# A tale of finding Android 0days By @Chal13W1zz ![](https://i.imgur.com/U73LsVX.png) <!-- ![image alt](https://www.researchgate.net/profile/Kirthika-B-2/publication/327387842/figure/fig1/AS:666401400430592@1535893883636/Evolution-of-Android-OS.png) --> --- --- ### Who am I? - <code class="blue">Am a jack of all trades :smiling_face_with_smiling_eyes_and_hand_covering_mouth: </code> - <code class="blue">I :heart: Android and ARM assembly </code> - <code class="blue">I use Parrot OS :cat:</code> ![](https://i.imgur.com/75ufgjp.png) --- ### Why hunt for Android 0days? :thinking_face: 1. Heavy bounty rewards :money_mouth_face: 2. Opensource, welcoming to hobbyists & researchers :books: 3. Rich people problems in IOS :broken_heart: 4. Well Documented with a supportive community :hugging_face: ![](https://i.imgur.com/vyN4FJt.png) --- ### Basics :yum: - Basic Memory Corruption Bugs - Languages (C , C++, Some assembly, Java, and English [optional]) - 8+ RAM, 50+ HDD , good internet ++ <code class="orange">Let us begin :tada:</code> ![](https://media.giphy.com/media/3bJHkntbTQIoakG3Mj/giphy.gif) --- ### Where Do I start? :cry: ![](https://media.giphy.com/media/3ofSBaX5R943uhfhle/giphy.gif) - Read dislosed reports p0, CTFs, google :) - Set up your lab (install build tools, get source) --- ### Where Do I start ctd... - SyzKaller (mailing list sub) - Read Security Bulletins - changelogs and patch diffing - Twitter - Stalk Other Researchers :eyes: --- ### My Hunting Methodology :bow_and_arrow: ![](https://media.giphy.com/media/3oriNLx3dUqFgVi86I/giphy.gif) - Read write ups and RCAs - kernel pull, sync and diff - Kernel browse (bootlin) [Time Travel] - Versioned Exploit --- ### Android Priviledge Escalation ![](https://i.imgur.com/i4fxq6w.png) ___ --- ## UAF Analogy ![](https://i.imgur.com/v5TUEdO.png) --- ## 0day/Nday? https://github.com/Chal13W1zz/bad-binder Demo --- ### Socials? :sheep: https://linktr.ee/chal13w1zz Twitter : https://twitter.com/Chal13W1zz ![](https://media.giphy.com/media/KEHi4pArjMWOSnpQfh/giphy.gif) --- ## Q & A :) Now you know how to the FBI :crossed_swords: ![](https://media.giphy.com/media/26FPOogenQv5eOZHO/giphy.gif)
{"metaMigratedAt":"2023-06-17T06:59:34.534Z","metaMigratedFrom":"YAML","title":"A tale of finding Android 0days","breaks":false,"description":"View the slide with \"Slide Mode\" or \"View Mode\".","slideOptions":"{\"transition\":\"fade\"}","contributors":"[{\"id\":\"75e61295-b6f5-4254-be45-560b6b402ebd\",\"add\":5831,\"del\":3300}]"}
    618 views