100 Commits
Author SHA1 Message Date
Ajin AbrahamandCursor Agent d3869adc46 docs: note CSRF POST and DOM XSS rules in AGENTS.md (#2684)
Document that mutating dynamic-analysis actions must be POST with a CSRF
token, and that template auto-escaping does not protect innerHTML sinks.

Co-authored-by: Cursor Agent <[email protected]>
2026-09-20 19:38:24 -07:00
Ajin Abraham c730571083 HOTFIX: Bump deps 2026-09-20 19:26:34 -07:00
Ajin Abraham 36ec4b82b8 bump signatures (#2682) 2026-09-20 18:11:06 -07:00
Ajin AbrahamandCursor Agent 2a8399fac9 Fix responsive layouts and request error handling (#2681)
* fix duplicate user and upload error handling

Co-authored-by: Ajin Abraham <[email protected]>

* fix: make analysis navigation and summaries responsive

Co-authored-by: Ajin Abraham <[email protected]>

---------

Co-authored-by: Cursor Agent <[email protected]>
2026-09-20 17:47:36 -07:00
Ajin AbrahamandCursor 6592454800 Prepare 4.5.3 dependency release (#2680)
* Harden path traversal checks for Windows root-relative escapes.

Reject POSIX/Windows absolute paths in is_path_traversal and require post-join containment at icon, network-config, and archive extraction sinks.

Co-authored-by: Cursor <[email protected]>

* Restrict network security config names to a basename.

CodeQL flagged the manifest-derived join; reduce the resource name first so path construction cannot escape xml_dir.

Co-authored-by: Cursor <[email protected]>

* Use os.path.basename for CodeQL-recognized path sanitization.

Path.name did not clear py/path-injection taint; basename plus existing containment checks keep the network-config read inside xml_dir.

Co-authored-by: Cursor <[email protected]>

* Drop CodeQL-appeasement basename sanitization from network config reads.

is_safe_path after join already rejects traversal, absolute, and Windows root-relative names; CodeQL py/path-injection is a false positive.

Co-authored-by: Cursor <[email protected]>

* Bound androguard ZIP member decompression

Use the configured per-file ZIP limit for apkinspector reads and cap
actual raw-DEFLATE output. Keep decompression-limit failures out of the
tampered-entry fallback so malicious compressed data cannot be treated
as stored bytes.

Co-authored-by: Cursor <[email protected]>

* Reject inactive SAML users before ACS group updates.

Existing accounts mapped from a valid IdP assertion should not have groups replaced or be passed to login() when is_active is False.

Co-authored-by: Cursor <[email protected]>

* Return the ACS error page for inactive users instead of raising Exception.

Co-authored-by: Cursor <[email protected]>

* Fix iOS plist-derived path traversal

Select and validate one contained IPA app bundle, reject unsafe plist
executable values, and guard icon and Mach-O inputs before access.
Harden equivalent source icon, plist, library, and dynamic icon paths.

Co-authored-by: Cursor <[email protected]>

* correct version

* fix CSRF in dynamic analysis actions

Co-authored-by: Ajin Abraham <[email protected]>

* document HTTPTools host header SSRF advisory

Co-authored-by: Ajin Abraham <[email protected]>

* prepare 4.5.3 dependency release

Co-authored-by: Ajin Abraham <[email protected]>

* support LIEF 0.17 Mach-O symbol types

Co-authored-by: Ajin Abraham <[email protected]>

* pin GitHub Actions to immutable commits

Co-authored-by: Ajin Abraham <[email protected]>

---------

Co-authored-by: Cursor <[email protected]>
2026-09-20 16:37:19 -07:00
Ajin AbrahamandCursor a23ff75ec0 Fix CSRF in dynamic analysis actions (#2679)
* Harden path traversal checks for Windows root-relative escapes.

Reject POSIX/Windows absolute paths in is_path_traversal and require post-join containment at icon, network-config, and archive extraction sinks.

Co-authored-by: Cursor <[email protected]>

* Restrict network security config names to a basename.

CodeQL flagged the manifest-derived join; reduce the resource name first so path construction cannot escape xml_dir.

Co-authored-by: Cursor <[email protected]>

* Use os.path.basename for CodeQL-recognized path sanitization.

Path.name did not clear py/path-injection taint; basename plus existing containment checks keep the network-config read inside xml_dir.

Co-authored-by: Cursor <[email protected]>

* Drop CodeQL-appeasement basename sanitization from network config reads.

is_safe_path after join already rejects traversal, absolute, and Windows root-relative names; CodeQL py/path-injection is a false positive.

Co-authored-by: Cursor <[email protected]>

* Bound androguard ZIP member decompression

Use the configured per-file ZIP limit for apkinspector reads and cap
actual raw-DEFLATE output. Keep decompression-limit failures out of the
tampered-entry fallback so malicious compressed data cannot be treated
as stored bytes.

Co-authored-by: Cursor <[email protected]>

* Reject inactive SAML users before ACS group updates.

Existing accounts mapped from a valid IdP assertion should not have groups replaced or be passed to login() when is_active is False.

Co-authored-by: Cursor <[email protected]>

* Return the ACS error page for inactive users instead of raising Exception.

Co-authored-by: Cursor <[email protected]>

* Fix iOS plist-derived path traversal

Select and validate one contained IPA app bundle, reject unsafe plist
executable values, and guard icon and Mach-O inputs before access.
Harden equivalent source icon, plist, library, and dynamic icon paths.

Co-authored-by: Cursor <[email protected]>

* correct version

* fix CSRF in dynamic analysis actions

Co-authored-by: Ajin Abraham <[email protected]>

* document HTTPTools host header SSRF advisory

Co-authored-by: Ajin Abraham <[email protected]>

---------

Co-authored-by: Cursor <[email protected]>
2026-09-20 16:36:10 -07:00
Ajin AbrahamandCursor e2609ad5aa Fix iOS plist-derived path traversal (#2678)
* Harden path traversal checks for Windows root-relative escapes.

Reject POSIX/Windows absolute paths in is_path_traversal and require post-join containment at icon, network-config, and archive extraction sinks.

Co-authored-by: Cursor <[email protected]>

* Restrict network security config names to a basename.

CodeQL flagged the manifest-derived join; reduce the resource name first so path construction cannot escape xml_dir.

Co-authored-by: Cursor <[email protected]>

* Use os.path.basename for CodeQL-recognized path sanitization.

Path.name did not clear py/path-injection taint; basename plus existing containment checks keep the network-config read inside xml_dir.

Co-authored-by: Cursor <[email protected]>

* Drop CodeQL-appeasement basename sanitization from network config reads.

is_safe_path after join already rejects traversal, absolute, and Windows root-relative names; CodeQL py/path-injection is a false positive.

Co-authored-by: Cursor <[email protected]>

* Bound androguard ZIP member decompression

Use the configured per-file ZIP limit for apkinspector reads and cap
actual raw-DEFLATE output. Keep decompression-limit failures out of the
tampered-entry fallback so malicious compressed data cannot be treated
as stored bytes.

Co-authored-by: Cursor <[email protected]>

* Reject inactive SAML users before ACS group updates.

Existing accounts mapped from a valid IdP assertion should not have groups replaced or be passed to login() when is_active is False.

Co-authored-by: Cursor <[email protected]>

* Return the ACS error page for inactive users instead of raising Exception.

Co-authored-by: Cursor <[email protected]>

* Fix iOS plist-derived path traversal

Select and validate one contained IPA app bundle, reject unsafe plist
executable values, and guard icon and Mach-O inputs before access.
Harden equivalent source icon, plist, library, and dynamic icon paths.

Co-authored-by: Cursor <[email protected]>

* correct version

---------

Co-authored-by: Cursor <[email protected]>
2026-09-20 16:35:00 -07:00
Ajin AbrahamandCursor 70ecabcafb Reject inactive SAML users before ACS group updates (#2677)
* Harden path traversal checks for Windows root-relative escapes.

Reject POSIX/Windows absolute paths in is_path_traversal and require post-join containment at icon, network-config, and archive extraction sinks.

Co-authored-by: Cursor <[email protected]>

* Restrict network security config names to a basename.

CodeQL flagged the manifest-derived join; reduce the resource name first so path construction cannot escape xml_dir.

Co-authored-by: Cursor <[email protected]>

* Use os.path.basename for CodeQL-recognized path sanitization.

Path.name did not clear py/path-injection taint; basename plus existing containment checks keep the network-config read inside xml_dir.

Co-authored-by: Cursor <[email protected]>

* Drop CodeQL-appeasement basename sanitization from network config reads.

is_safe_path after join already rejects traversal, absolute, and Windows root-relative names; CodeQL py/path-injection is a false positive.

Co-authored-by: Cursor <[email protected]>

* Bound androguard ZIP member decompression

Use the configured per-file ZIP limit for apkinspector reads and cap
actual raw-DEFLATE output. Keep decompression-limit failures out of the
tampered-entry fallback so malicious compressed data cannot be treated
as stored bytes.

Co-authored-by: Cursor <[email protected]>

* Reject inactive SAML users before ACS group updates.

Existing accounts mapped from a valid IdP assertion should not have groups replaced or be passed to login() when is_active is False.

Co-authored-by: Cursor <[email protected]>

* Return the ACS error page for inactive users instead of raising Exception.

Co-authored-by: Cursor <[email protected]>

---------

Co-authored-by: Cursor <[email protected]>
2026-09-20 16:34:04 -07:00
Ajin AbrahamandCursor a04a42e768 Bound androguard ZIP member decompression (#2675)
* Harden path traversal checks for Windows root-relative escapes.

Reject POSIX/Windows absolute paths in is_path_traversal and require post-join containment at icon, network-config, and archive extraction sinks.

Co-authored-by: Cursor <[email protected]>

* Restrict network security config names to a basename.

CodeQL flagged the manifest-derived join; reduce the resource name first so path construction cannot escape xml_dir.

Co-authored-by: Cursor <[email protected]>

* Use os.path.basename for CodeQL-recognized path sanitization.

Path.name did not clear py/path-injection taint; basename plus existing containment checks keep the network-config read inside xml_dir.

Co-authored-by: Cursor <[email protected]>

* Drop CodeQL-appeasement basename sanitization from network config reads.

is_safe_path after join already rejects traversal, absolute, and Windows root-relative names; CodeQL py/path-injection is a false positive.

Co-authored-by: Cursor <[email protected]>

* Bound androguard ZIP member decompression

Use the configured per-file ZIP limit for apkinspector reads and cap
actual raw-DEFLATE output. Keep decompression-limit failures out of the
tampered-entry fallback so malicious compressed data cannot be treated
as stored bytes.

Co-authored-by: Cursor <[email protected]>

---------

Co-authored-by: Cursor <[email protected]>
2026-09-20 16:32:50 -07:00
Ajin AbrahamandCursor 388f26ad5e Harden path traversal against Windows root-relative escapes (#2673)
* Harden path traversal checks for Windows root-relative escapes.

Reject POSIX/Windows absolute paths in is_path_traversal and require post-join containment at icon, network-config, and archive extraction sinks.

Co-authored-by: Cursor <[email protected]>

* Restrict network security config names to a basename.

CodeQL flagged the manifest-derived join; reduce the resource name first so path construction cannot escape xml_dir.

Co-authored-by: Cursor <[email protected]>

* Use os.path.basename for CodeQL-recognized path sanitization.

Path.name did not clear py/path-injection taint; basename plus existing containment checks keep the network-config read inside xml_dir.

Co-authored-by: Cursor <[email protected]>

* Drop CodeQL-appeasement basename sanitization from network config reads.

is_safe_path after join already rejects traversal, absolute, and Windows root-relative names; CodeQL py/path-injection is a false positive.

Co-authored-by: Cursor <[email protected]>

---------

Co-authored-by: Cursor <[email protected]>
2026-09-20 16:30:53 -07:00
Ajin AbrahamandCursor 18bb89b672 Give gh an explicit repo so welcome comments work without a checkout. (#2674)
gh pr comment fails with "not a git repository" because this workflow
intentionally skips checkout; GH_REPO and -R keep pull_request_target
from needing a clone of untrusted PR code.

Co-authored-by: Cursor <[email protected]>
2026-09-20 14:12:09 -07:00
Ajin AbrahamandCursor f823a7cf6e Replace wow-actions/auto-comment with native gh comments. (#2672)
Use pull_request_target only for posting fixed welcome text, with no
checkout or PR code execution, so fork PRs can be commented on without
exposing a stolen write token.

Co-authored-by: Cursor <[email protected]>
2026-09-20 13:32:32 -07:00
Ajin AbrahamandCursor 42ee5dc7e9 Fix DNS rebinding SSRF with pinned safe HTTP requests. (#2670)
* Fix DNS rebinding SSRF with pinned safe HTTP requests.

Add shared SSRF-safe request helpers that resolve once, connect to validated public IPs while preserving Host/SNI, reject redirects and internal addresses, and fail closed when upstream proxies would bypass pinning. Migrate assetlinks, Firebase, APK downloader, malware geolocation, and httptools shutdown to the hardened paths.

Co-authored-by: Cursor <[email protected]>

* remove test file

* Address SSRF hardening review feedback

Co-authored-by: Cursor <[email protected]>

* Avoid reassigning stop_httptools url parameter.

Use a dedicated proxy_kill_url so SonarCloud no longer flags
parameter reassignment before the initial value is used.

Co-authored-by: Cursor <[email protected]>

* bump version + deps

---------

Co-authored-by: Cursor <[email protected]>
2026-09-20 13:23:01 -07:00
Ajin AbrahamandCursor 3f48c5deb5 ci: publish to PyPI with OIDC Trusted Publishing (#2646)
* ci: publish to PyPI with OIDC Trusted Publishing

Replace the long-lived PYPI_PASSWORD token with GitHub Actions OIDC
and pypa/gh-action-pypi-publish on release publish events.

Co-authored-by: Cursor <[email protected]>

* ci: drop inline comment on id-token permission

Co-authored-by: Cursor <[email protected]>

---------

Co-authored-by: Cursor <[email protected]>
2026-08-09 23:14:01 -07:00
Ajin AbrahamandCursor fe882bf0dc chore: bump Python dependencies (#2645)
* chore: bump Python dependencies

Refresh poetry.lock within existing constraints (Django 6.1, Frida,
libsast, and related transitive updates).

Co-authored-by: Cursor <[email protected]>

* chore: raise libsast constraint to ^3.1.8

Co-authored-by: Cursor <[email protected]>

* chore: refresh poetry.lock content-hash after libsast bump

Co-authored-by: Cursor <[email protected]>

---------

Co-authored-by: Cursor <[email protected]>
2026-08-09 22:47:36 -07:00
Ajin AbrahamandCursor 95321b5b2e Migrate VirusTotal integration to API v3. (#2644)
Replace deprecated v2 endpoints with v3 report/upload flows, add
large-file upload_url support up to 650MB, and normalize responses
for existing report templates. Refs #2560.

Co-authored-by: Cursor <[email protected]>
2026-08-09 18:31:11 -07:00
Ajin AbrahamandCursor a0f8a0ded1 ci/docker: supply-chain Actions updates and Postgres 18 compose layout (#2643)
* ci: bump Actions versions, pin Docker actions, add Dependabot

Keep CI supply chain current after the Docker SBOM work: update test,
publish, and CodeQL workflows, SHA-pin Docker setup/login actions, and
enable weekly GitHub Actions Dependabot updates.

Co-authored-by: Cursor <[email protected]>

* docker: use Postgres latest and PG18 data volume layout

Co-authored-by: Cursor <[email protected]>

* Bump version to 4.5.2

Co-authored-by: Cursor <[email protected]>

---------

Co-authored-by: Cursor <[email protected]>
2026-08-09 18:14:05 -07:00
Ajin Abraham 62563ca429 [HOTFIX][Security] Security Updates July 5 2026 (#2627)
Security Fixes

[GHSA-8j49-mmcx-4mp5] Arbitrary File Read via Path Traversal in ZIP/APK Icon Extraction
The android:icon attribute from an APK manifest was interpolated into file paths without validation, allowing a crafted APK to read arbitrary files from the server. Fixed by adding is_path_traversal() and is_safe_path() guards in find_icon_path_zip. Dependency bump included.

[GHSA-3p54-567p-2wpr] CSRF Checks Not Enforced After Django Middleware Migration
The migration from the deprecated MIDDLEWARE_CLASSES to MIDDLEWARE omitted CsrfViewMiddleware, SecurityMiddleware, and XFrameOptionsMiddleware, leaving CSRF, HSTS, and clickjacking protections silently disabled. All three have been restored to the active MIDDLEWARE tuple. The now-dead MIDDLEWARE_CLASSES block has been removed to prevent future confusion.

[GHSA-x768-8642-mmq9] Zip Bomb Denial of Service via Per-File Size Limit Bypass
The per-file size check in ZIP extraction logged a warning on oversized members but was missing a continue, allowing files exceeding ZIP_MAX_UNCOMPRESSED_FILE_SIZE to be extracted anyway as long as the aggregate limit was not reached. Fixed by adding the missing continue.

[GHSA-95px-34x5-p37h] SSRF Port Restriction Bypass in assetlinks_check
valid_host() was called with only the bare hostname, allowing android:port to be appended afterward without going through port validation, bypassing the HTTP/HTTPS-only restriction. Fixed with a two-layer approach: primary port allowlist check before URL assembly in get_browsable_activities, and a defence-in-depth re-check in _check_url.

Hardening

The hand-rolled safe_extract used os.path.abspath (symlink-blind) instead of os.path.realpath, creating a TOCTOU window where a symlink could redirect extraction outside the destination directory. Replaced with Python 3.12's tarfile.extractall(filter='data') (PEP 706), which rejects symlinks, hardlinks, absolute paths, and traversal members per-member before extraction. A robust realpath-based fallback is included for older Python versions.
Both download_app_data call sites in the iOS dynamic analyser now wrap app_container and tarfile with shlex.quote when building the SSH tar command, as defensive coding hygiene.
Refactoring

is_path_traversal, is_safe_path, clean_filename, cmd_injection_check, is_pipe_or_link, and is_attack_pattern were scattered across utils.py and shared.py. All have been moved to mobsf/MobSF/security.py as the single authoritative location for security primitives.
Developer Tooling

AGENTS.md / CLAUDE.md - AI agent guidelines
Added a coding-standards document for AI coding agents (Cursor, Claude, Codex) covering MobSF-specific secure-by-default patterns: path traversal guards, archive extraction safety, Django middleware active-tuple hygiene, split-validation anti-patterns (SSRF port bypass), guard completeness (continue/return/raise after every security check), and Django-specific security features (form validators, decorators, middleware). CLAUDE.md is a symlink to AGENTS.md.
2026-07-05 16:55:49 -07:00
6e875fb77b Jailbroken iOS Device Support (#2536)
Enables dynamic analysis on real jailbroken iOS devices connected via USB or WiFi SSH, complementing the existing Corellium-based iOS analysis.              
                                                                                                                                                                                                                                                                                                                                                                                                                                                                
  - SSH connectivity — connects to jailbroken devices over USB (via iproxy port forwarding) or WiFi using Paramiko SSH                                         
  - Frida instrumentation — spawns/attaches Frida on-device, with full hook support matching the existing Corellium flow                                       
  - Environment setup — installs AppSync Unified and Frida server on first run; supports both arm and arm64 devices                                            
  - Dynamic analysis — app file extraction, system log streaming (oslog), screenshot capture, process listing, and report generation
  - SSH terminal — execute shell commands on the device over SSH

---------

Co-authored-by: CylentSec <[email protected]>
Co-authored-by: Oz <[email protected]>
2026-03-23 01:46:03 -07:00
Ajin Abraham 6f8a43c1b7 [SECURITY][HOTFIX] Security Fixes and Hardening (#2600)
* Fix GHSA-hqjr-43r5-9q58

* Update security docs

* Security hardening

* Bump deps
2026-03-21 14:50:01 -07:00
Ajin Abraham 2b08dd050e [SECURITY] Security Update + Dependency Bump (#2584)
* Bump Dependencies
* Fix a Stored XSS: GHSA-8hf7-h89p-3pqj
* Remove all  | safe in templates and HTML from Python
* Add permissions to Github Actions
2026-01-25 22:33:34 -08:00
Ajin Abraham 4b004f3817 HOTFIX: Fix AppSec Score Card for iOS 2025-12-08 19:17:25 -08:00
Ajin Abraham 2c712e2ebc [HOTFIX] Dec 2025 QA + Bug Fixes (#2574)
* Dependency bump
* Fix [FEATURE] urls should be extracted as case-sensitive #2491
* Fix Code analysis -> IP Address disclosure flags on invalid IP's (Version Numbers) #2562
2025-12-07 21:34:08 -08:00
Ajin Abraham 9b6e0f0fe4 Socket Supply Chain Scan (#2559)
Socket Supply Chain Firewall
2025-10-04 15:04:04 -07:00
Ajin Abraham e371db8388 [HOTFIX] Update Slack Join Link (#2556)
* Update README.md

* Update SUPPORT.md

* Update bug_report.md

* Update CONTRIBUTING.md

* Update auto-comment.yml
2025-09-30 10:54:10 -07:00
Ajin Abraham 5d1096d458 Hotfix: Fix LIEF nx and arc check 2025-09-07 12:33:53 -07:00
Ajin Abraham de7bf03656 Python 3.13 Support (#2546)
* Python Support updated to 3.12-3.13
* Bump mitmproxy
* Bump httptools
* Remove pinned xmlsec, lxml
* Android Permission Update
* Updates Signatures
2025-08-30 23:46:20 -07:00
Ajin Abraham 7f3bc086c0 [Security] Fix Vulnerabilities Aug 2025 MobSF v4.4.1 (#2545)
Bump dependencies
Fix Security Vulnerabilities reported by @noname1337h1
https://github.com/MobSF/Mobile-Security-Framework-MobSF/security/advisories/GHSA-9gh8-9r95-3fc3
https://github.com/MobSF/Mobile-Security-Framework-MobSF/security/advisories/GHSA-ccc3-fvfx-mw3v
2025-08-30 19:28:41 -07:00
Ajin Abraham 7e0355c51d June 22nd 2025 updates (#2530)
* Breaking change: Frida 17+ support and script updates
* Breaking change: Corellium iOS device must install frida >=17
* Updated Frida scripts for logging, ssl/cert pinning bypass
* Added bridges support to frida
* Poetry dependency updates
* Fix Frida Code Editor code alignment issues
* Fix Google Play Scrapper timeout issues behind proxy
* Apply MobSF proxy settings to standalone tools_download.py
2025-06-23 00:57:33 -07:00
Ajin Abraham 6987a94648 v4.3.3 Security Updates (#2518)
* Fix GHSA-mwfg-948f-2cc5

* stricter email case validation

* Fix GHSA-c5vg-26p8-q8cr

* Bump deps

* Lint QA
2025-05-04 16:33:07 -07:00
Ajin Abraham cecec6e96d update postgres to 14 2025-04-25 14:05:53 -07:00
Ajin Abraham 702e9b2100 Lint fixing: 2025-04-25 11:23:09 -07:00
Ajin Abraham caa223d94a pin lxml version as well 2025-04-25 11:16:33 -07:00
Ajin Abraham 4b8bab5a98 [SECURITY] Improve SSRF checks, strict path check for well_known_path (#2510)
* Improved SSRF checks (credential checks, length check, port check, path, query, and params check, ipv6, ipv4 coverage, handle possible decimal or hex IP bypasses)
* Add additional strict path check for Applink well known path
* Moved `valid_host` to `security.py`
* Update `security.md`
* Bump dependencies
* Fix docker build
2025-03-28 17:38:23 -07:00
Ajin Abraham 506434670a March 25 QA (#2504)
* Dependency bump
* Strict firebaseio domain check
* Fix frida server download proxy SSL verify config
* Fix CI build on mac
2025-03-23 12:27:01 -07:00
Ajin Abraham 05206e72ca [SECURITY] Security update to fix vulnerabilities reported by Positive Technologies researchers (#2488)
* Fix Stored XSS in iOS Dynamic Analysis, GHSA-cxqq-w3x5-7ph3
* Fix DOS by loose re_path check and strict check inside function, GHSA-jrm8-xgf3-fwqr
* Fix API Key leakage, replace REST API with authenticated endpoint, GHSA-79f6-p65j-3m2m
* Update SECURITY.md
2025-02-04 21:00:57 -08:00
Ajin AbrahamandNick Lupien d1d3b7a9ae Dep bump + Support HTTPS upgrade for Assetlinks check (#2484)
* Fix false positives caused in Android manifest analysis
* Dep bumps + Support HTTPS upgrade for Assetlinks check
* MobSF version bump to 4.3.0

---------

Co-authored-by: Nick Lupien <[email protected]>
2025-01-22 23:15:32 -08:00
Ajin AbrahamandByteSnipers GmbH 79b2d28c3b Byte snipers patch 2 (#2477)
* Fix for missing 'packaging.metadata module

Changed the packaging version to 24.2

Co-authored-by: ByteSnipers GmbH <[email protected]>
2024-12-18 18:35:11 -08:00
Ajin Abraham 8310104ba9 Update README.md 2024-12-02 22:38:47 -08:00
Ajin Abraham 5ce7e237af [4.2.8] Multiple APK Analysis improvements, general Code QA & bug fixes (#2470)
* Dockerfile QA
* Add sdk-build-tools to Docker image
* Replace biplist with plistlib std lib
* Fixed a bug in iOS pbxproj parsing
* Added support for APK parsing with aapt2/aapt
* Use aapt/aapt2 as a fallback for APK parsing, files listing and string extraction
* Added "started at" to Scan task queue model #2463
* Tasks List API to return string status #2464
* Replaced all minidom calls with defusedxml.minidom
* Code QA on android manifest data extraction and parsing
* Improved android file analysis
* Improved android manifest data extraction
* Improved android icon file extraction
* Improved android app name extraction
* Improved android appstore package details extraction
* Android string extraction to fallback on aapt2 strings
* APK analysis arguments refactor
* Handle packed APKs, refactor unzip to handle malformed APK files
* Handle reserved filename conflict during ZIP extraction
* Explicit Zipslip handling during ZIP extraction
* Graceful files extraction on unzip failure
* Removed bail out and continue analysis
* Moved androguard parsing to the start of static analysis
* AndroidManifest.xml fallback from apktool to androguard during extraction and parsing
* Updated Tasks UI to show started at
2024-11-28 17:26:50 -08:00
Ajin Abraham a015df5871 [4.2.7] Updates (#2462)
Bump to google fork of baksmali 3.0.8
IPA: Graceful handling of plist dump exception
2024-11-25 00:04:40 -08:00
Ajin Abraham af49985dd1 [4.2.7] Androguard & ApkInspector Bump + Patch AXMLParsing (#2461)
* Androguard 293ab2d89ab9ce011c7dbbc5df3c876172875a1c update
* AXML Parser warn "reserved must be zero!" instead of raise
* Fallback on get app name when androguard returns empty string
2024-11-24 22:53:21 -08:00
Ajin Abraham 8cd9838369 4.2.6 (#2459)
* Updated permissions
* Added and updated permission mapping rules
* Handle errors gracefully from get_app_name and icon_analysis
* Add new scans in tasks view without needing and explicit refresh
* Optimizing downloads, adding downloads for source code types and windows appx
2024-11-24 14:20:35 -08:00
Ajin Abraham b4cf9b70ac 4.2.5 (#2457)
* Unified async scan timeout
* Allow incomplete scan delete after async scan timeout duration
* Added support for Android SBOM analysis
* Make dependencies unpinned (Address #2458)
2024-11-23 13:48:12 -08:00
Ajin Abraham 4b394a2b8a [4.2.4] Async analysis REST API support, fix timeout handle function, Qa (#2456)
* Async analysis REST API support & Docs
* Fix timeout handle function
* Code QA untar permissions
2024-11-20 22:56:46 -08:00
Ajin Abraham a7fa82798f Update status on task timeout (#2454) 2024-11-20 14:05:59 -08:00
Ajin Abraham 523abbaff1 4.2.2 (#2452)
* QA
* Verbose
2024-11-19 13:34:16 -08:00
Ajin Abraham 003ee16519 4.2.1 (#2451)
* Improvements in scan queue
* Fix TOCTOU in delete scans view
2024-11-18 20:56:18 -08:00
Ajin Abraham b5da756615 4.2.0 (#2450)
- Added malware lookup using SHA2 with VirusTotal, Triage, Hybrid Analysis, and MetaDefender.
- Fixed permissions of extracted files to counter anti-analysis techniques.
- Resolved APK parsing errors in `androguard`.
- Handled exceptions in `string_on_binary`.
- Optimized APK ZIP analysis for improved performance.
- Fixed untar permission errors in dynamic analysis.
- Added bypass for SSL pinning in Boye's `AbstractVerifier`.
- Updated bypass for SSL pinning in Appmattus's `CertificateTransparencyInterceptor`.
- Introduced SSL pinning detector script.
- Improved Frida intent dumper script.
- Added Frida intent tracer script.
- Introduced timeouts for all HTTP calls.
- Added `django-q2`-based asynchronous scans for Android and iOS binaries and source code.
- Fixed bug in certificate analysis.
- Enabled asynchronous scans in Docker Compose setup.
- Performed QA for Android and iOS SAST modules.
- Added Frida script for `audit-webview`.
- Introduced Frida script for `trace-javascript-interface`.
- Upgraded `libsast` for improved file reading, multiprocessing, and multithreading.
- Fixed PNG crush issues on Darwin systems.
- Performed QA on the home screen UI.
- Updated `httptools` and `libsast` dependencies.
2024-11-17 22:26:06 -08:00
Ajin Abraham 3cf21cec16 4.1.9 (#2449)
* Anti-analysis bypass
   - JADX fallback to DEX files on APK decompilation failure
   - apktool fallback to androguard for AndroidManifest.xml extraction
   - apksigner.jar fallback to apksigtool/androguard for signature version extraction
   - Graceful erorrs for failures instead of exceptions
2024-11-11 15:44:03 -08:00
Ajin Abraham 70e243d661 4.1.8 (#2448)
* APKID QA.
* Bash and Batch file script QA.
* Android Report template optimizations on how exported components are displayed.
* Clickable Android Activities, Services, Providers and Recievers.
* Updated Android version support to 11.0 for Android Studio AVD.
* Created helper scripts for AVDs `scripts/start_avd.sh` and `scripts/start_avd.ps1`.
2024-11-10 00:44:20 -08:00
Ajin Abraham 76596e33ed docker compose QA, explict requests timeout (#2447)
* Dependency update
* Explicit timeout for all requests
* Support proxy for all http(s) calls
* Optimize jadx download, support system proxy
2024-11-08 17:05:49 -08:00
Ajin Abraham ee2cb73824 Add support for pulling split apks, Fixes #2271 (#2446)
* Add support for pulling split apks from device, Fixes #2271
* Replace Quark with Behaviour analysis using quark rules
2024-11-07 19:34:37 -08:00
Ajin Abraham e5af3a8219 4.1.5 (#2445)
* Support custom home from environment variables
* Reduce iOS binary findings severity to warning from high
* Code QA and dependency updates
* docker-compose QA, added example nginx config
* Added docker-compose_swarm.yml by @antonkap add support for docker secrets
* IPA PNG Uncrush support for Windows and Linux #2397
2024-11-06 22:59:01 -08:00
Ajin Abraham e4406e9479 [HOTFIX] + Features (#2444)
Add support for sample download in recent scans.
Bug fix in firebase analysis (dict mutation errors)
2024-11-05 18:14:56 -08:00
Ajin Abraham 17f3f028ff HOTFIX: Libsast bump (#2443)
* Libsast bump
* Bump libsast to address match case
2024-11-04 13:06:11 -08:00
Ajin Abraham 6947649b18 Multiple Features (Scan timeout, Firebase Remote Config, Search Scans) (#2441)
Support time out for SAST and Binary scans
Search by MD5, package name, file name and app name.
Search REST API + docs + tests
Firebase remote config check [FEATURE] Add support for Firebase Remote Config information  #2429
autopep8
2024-10-29 00:51:13 -07:00
Ajin Abraham 9b2a3c8552 [HOTFIX] Dockerfile and dependency upgrade, Bug Fixes (#2439)
* Dockerfile: migrate from Ubuntu to Debian Bookworm
* Update and MachO and ELF Analysis
* Update docker compose with postgres
* JDK bump to 22.0.2
* Python bump to 3.12
* Bump jadx, apktool, vd2svg, bundletool
* Remove jadx from repo and download it dynamically during setup
* Install jadx during docker build
* Replace deprecated dependencies
* Bump httptools
* Postgres Support by default
* Bump LIEF to latest, reintroduce PIE checks for ELF
* Fixes #2430 #2432 #2395
* Bug Fixes
2024-10-28 02:36:51 -07:00
Ajin Abraham fec37069f3 [HOTFIX] dep bups + Fix #2424 2024-10-08 16:45:20 -07:00
Ajin Abraham 8ebe4982d9 Bump deps (#2426) 2024-09-20 08:57:30 -07:00
Ajin Abraham cc625fe843 [SECURITY][HOTFIX] Fixes GHSA-4hh3-vj32-gr6j (#2421)
* Fixes GHSA-4hh3-vj32-gr6j
* update SECURITY.md
* update dependencies
2024-08-18 02:07:14 -07:00
Ajin Abraham 5b7c5c0075 [EFR][HOTFIX] Realtime Scan status and logs (#2416)
* Realtime Scan Status in UI and PDF reports
* Scan Status REST API & tests
* Fixes #2414
* Address #2413
* Code QA
* Dependency and version bump
2024-08-04 12:07:38 -07:00
Ajin Abraham 1fdc718b07 Update SECURITY.md (#2418) 2024-07-31 11:57:39 -07:00
Ajin Abraham a9de0335d4 [HOTFIX] AppSec PNW 2024, Deeplink Trigger Support for Android Dynamic Analyzer (#2402)
* iOS  Dynamic Analyzer String Compare Frida script improvement
* Android Dynamic Analyzer Deeplink UI trigger support 
* Android & iOS Dynamic Analyzer UI Improvements
* Android & iOS Dynamic Analyzer Bug fixes
2024-07-25 21:30:09 -07:00
Ajin Abraham 39ba3e64be [HOTFIX] Code QA (#2393)
* QA
* Add new android rule setAllow*FromFileURLs
* android root bypass and debugger bypass scripts improvements
* Dockerfile qa
* prevent entrypoint exit if username already exists
2024-06-02 16:37:00 -07:00
Ajin Abraham 680ca5d302 [HOTFIX] Support AAB with MobSF, Convert AAB to APK, Fixes #2387 (#2391)
* AAB to APK conversion
* relative urls fix for recent scan
2024-05-24 20:46:23 -07:00
Ajin Abraham cf390e2863 Merge branch 'master' into master 2024-05-24 12:34:44 -07:00
Ajin Abraham aeba044014 [HOTFIX] SSO Support hosts behind proxy (#2390)
* Added support for proxy setup and custom SP host
2024-05-23 13:05:27 -07:00
Ajin Abraham b46c0037ac [EFR][HOTFIX] SSO Support + Okta SSO Documentation (#2389)
* Add support for SSO with SAML2.0
* Bump Deps
* Docs Updated
* Bump MobSF version
2024-05-22 21:27:49 -07:00
Ajin Abraham 76187b805f [EFR] AuthZ and AuthN for MobSF + Bug Fixes (#2366)
Authentication and Authorization (`Maintainer` , Viewer`) support in MobSF
* Basic User Management
* Bug Fixes in Runtime Executable Tampering
* Ratelimiting support for login endpoint
* Disable AuthZ/AuthN for REST API and also via ENV VAR `MOBSF_DISABLE_AUTHENTICATION=1`
* Bug Fix #2285 
* Bug Fix Icon Analysis Nonetype
* Update SSRF Filter
* Dependency Bump
* Beta to Stable release from V4
* Runs with DEBUG=False
* New home screen UI
2024-05-21 10:08:01 -07:00
Ajin Abraham 4549ebd9d7 Update home.py 2024-05-20 10:30:07 -07:00
Ajin Abraham 7ee126639e Lint fixes 2024-05-20 10:20:53 -07:00
Ajin Abraham 31026cbacd Update auto-comment.yml 2024-05-03 20:08:42 -07:00
Ajin Abraham 126eb78c3a Update CONTRIBUTING.md 2024-05-03 20:08:06 -07:00
Ajin Abraham 84d52a999a Update SUPPORT.md (#2384) 2024-05-03 20:07:25 -07:00
Ajin Abraham fb853e8865 Update bug_report.md 2024-05-03 20:06:20 -07:00
Ajin Abraham 485d31f1ac Update README.md (#2383) 2024-05-03 20:02:09 -07:00
Ajin Abraham 99977da400 Update SECURITY.md 2024-04-03 21:50:07 -07:00
Ajin Abraham 43bb71d115 [HOTFIX][SECURITY] Fixes an SSRF vulnerability report from positive technologies (#2373)
Address: https://github.com/MobSF/Mobile-Security-Framework-MobSF/security/advisories/GHSA-wpff-wm84-x5cx
2024-04-03 21:47:14 -07:00
Ajin Abraham ccfedc0e45 HOTFIX: Possible SSRF 2024-03-23 19:15:30 -07:00
Ajin Abraham 482bda913f Update SECURITY.md 2024-03-22 17:11:10 -07:00
Ajin Abraham 356895c611 Update SECURITY.md (#2365) 2024-03-22 17:10:34 -07:00
Ajin Abraham 3a7d12488c Update SECURITY.md (#2364) 2024-03-22 17:03:04 -07:00
Ajin Abraham 5056a7d660 HOTFIX: Remove Androguard dependency use only features required by MobSF (#2363)
This PR strips out androguard and it's dependencies from MobSF.
Extract androguard related functions used by MobSF.
Some dependencies such as pyQt5 from apkinspector is breaking the ARM64 docker image.
This should address that issue.
In future, we will have to copy over any fixes to axml, apk, public, types from androguard and ZipEntry from apkinspector. 
We won't be adding linting to these files. The extracted functions will be considered as an external tool.
2024-03-22 15:30:05 -07:00
Ajin Abraham 4417da03ba poetry pyqt5 fixes (#2362)
* poetry pyqt5 fixes

* QA

* fix

* Cert analysis qa

* QA

* pin pyqt5
2024-03-22 13:52:04 -07:00
Ajin Abraham 34473d3dac HOTFIX: Individual image publish 2024-03-19 17:31:05 -07:00
Ajin Abraham d4e67866e4 Fix #2349 2024-03-18 18:28:11 -07:00
Ajin Abraham 29df4f2f03 Runtime Exec Tampering Detection, iOS Dynamic REST APIs, Datatables Export (#2339)
* Runtime Executable Tampering Detection

* Add security.py

* Code QA Performance

* Code QA Runtime EXEC tampering detection

* Corellium API QA + Domain support

* REST API Docs + Datatables export
2024-02-09 18:42:00 -08:00
Ajin Abraham da7d1eec09 [HOTFIX][SECURITY] Fix an LFI, DSA Pub Key parsing bug and dependencies (#2326)
* [SECURITY] Fixes an LFI reported by @0x33c0unt - A crafted APK resource with icon name containing arbitrary path will get copied by MobSF as the icon file to the download directory which is available under `/download/` route. Fixed by https://github.com/MobSF/Mobile-Security-Framework-MobSF/commit/a58f8a8c0aa49e1581d97e19e8e2255ca96cd838
* Fixes #2324 , Bug in parsing DSA Public Key parameters for fingerprint calculation.
* Update dependencies
2024-01-13 20:00:46 -08:00
Ajin Abraham e67ceeba82 Update SECURITY.md (#2323)
updated security policy
2024-01-10 22:36:51 -08:00
Ajin Abraham b6287be97a GPT Goodness (#2318)
* QA
* Version Bump
2024-01-10 22:07:21 -08:00
Ajin Abraham efb779461e Update submodule 2024-01-06 23:17:06 -08:00
Ajin Abraham 19c1b55c2c HOTFIX: update apktool, fixes a security issue GHSA-2hqv-2xv4-5h5w 2024-01-06 20:12:47 -08:00
Ajin Abraham 9f0467c370 Bug Fix and QA (#2315)
* Bug Fix
* QA
* Version bumps
2023-12-28 01:36:41 -08:00
Ajin Abraham 334231140f [HOTFIX] Malware Permission Check for Android, API Rules + Version Bump (#2313)
* Malware Permission Check for Android
* New Android API rule to support Passkeys
* Updated Readme
* Version Bump
2023-12-22 17:17:10 -08:00
Ajin Abraham b48276a5b6 Multiple Features Improved or Added (#2310)
* Android added App Link assetlinks.json check
* Added more new permission mappings
* Updated Permission database
* Improved Source code view content search
* Added upstream proxy support for Corellium API calls
* Updated Readme
2023-12-19 17:29:50 -08:00
Ajin Abraham 1f8c6099bb [HOTFIX] ChatGPT Permission Mapping + Improved Description (#2308)
* Android Permission Mapping, generated with ChatGPT + axplorer. Addressed #1772 
* Android Permission description enhancement generated with ChatGPT
* Added new permissions to permission analyzer
2023-12-18 00:23:12 -08:00
Ajin Abraham c6f037103d Bug Fixes + Improvements (#2307)
* Replace Android test APK
* Added tests for Library analysis from binary (scan_library route)
* iOS merge findings from swift and objective c rules with same rule identifier. Fixes #2287 
* iOS Binary analysis, sort regex matches. Fixes #2252
* Framework dylibs with no extensions to skip PIE checks. Fixes #2307
* Select correct network_security config. Fixes #2049
* Android Manifest Analysis added support for detecting task hijacking (StrandHogg 1.0 and StrandHogg 2.0) . Fixes #2124
* Added new manifest analysis rule to warn on apps targeting older Android OS
* Updated severity of findings
* UI improvement for AppSec dashboard to show a loader
* UI changes in Static Analysis to collapse large no of files in API and Code Analysis for better real estate
* Improved certificate file analysis for android, jar, aar, and ios
* MobSF version Bump
2023-12-16 22:19:09 -08:00
Ajin Abraham 78e9563f90 [EFR][HOTFIX] QA Request (#2306)
* Scan independent library file (.so, .dylib, Framework dylib) from APK/IPA Static Analysis Report
* Library analysis refactored relative path helper for Django template.
* Re-introduced RELRO checks for Android, added Dart binary check to avoid Flutter false positives.
* Improved stripped debug symbol check for ELF and MachO using native OS tools such as nm and objdump when available.
* Merge iOS Framework and Dylib Analysis.
2023-12-16 13:37:34 -08:00
Ajin Abraham d3b02143fe [HOTFIX] RPC hook suggestions + Bug Fix (#2301)
* String compare script improvements
* Fix iOS Frida script bugs
* Added RPC helpers for hook suggestion (TODO:Expose to UI)
* Code QA
2023-12-06 18:14:45 -08:00