PoC-Deployer-System
1.5.7 · GitHub
More about this app
Exploits CVE-2024-31317 for Zygote injection, integrating remote terminal and file transfer capabilities
PoC-Deployer-System
English | 中文
基于 CVE-2024-31317 的 Zygote 注入工具制作的可视化工具,集成远程终端和文件传输。
Binder-CLI - 通过 binder 访问系统服务
截图
| UID/GID 注入 | 高级功能 | 反向 Shell |
|---|---|---|
![]() |
![]() |
![]() |
快速开始
环境要求
- Android 9-13,安全补丁 2024.6 之前
- 已激活 Shizuku
- 特殊设备需关闭厂商限制(MIUI/ColorOS/OriginOS)
使用步骤
- 安装 Shizuku 并激活
- 安装应用,授予 Shizuku 权限
- 配置目标参数(UID/GID/SELinux上下文)
- 启动远程终端(反弹shell)
- 连接反向 Shell:
stty raw -echo; nc 127.0.0.1 8080; stty sane
功能
| 功能 | 说明 |
|---|---|
| Zygote 注入 | 通过 hidden_api_blacklist_exemptions 实现 |
| 远程终端 | 完整 PTY,支持窗口调整 |
| 应用数据传输 | 速度 50-100 MB/s |
| 访问控制 | UID 白名单 |
端口说明
| 端口 | 用途 | 认证 |
|---|---|---|
| 8080 | 本地反弹shell | 本地UID白名单 |
| 8081 | 控制接口 | MD5密钥 |
| 56423 | 文件接收 | 本地 |
8081控制命令
EXEC <cmd> - 执行命令
STATUS - 系统状态
POLICY_ADD <uid> - 添加白名单
POLICY_LIST - 查看白名单
SEND_APP_DIR - 发送应用目录
故障排查
# 检查进程
ps -A | grep zYg0te
# 检查端口
netstat -tlnp | grep 56423
# 查看日志
logcat -s FolderReceiver:*
免责声明
仅用于安全研究,禁止非法用途。使用者承担全部责任。
致谢
How Shizuku is used
Can deploy payloads, grant secure permission and control Settings via `pm grant` and `am start` through Shizuku.
This is an AI-assisted analysis of Shizuku-related usages in the app's public source code. It is best effort, so it may not catch every single usage.
How this app uses Shizuku
Shizuku is used to run elevated shell commands that prepare and trigger payload injection.
- Deploy exploit payload: The command or payload text chosen in the app is written to protected storage with a shell redirect through Shizuku, then activated by restarting the system Settings app.
- Grant secure permission: The app grants itself the secure settings permission with the
pm grantshell command through Shizuku so it can write the global settings value used for injection. - Control Settings app: The Settings app is stopped and relaunched with the
am force-stopandam startshell commands through Shizuku around the payload write. - Start background services: Background helpers for policy and terminal access are launched with a Shizuku shell and stopped by sending a stop signal to the local port through Shizuku.
- Manage access list: UIDs chosen in the authorization list are written to a system owned allowlist with a Shizuku shell redirect and made accessible with the
chmodshell command through Shizuku.
Android APIs or commands used
pm grantam force-stopam startchmodnetcat
Notable details
The interactive terminal screen and its local setup commands run as the app itself without Shizuku; only payload preparation, permission grant, Settings control, background service launch and allowlist update use the Shizuku shell path.
Changelog
What's new for version 1.5.7
我好像不想写更新内容呢(
Permissions
9 permissions requested


