ๋ช…๋ น์—์„œ ๋‹ค์Œ ์ด๋ฆ„์˜ VM์„ ์ƒ์„ฑํ–ˆ์Šต๋‹ˆ๋‹ค โ€œAVD9โ€ device โ€œNexus 5Xโ€œ์™€ Android image โ€œsystem-images;android-28;google_apis;x86_64โ€œ๋ฅผ ์‚ฌ์šฉํ–ˆ์Šต๋‹ˆ๋‹ค.\ ์ด์ œ ์ƒ์„ฑํ•œ virtual machines์„ ๋‚˜์—ดํ•˜๋ ค๋ฉด:

C:\Users\<UserName>\AppData\Local\Android\Sdk\tools\bin\avdmanager.bat list avd

Name: AVD9
Device: Nexus 5X (Google)
Path: C:\Users\cpolo\.android\avd\AVD9.avd
Target: Google APIs (Google Inc.)
Based on: Android API 28 Tag/ABI: google_apis/x86_64

The following Android Virtual Devices could not be loaded:
Name: Pixel_2_API_27
Path: C:\Users\cpolo\.android\avd\Pixel_2_API_27_1.avd
Error: Google pixel_2 no longer exists as a device

๊ฐ€์ƒ ๋จธ์‹  ์‹คํ–‰

Warning

macOS์—์„œ๋Š” avdmanager ๋„๊ตฌ๋ฅผ /Users/<username>/Library/Android/sdk/tools/bin/avdmanager์—์„œ, emulator๋Š” /Users/<username>/Library/Android/sdk/emulator/emulator์—์„œ ์ฐพ์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค(์„ค์น˜๋œ ๊ฒฝ์šฐ).

์šฐ๋ฆฌ๋Š” ์ด๋ฏธ ์ƒ์„ฑ๋œ ๊ฐ€์ƒ ๋จธ์‹ ์„ ๋‚˜์—ดํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ๋ณด์•˜์ง€๋งŒ, ๋‹ค์Œ ๋ช…๋ น์„ ์‚ฌ์šฉํ•ด ๋‚˜์—ดํ•  ์ˆ˜๋„ ์žˆ์Šต๋‹ˆ๋‹ค:

C:\Users\<UserName>\AppData\Local\Android\Sdk\tools\emulator.exe -list-avds
AVD9
Pixel_2_API_27

๋‹ค์Œ์„ ์‚ฌ์šฉํ•˜์—ฌ ์ƒ์„ฑ๋œ ๋ชจ๋“  ๊ฐ€์ƒ ๋จธ์‹ ์„ ๊ฐ„๋‹จํžˆ ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค:

C:\Users\<UserName>\AppData\Local\Android\Sdk\tools\emulator.exe -avd "VirtualMachineName"
C:\Users\<UserName>\AppData\Local\Android\Sdk\tools\emulator.exe -avd "AVD9"

๋˜๋Š” ๋” ๊ณ ๊ธ‰ ์˜ต์…˜์„ ์‚ฌ์šฉํ•˜์—ฌ ๋‹ค์Œ๊ณผ ๊ฐ™์€ ๊ฐ€์ƒ ๋จธ์‹ ์„ ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค:

C:\Users\<UserName>\AppData\Local\Android\Sdk\tools\emulator.exe -avd "AVD9" -http-proxy 192.168.1.12:8080 -writable-system

๋ช…๋ น์ค„ ์˜ต์…˜

ํ•˜์ง€๋งŒ ๊ฐ€์ƒ ๋จธ์‹ ์„ ์‹œ์ž‘ํ•  ๋•Œ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋Š” ์œ ์šฉํ•œ ๋ช…๋ น์ค„ ์˜ต์…˜์ด ๋งค์šฐ ๋งŽ์Šต๋‹ˆ๋‹ค. ์•„๋ž˜์—๋Š” ๋ช‡ ๊ฐ€์ง€ ํฅ๋ฏธ๋กœ์šด ์˜ต์…˜์„ ์ •๋ฆฌํ–ˆ์œผ๋ฉฐ ์ „์ฒด ๋ชฉ๋ก์€ find a complete list here

Boot

  • -snapshot name : VM ์Šค๋ƒ…์ƒท ์‹œ์ž‘
  • -snapshot-list -snapstorage ~/.android/avd/Nexus_5X_API_23.avd/snapshots-test.img : ๊ธฐ๋ก๋œ ๋ชจ๋“  ์Šค๋ƒ…์ƒท์„ ๋‚˜์—ด

Network

  • -dns-server 192.0.2.0, 192.0.2.255 : ์‰ผํ‘œ๋กœ ๊ตฌ๋ถ„๋œ DNS ์„œ๋ฒ„๋“ค์„ VM์— ์ง€์ •ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
  • -http-proxy 192.168.1.12:8080 : ์‚ฌ์šฉํ•  HTTP ํ”„๋ก์‹œ๋ฅผ ์ง€์ •ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค (ํŠธ๋ž˜ํ”ฝ์„ ์บก์ฒ˜ํ•  ๋•Œ Burp์™€ ํ•จ๊ป˜ ๋งค์šฐ ์œ ์šฉํ•ฉ๋‹ˆ๋‹ค)
  • ํ”„๋ก์‹œ ์„ค์ •์ด ์–ด๋–ค ์ด์œ ๋กœ ์ž‘๋™ํ•˜์ง€ ์•Š์œผ๋ฉด, ๋‚ด๋ถ€์ ์œผ๋กœ ์„ค์ •ํ•˜๊ฑฐ๋‚˜ โ€œSuper Proxyโ€ ๋˜๋Š” โ€œProxyDroidโ€ ๊ฐ™์€ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์„ ์‚ฌ์šฉํ•˜์—ฌ ๊ตฌ์„ฑํ•ด ๋ณด์„ธ์š”.
  • -netdelay 200 : ๋„คํŠธ์›Œํฌ ์ง€์—ฐ์„ ๋ฐ€๋ฆฌ์ดˆ ๋‹จ์œ„๋กœ ์—๋ฎฌ๋ ˆ์ด์…˜ํ•ฉ๋‹ˆ๋‹ค.
  • -port 5556 : ์ฝ˜์†”๊ณผ adb์— ์‚ฌ์šฉ๋˜๋Š” TCP ํฌํŠธ ๋ฒˆํ˜ธ๋ฅผ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค.
  • -ports 5556,5559 : ์ฝ˜์†”๊ณผ adb์— ์‚ฌ์šฉ๋˜๋Š” TCP ํฌํŠธ๋ฅผ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค.
  • -tcpdump /path/dumpfile.cap : ๋ชจ๋“  ํŠธ๋ž˜ํ”ฝ์„ ํŒŒ์ผ๋กœ ์บก์ฒ˜ํ•ฉ๋‹ˆ๋‹ค

System

  • -selinux {disabled|permissive} : Linux ์šด์˜์ฒด์ œ์—์„œ Security-Enhanced Linux ๋ณด์•ˆ ๋ชจ๋“ˆ์„ disabled ๋˜๋Š” permissive ๋ชจ๋“œ๋กœ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค.
  • -timezone Europe/Paris : ๊ฐ€์ƒ ๋””๋ฐ”์ด์Šค์˜ ํƒ€์ž„์กด์„ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค
  • -screen {touch(default)|multi-touch|o-touch} : ์—๋ฎฌ๋ ˆ์ด์…˜๋œ ํ„ฐ์น˜ ์Šคํฌ๋ฆฐ ๋ชจ๋“œ๋ฅผ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค.
  • -writable-system : ์ด ์˜ต์…˜์„ ์‚ฌ์šฉํ•˜๋ฉด ์—๋ฎฌ๋ ˆ์ด์…˜ ์„ธ์…˜ ๋™์•ˆ ์‹œ์Šคํ…œ ์ด๋ฏธ์ง€๋ฅผ ์“ฐ๊ธฐ ๊ฐ€๋Šฅํ•˜๊ฒŒ ๋งŒ๋“ญ๋‹ˆ๋‹ค. ๋˜ํ•œ adb root; adb remount๋ฅผ ์‹คํ–‰ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ์‹œ์Šคํ…œ์— ์ƒˆ๋กœ์šด ์ธ์ฆ์„œ๋ฅผ ์„ค์น˜ํ•  ๋•Œ ๋งค์šฐ ์œ ์šฉํ•ฉ๋‹ˆ๋‹ค.

Linux CLI setup (SDK/AVD quickstart)

๊ณต์‹ CLI ๋„๊ตฌ๋กœ Android Studio ์—†์ด๋„ ๋น ๋ฅด๊ณ  ๋””๋ฒ„๊น… ๊ฐ€๋Šฅํ•œ ์—๋ฎฌ๋ ˆ์ดํ„ฐ๋ฅผ ์‰ฝ๊ฒŒ ์ƒ์„ฑํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

# Directory layout
mkdir -p ~/Android/cmdline-tools/latest

# Download commandline tools (Linux)
wget https://dl.google.com/android/repository/commandlinetools-linux-13114758_latest.zip -O /tmp/cmdline-tools.zip
unzip /tmp/cmdline-tools.zip -d ~/Android/cmdline-tools/latest
rm /tmp/cmdline-tools.zip

# Env vars (add to ~/.bashrc or ~/.zshrc)
export ANDROID_HOME=$HOME/Android
export PATH=$ANDROID_HOME/cmdline-tools/latest/bin:$ANDROID_HOME/platform-tools:$ANDROID_HOME/emulator:$PATH

# Install core SDK components
sdkmanager --install "platform-tools" "emulator"

# Install a debuggable x86_64 system image (Android 11 / API 30)
sdkmanager --install "system-images;android-30;google_apis;x86_64"

# Create an AVD and run it with a writable /system & snapshot name
avdmanager create avd -n PixelRootX86 -k "system-images;android-30;google_apis;x86_64" -d "pixel"
emulator -avd PixelRootX86 -writable-system -snapshot PixelRootX86_snap

# Verify root (debuggable images allow `adb root`)
adb root
adb shell whoami  # expect: root

์ฐธ๊ณ 

  • ์‹œ์Šคํ…œ ์ด๋ฏธ์ง€ ์ข…๋ฅ˜: google_apis (๋””๋ฒ„๊น… ๊ฐ€๋Šฅ, adb root ํ—ˆ์šฉ), google_apis_playstore (root ๋ถˆ๊ฐ€), aosp/default (๊ฒฝ๋Ÿ‰).
  • ๋นŒ๋“œ ์œ ํ˜•: userdebug๋Š” ๋””๋ฒ„๊ทธ ๊ฐ€๋Šฅ ์ด๋ฏธ์ง€์—์„œ ์ข…์ข… adb root๋ฅผ ํ—ˆ์šฉํ•ฉ๋‹ˆ๋‹ค. Play Store ์ด๋ฏธ์ง€๋Š” ํ”„๋กœ๋•์…˜ ๋นŒ๋“œ๋กœ ๋ฃจํŠธ ๊ถŒํ•œ์„ ์ฐจ๋‹จํ•ฉ๋‹ˆ๋‹ค.
  • x86_64 ํ˜ธ์ŠคํŠธ์—์„œ๋Š” API 28+๋ถ€ํ„ฐ ์ „์ฒด ์‹œ์Šคํ…œ ARM64 ์—๋ฎฌ๋ ˆ์ด์…˜์ด ์ง€์›๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. Android 11+์˜ ๊ฒฝ์šฐ ๋งŽ์€ ARM ์ „์šฉ ์•ฑ์„ ๋น ๋ฅด๊ฒŒ ์‹คํ–‰ํ•˜๊ธฐ ์œ„ํ•ด ์•ฑ๋ณ„ ARM-to-x86 ๋ณ€ํ™˜์„ ํฌํ•จํ•˜๋Š” Google APIs/Play ์ด๋ฏธ์ง€๋ฅผ ์‚ฌ์šฉํ•˜์„ธ์š”.

CLI์—์„œ ์Šค๋ƒ…์ƒท

# Save a clean snapshot from the running emulator
adb -s emulator-5554 emu avd snapshot save my_clean_setup

# Boot from a named snapshot (if it exists)
emulator -avd PixelRootX86 -writable-system -snapshot my_clean_setup

ARMโ†’x86 ๋ฐ”์ด๋„ˆ๋ฆฌ ๋ณ€ํ™˜ (Android 11+)

Android 11+์˜ Google APIs ๋ฐ Play Store images๋Š” ์‹œ์Šคํ…œ์˜ ๋‚˜๋จธ์ง€๋ฅผ ๋„ค์ดํ‹ฐ๋ธŒ x86/x86_64๋กœ ์œ ์ง€ํ•˜๋ฉด์„œ ํ”„๋กœ์„ธ์Šค๋ณ„๋กœ ARM ์•ฑ ๋ฐ”์ด๋„ˆ๋ฆฌ๋ฅผ ๋ณ€ํ™˜ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๋Š” ๋ฐ์Šคํฌํ†ฑ์—์„œ ๋งŽ์€ ARM-only ์•ฑ์„ ํ…Œ์ŠคํŠธํ•˜๊ธฐ์— ์ถฉ๋ถ„ํžˆ ๋น ๋ฅธ ๊ฒฝ์šฐ๊ฐ€ ๋งŽ์Šต๋‹ˆ๋‹ค.

ํŒ: pentests ๋™์•ˆ Google APIs x86/x86_64 images๋ฅผ ์„ ํ˜ธํ•˜์„ธ์š”. Play images๋Š” ํŽธ๋ฆฌํ•˜์ง€๋งŒ adb root๋ฅผ ์ฐจ๋‹จํ•ฉ๋‹ˆ๋‹ค; Play services๊ฐ€ ๋ฐ˜๋“œ์‹œ ํ•„์š”ํ•˜๊ณ  root๊ฐ€ ์—†๋‹ค๋Š” ๊ฒƒ์„ ์ˆ˜์šฉํ•  ๋•Œ๋งŒ ์‚ฌ์šฉํ•˜์„ธ์š”.

Play Store ๋””๋ฐ”์ด์Šค์˜ root ํš๋“

Play Store๊ฐ€ ํฌํ•จ๋œ ๋””๋ฐ”์ด์Šค๋ฅผ ๋‹ค์šด๋กœ๋“œํ•œ ๊ฒฝ์šฐ ์ง์ ‘์ ์œผ๋กœ root๋ฅผ ์–ป์„ ์ˆ˜ ์—†์œผ๋ฉฐ ๋‹ค์Œ๊ณผ ๊ฐ™์€ ์˜ค๋ฅ˜ ๋ฉ”์‹œ์ง€๊ฐ€ ํ‘œ์‹œ๋ฉ๋‹ˆ๋‹ค

$ adb root
adbd cannot run as root in production builds

rootAVD์™€ Magisk๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ rootํ•  ์ˆ˜ ์žˆ์—ˆ์Šต๋‹ˆ๋‹ค (์˜ˆ: this video ๋˜๋Š” this one).

Burp ์ธ์ฆ์„œ ์„ค์น˜

๋‹ค์Œ ํŽ˜์ด์ง€๋ฅผ ํ™•์ธํ•˜์—ฌ ์ปค์Šคํ…€ CA ์ธ์ฆ์„œ๋ฅผ ์„ค์น˜ํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ์•Œ์•„๋ณด์„ธ์š”:

Install Burp Certificate

์œ ์šฉํ•œ AVD ์˜ต์…˜

์Šค๋ƒ…์ƒท ์ฐ๊ธฐ

์–ธ์ œ๋“ ์ง€ VM์˜ ์Šค๋ƒ…์ƒท์„ ์ฐ์œผ๋ ค๋ฉด GUI๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค:

์ฐธ๊ณ ์ž๋ฃŒ

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ