Deco Aprilliansyah
Universitas Ahmad Dahlan

Published : 2 Documents Claim Missing Document
Claim Missing Document
Check
Articles

Found 2 Documents
Search

Penetration Testing with OWASP Mobile for Android Security Optimization Deco Aprilliansyah; Imam Riadi; Sunardi
Journal of Cyber Health and Computer Vol 1 No 1 (2023): Journal of Cyber Health and Computer (JOCHAC)
Publisher : SIBER PRESS Universitas SIBERMU

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.64163/jochac.v1i1.3

Abstract

Security and privacy are very important on android devices to prevent crimes such as the theft of data and confidential information for users. There are many attack methods that can be carried out by irresponsible parties, one of which is penetration testing. The need to improve the security of android devices from cyber crimes that can occur at any time so that the security and information belonging to users are more secure. Based on this, this study offers how attackers perform penetration testing on targets using android devices using the OWASP Mobile framework based on the steps in the Security Testing Guide (OWASP MSTG) manual. The penetration testing activity is carried out in five steps. Namely, injection of backdoors on the application, finding vulnerabilities, scanning, exploiting and making reports. The results of this study obtained some information on application IOCs and other information in the form of contact data, SMS data, and audio records belonging to the attacked device. Based on this, this research can be used by security parties to patch loopholes in their applications and systems.
Analysis of Remote Access Trojan Attack using Android Debug Bridge Deco Aprilliansyah; Imam Riadi; Sunardi
IJID (International Journal on Informatics for Development) Vol. 10 No. 2 (2021): IJID December
Publisher : Faculty of Science and Technology, Universitas Islam Negeri (UIN) Sunan Kalijaga Yogyakarta

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.14421/ijid.2021.2839

Abstract

The security hole in the android operating system sometimes not realized by users such as malware and exploitation by third parties to remote access. This study conducted to identify the vulnerabilities of android operating system by using Ghost Framework. The vulnerability of the android smartphone are found by using the Android Debug Bridge (ADB) with the exploitation method as well as to analyze the test results and identify remote access Trojan attacks. The exploitation method with several steps from preparing the tools and connecting to the testing commands to the testing device have been conducted. The result shows that android version 9 can be remote access by entering the exploit via ADB. Some information has been obtained by third parties, enter and change the contents of the system directory can be remote access like an authorized to do any activities on the device such as opening lock screen, entering the directory system, changing the system, etc.