ShizuStore

PoC-Deployer-System

wqry085

1.5.7 · GitHub

Download APK
Miscellaneous Android 9+ 9 months ago MIT
35 ShizuStore
2.2k GitHub
88 Stars
9 MB Size

More about this app

Exploits CVE-2024-31317 for Zygote injection, integrating remote terminal and file transfer capabilities

PoC-Deployer-System

License: MIT Android

English | 中文

基于 CVE-2024-31317 的 Zygote 注入工具制作的可视化工具,集成远程终端和文件传输。

Binder-CLI - 通过 binder 访问系统服务

截图

UID/GID 注入 高级功能 反向 Shell
注入 高级 Shell

快速开始

环境要求

  • Android 9-13,安全补丁 2024.6 之前
  • 已激活 Shizuku
  • 特殊设备需关闭厂商限制(MIUI/ColorOS/OriginOS)

使用步骤

  1. 安装 Shizuku 并激活
  2. 安装应用,授予 Shizuku 权限
  3. 配置目标参数(UID/GID/SELinux上下文)
  4. 启动远程终端(反弹shell)
  5. 连接反向 Shell:
stty raw -echo; nc 127.0.0.1 8080; stty sane

功能

功能 说明
Zygote 注入 通过 hidden_api_blacklist_exemptions 实现
远程终端 完整 PTY,支持窗口调整
应用数据传输 速度 50-100 MB/s
访问控制 UID 白名单

端口说明

端口 用途 认证
8080 本地反弹shell 本地UID白名单
8081 控制接口 MD5密钥
56423 文件接收 本地

8081控制命令

EXEC <cmd>       - 执行命令
STATUS           - 系统状态
POLICY_ADD <uid> - 添加白名单
POLICY_LIST      - 查看白名单
SEND_APP_DIR     - 发送应用目录

故障排查

# 检查进程
ps -A | grep zYg0te
# 检查端口
netstat -tlnp | grep 56423
# 查看日志
logcat -s FolderReceiver:*

免责声明

仅用于安全研究,禁止非法用途。使用者承担全部责任。

致谢

https://github.com/Webldix

Close

How Shizuku is used

Can deploy payloads, grant secure permission and control Settings via `pm grant` and `am start` through Shizuku.

This is an AI-assisted analysis of Shizuku-related usages in the app's public source code. It is best effort, so it may not catch every single usage.

How this app uses Shizuku

Shizuku is used to run elevated shell commands that prepare and trigger payload injection.

  • Deploy exploit payload: The command or payload text chosen in the app is written to protected storage with a shell redirect through Shizuku, then activated by restarting the system Settings app.
  • Grant secure permission: The app grants itself the secure settings permission with the pm grant shell command through Shizuku so it can write the global settings value used for injection.
  • Control Settings app: The Settings app is stopped and relaunched with the am force-stop and am start shell commands through Shizuku around the payload write.
  • Start background services: Background helpers for policy and terminal access are launched with a Shizuku shell and stopped by sending a stop signal to the local port through Shizuku.
  • Manage access list: UIDs chosen in the authorization list are written to a system owned allowlist with a Shizuku shell redirect and made accessible with the chmod shell command through Shizuku.

Android APIs or commands used

  • pm grant
  • am force-stop
  • am start
  • chmod
  • netcat

Notable details

The interactive terminal screen and its local setup commands run as the app itself without Shizuku; only payload preparation, permission grant, Settings control, background service launch and allowlist update use the Shizuku shell path.

Close

Changelog

What's new for version 1.5.7

我好像不想写更新内容呢(

Close

Permissions

9 permissions requested

  • android.permission.ACCESS_NETWORK_STATE
  • android.permission.WRITE_SECURE_SETTINGS
  • android.permission.INTERNET
  • android.permission.FORCE_STOP_PACKAGES
  • android.permission.READ_LOGS
  • android.permission.READ_EXTERNAL_STORAGE
  • android.permission.WRITE_EXTERNAL_STORAGE
  • moe.shizuku.manager.permission.API_V23
  • com.wqry085.deployesystem.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION
Close