Hacking Mobile Platforms Flashcards

1
Q

Which of the following is not an OWASP Top 10 Mobile Risk?

Buffer overflow
Reverse engineering
Insecure communication
Insecure cryptography

A

Buffer overflow

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

On android, which of the following Java API framework blocks manages the data sharing between applications?

Notification manager
Content providers
Window manager
Activity manager

A

Content providers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Which of the following is an Android banking Trojan that uses a malicious SMS to compromise the security of a target mobile device by dynamically loading web views and targeting specific domains based on received commands?

Fing
xHelper
Gustuff
cSploit

A

Gustuff

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is xHelper?

A

Android/Trojan.Dropper.xHelper is a variant of Android/Trojan.Dropper. The first noticeable characteristic of xHelper is the use of stolen package names. For instance, xHelper uses package names starting with “com.muf.”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is cSploit?

A

cSploit is an Android network analysis and penetration suite that is used to map the local network, fingerprint hosts’ operating systems and open ports, perform integrated traceroute, forge TCP/UDP packets, and perform MITM attacks such as password sniffing, JavaScript injection, capturing real-time network traffic, DNS spoofing, and session hijacking

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is TunesGo?

A

TunesGo is an android tool that has an advanced android root module that recognizes and analyzes your Android device and chooses an appropriate Android-root-plan for it automatically.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is zANTI?

A

zANTI is an android application that acts as a pentesting toolkit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is DroidSheep?

A

DroidSheep is a simple Android tool for web session hijacking (sidejacking)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is ORBOT?

A

Orbot is a proxy app that empowers other apps to use the internet more privately. It uses Tor to encrypt your Internet traffic and then hides it by bouncing through a series of computers around the world. Attackers can use this application to hide their identity while performing attacks or surfing through the target web applications.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are Velonzy, TaiG and Yalu?

A

iOS Jailbreaking Tools

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is X-Ray?

A

X-Ray is an android vulnerability scanner

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is Spyzie?

A

Spyzie is an iOS spyware tool to gather SMS logs, call logs, app chats, GPS, etc.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is Apricot?

A

Apricot is a web-based mirror OS for iPhone. It supports iOS 13.2 devices. Users can run this mirror iOS version with the default iOS 13.2 simultaneously

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is Hexxa Plus?

A

Hexxa Plus is a Jailbreak Repo Extractor for iOS 13.2, which allows you to install themes, tweaks, and apps. It is compatible with iOS 13 and higher versions up to iOS 13.2.3 including iOS 13.3 beta

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is Trident?

A

Trident is a sophisticated spyware that exploits vulnerabilities in an iPhone to spy on users. These vulnerabilities allow attackers to jailbreak the target iPhone remotely and install malicious spyware such as Pegasus. Trident is capable of taking complete control of the target mobile device, and it allows attackers to monitor and track all the user activities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is Core OS?

A

This layer on iOS contains low-level features on which most other technologies are based. Frameworks in this layer are useful when dealing explicitly with security or communicating with an external hardware and networks. The services provided by this layer are dependent on the Kernel and Device Drivers layer

17
Q

What is Core Services?

A

This layer contains fundamental system services for apps. The key services are Core Foundation and Foundation frameworks (define the basic types that all apps use). Individual technologies that support features such as social media, iCloud, location, and networking belong to this layer

18
Q

What is a semi-tethered jailbreak?

A

A semi-tethered jailbreak is one which a jailbreak tool applies to an iOS device, which will be lost and need to be re-applied on reboot.

19
Q

What is an untethered jailbreak?

A

A persistent jailbreak which lasts through reboots

20
Q

What is XenMobile?

A

An MDM (Citrix XenMobile / Citrix Endpoint Management)