Giter Site home page Giter Site logo

xamarin-security-scanner's Introduction

header

A tool to find security vulnerabilities in Xamarin.Android apps. It finds vulnerabilities by analyzing the source code (SAST).

It is inspired by and contains code from QARK (Quick Android Review Kit).

Getting Started

The quickest way to get started is to use Docker.

git clone <project_url>
cd xamarin-security-scanner
docker build ./XamarinSecurityScanner -t xamarin-security-scanner
docker run -v <absolute_path_to_project>:/project xamarin-security-scanner

Another option is to install .NET Core 2.2, and run the following commands:

git clone <project_url>
cd xamarin-security-scanner
dotnet run --project .\XamarinSecurityScanner\XamarinSecurityScanner.App --path <path_to_project>

Example output:

screenshot

Usage

Usage: XamarinSecurityScanner.App [options]

Options:
  -p|--path <PATH>                Path to scan
  -t|--threshold <THRESHOLD>      Vulnerability threshold
  -e|--enable-logging             Enable logging
  -i|--ignore-file <IGNORE_FILE>  Path to ignore file
  -?|-h|--help                    Show help information

For more information on how to use the Xamarin Security Scanner, see the configuration docs.

Functionality

The tool reports the following issues:

  • Certificate validation overwritten
  • Permissions may not be enforced
  • Unsafe cipher mode used
  • External storage is used
  • Hardcoded HTTP URL found
  • JavaScript enabled in WebView
  • JavascriptInterface is added to a WebView
  • Logging was found
  • Access to phone number
  • WorldReadable file found
  • Backups are enabled
  • App has debugging enabled
  • App supports outdated Android version
  • App contains a private key

Credits

Marco Kuiper (@marcofolio) - For the logo.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.