Mobile Hacking
Android and iOS hacking aligned with the OWASP Mobile Application Security Verification Standard (MASVS).
Overview
- •Setting up the environment (Android Studio, Xcode, Genymotion, Firebase)
- •Crafting and distributing malicious payloads
- •iOS development with Swift and Xcode
- •Rooting Android and jailbreaking iOS devices
- •Hands-on practice labs
Select your module(s)
You can select the modules you want to learn. There's a recommended order in the learning curve, unless you already know something and want to go further.
Basic tool set up. To run an environment where we can work on our Mobile Hacking course, we must install some basic tools to perform the hack.
- Installing VM (Virtual Machine) — We must install a Virtual Machine on Windows or MAC to run our hacking tools in a safe environment.
- Installing Offensive Security Linux — At this stage, we will install the tool that will help us with our hacks later. We have many options, but we will refer this time to Kali Linux, Parrot Security, and UTM.
- Installing Android Studio — If we don't have an Android phone, we can use Android Studio to emulate it and for other technical purposes.
- Installing JDK Tools — If you have payload issues, the JDK Tool will help us with that, as it will enable the needed libraries to run them.
- Installing Swift for MAC/Windows — Apple created Swift, a programming language that built apps for Apple devices. It's a high-level, general-purpose language designed to be easy to learn.
- Installing Xcode for MAC — Xcode is Apple's integrated development environment for macOS, which is used to develop software for macOS, iOS, iPadOS, watchOS, tvOS, and visionOS.
- Installing Genymotion — Genymotion is an efficient Android emulator for testing Android applications. Learn about main concepts, from configuration to deploying a test application to the Emulator.
- Installing Firebase — Firebase provides detailed documentation and cross-platform app development SDKs, to help you build and ship apps for iOS, Android, the Web, Flutter, Unity, and C++.
- Linux Fundamentals — Before hacking, we have to learn the basics of commands.
In this module, we will understand the basic concepts of a malicious payload and how to create it and distribute it.
- Metasploit (meterpreter & postgresql) — Metasploit is a tool for exploitation. We will use "Msfvenom" to create our payloads.
- Tunneling (ngrok & apache) — Tunneling allows secure data transmission between networks. It's often used in virtual private networks (VPNs). We will use it as part of our backdoor.
- Developer Key — If we want our payload to work successfully on a device, we must sign our application first. So it can be downloaded and distributed by users.
In this course, we will learn the usage of Swift and Xcode. Languages that can help us in the future to hack and to understand better how internally works an iOS.
- Swift fundamentals — We will learn about the environment and how to use some functions.
- Xcode fundamentals — We will learn about the environment and how to use some functions.
iOS jailbreaking is the use of a privilege escalation exploit to remove software restrictions imposed by Apple on devices running iOS and iOS-based operating systems. It is typically done through a series of kernel patches.
- Jailbreaking iOS — We will learn the process of jailbreaking an iOS device.
- Rooting Android — We will learn the process of rooting an Android device.
We will put everything into practice. We have CTFs in different situations to make them as authentic as possible.
- CTFs — Virtual Machines (mobile emulators) and real mobile hacking at your disposal!
$60,000 MXN in 4 weekly payments, or $40,000 MXN one-time (bank transfer or PayPal). 24 hours total (3h Sat / 3h Sun × 4 weeks). Before taxes.
Plan your training path
Tell us your team, schedule and modules of interest and we will reply with the next steps.
Request informationOnline enrollment is coming soon. In the meantime, contact us to enroll.
