├── .gitignore
├── .idea
├── .gitignore
├── artifacts
│ └── AndroidTest.xml
├── encodings.xml
├── misc.xml
├── uiDesigner.xml
└── vcs.xml
├── .mvn
└── wrapper
│ ├── maven-wrapper.jar
│ └── maven-wrapper.properties
├── README.md
├── mvnw
├── mvnw.cmd
├── out
└── artifacts
│ └── AndroidTest
│ ├── AndroidTest.jar
│ ├── apk-parser-2.5.3.jar
│ ├── javafx-base-17.0.2-win.jar
│ ├── javafx-base-17.0.2.jar
│ ├── javafx-controls-17.0.2-win.jar
│ ├── javafx-controls-17.0.2.jar
│ ├── javafx-fxml-17.0.2-win.jar
│ ├── javafx-fxml-17.0.2.jar
│ ├── javafx-graphics-17.0.2-win.jar
│ └── javafx-graphics-17.0.2.jar
├── pom.xml
└── src
└── main
├── java
├── com
│ └── example
│ │ └── androidtest
│ │ ├── HelloApplication.java
│ │ └── TestPage.java
├── controller
│ ├── AnalyseViewController.java
│ ├── HelloController.java
│ ├── LoadViewController.java
│ └── LoginController.java
├── module-info.java
└── utils
│ ├── ApkUtils.java
│ └── DataAnalyseUtils.java
└── resources
├── META-INF
└── MANIFEST.MF
└── com
└── example
└── androidtest
├── analyse-view2.fxml
├── hello-view.fxml
├── img.png
├── load-view.fxml
├── login-view.fxml
├── login_css.css
├── 危险权限.txt
├── 危险权限组.txt
└── 漏洞.txt
/.gitignore:
--------------------------------------------------------------------------------
1 | target/
2 | !.mvn/wrapper/maven-wrapper.jar
3 | !**/src/main/**/target/
4 | !**/src/test/**/target/
5 |
6 | ### IntelliJ IDEA ###
7 | .idea/modules.xml
8 | .idea/jarRepositories.xml
9 | .idea/compiler.xml
10 | .idea/libraries/
11 | *.iws
12 | *.iml
13 | *.ipr
14 |
15 | ### Eclipse ###
16 | .apt_generated
17 | .classpath
18 | .factorypath
19 | .project
20 | .settings
21 | .springBeans
22 | .sts4-cache
23 |
24 | ### NetBeans ###
25 | /nbproject/private/
26 | /nbbuild/
27 | /dist/
28 | /nbdist/
29 | /.nb-gradle/
30 | build/
31 | !**/src/main/**/build/
32 | !**/src/test/**/build/
33 |
34 | ### VS Code ###
35 | .vscode/
36 |
37 | ### Mac OS ###
38 | .DS_Store
--------------------------------------------------------------------------------
/.idea/.gitignore:
--------------------------------------------------------------------------------
1 | # Default ignored files
2 | /shelf/
3 | /workspace.xml
4 | # Editor-based HTTP Client requests
5 | /httpRequests/
6 | # Datasource local storage ignored files
7 | /dataSources/
8 | /dataSources.local.xml
9 |
--------------------------------------------------------------------------------
/.idea/artifacts/AndroidTest.xml:
--------------------------------------------------------------------------------
1 |
2 |
3 | $PROJECT_DIR$/out/artifacts/AndroidTest
4 |
5 |
6 |
7 |
8 |
9 |
10 |
11 |
12 |
13 |
14 |
15 |
16 |
17 |
18 |
19 |
20 |
21 |
22 |
23 |
24 |
25 |
26 |
27 |
28 |
29 |
30 |
--------------------------------------------------------------------------------
/.idea/encodings.xml:
--------------------------------------------------------------------------------
1 |
2 |
3 |
4 |
5 |
6 |
7 |
--------------------------------------------------------------------------------
/.idea/misc.xml:
--------------------------------------------------------------------------------
1 |
2 |
3 |
4 |
9 |
10 |
11 |
12 |
13 |
--------------------------------------------------------------------------------
/.idea/uiDesigner.xml:
--------------------------------------------------------------------------------
1 |
2 |
3 |
4 |
5 | -
6 |
7 |
8 | -
9 |
10 |
11 | -
12 |
13 |
14 | -
15 |
16 |
17 | -
18 |
19 |
20 |
21 |
22 |
23 | -
24 |
25 |
26 |
27 |
28 |
29 | -
30 |
31 |
32 |
33 |
34 |
35 | -
36 |
37 |
38 |
39 |
40 |
41 | -
42 |
43 |
44 |
45 |
46 | -
47 |
48 |
49 |
50 |
51 | -
52 |
53 |
54 |
55 |
56 | -
57 |
58 |
59 |
60 |
61 | -
62 |
63 |
64 |
65 |
66 | -
67 |
68 |
69 |
70 |
71 | -
72 |
73 |
74 | -
75 |
76 |
77 |
78 |
79 | -
80 |
81 |
82 |
83 |
84 | -
85 |
86 |
87 |
88 |
89 | -
90 |
91 |
92 |
93 |
94 | -
95 |
96 |
97 |
98 |
99 | -
100 |
101 |
102 | -
103 |
104 |
105 | -
106 |
107 |
108 | -
109 |
110 |
111 | -
112 |
113 |
114 |
115 |
116 | -
117 |
118 |
119 | -
120 |
121 |
122 |
123 |
124 |
--------------------------------------------------------------------------------
/.idea/vcs.xml:
--------------------------------------------------------------------------------
1 |
2 |
3 |
4 |
5 |
6 |
--------------------------------------------------------------------------------
/.mvn/wrapper/maven-wrapper.jar:
--------------------------------------------------------------------------------
https://raw.githubusercontent.com/Bamboo-fly/Android-Vulnerability-Analysis/e2f7d7f81419a816a77aa1b9f4439d7c0ce18179/.mvn/wrapper/maven-wrapper.jar
--------------------------------------------------------------------------------
/.mvn/wrapper/maven-wrapper.properties:
--------------------------------------------------------------------------------
1 | distributionUrl=https://repo.maven.apache.org/maven2/org/apache/maven/apache-maven/3.8.5/apache-maven-3.8.5-bin.zip
2 | wrapperUrl=https://repo.maven.apache.org/maven2/org/apache/maven/wrapper/maven-wrapper/3.1.0/maven-wrapper-3.1.0.jar
--------------------------------------------------------------------------------
/README.md:
--------------------------------------------------------------------------------
1 | # Android-Vulnerability-Analysis
2 | 基于JavaFX框架做的一款安卓漏洞分析桌面软件,采用了反编译技术与静态分析技术,上传apk包即可分析APP可能包含的风险。
3 |
--------------------------------------------------------------------------------
/mvnw:
--------------------------------------------------------------------------------
1 | #!/bin/sh
2 | # ----------------------------------------------------------------------------
3 | # Licensed to the Apache Software Foundation (ASF) under one
4 | # or more contributor license agreements. See the NOTICE file
5 | # distributed with this work for additional information
6 | # regarding copyright ownership. The ASF licenses this file
7 | # to you under the Apache License, Version 2.0 (the
8 | # "License"); you may not use this file except in compliance
9 | # with the License. You may obtain a copy of the License at
10 | #
11 | # https://www.apache.org/licenses/LICENSE-2.0
12 | #
13 | # Unless required by applicable law or agreed to in writing,
14 | # software distributed under the License is distributed on an
15 | # "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
16 | # KIND, either express or implied. See the License for the
17 | # specific language governing permissions and limitations
18 | # under the License.
19 | # ----------------------------------------------------------------------------
20 |
21 | # ----------------------------------------------------------------------------
22 | # Maven Start Up Batch script
23 | #
24 | # Required ENV vars:
25 | # ------------------
26 | # JAVA_HOME - location of a JDK home dir
27 | #
28 | # Optional ENV vars
29 | # -----------------
30 | # M2_HOME - location of maven2's installed home dir
31 | # MAVEN_OPTS - parameters passed to the Java VM when running Maven
32 | # e.g. to debug Maven itself, use
33 | # set MAVEN_OPTS=-Xdebug -Xrunjdwp:transport=dt_socket,server=y,suspend=y,address=8000
34 | # MAVEN_SKIP_RC - flag to disable loading of mavenrc files
35 | # ----------------------------------------------------------------------------
36 |
37 | if [ -z "$MAVEN_SKIP_RC" ] ; then
38 |
39 | if [ -f /usr/local/etc/mavenrc ] ; then
40 | . /usr/local/etc/mavenrc
41 | fi
42 |
43 | if [ -f /etc/mavenrc ] ; then
44 | . /etc/mavenrc
45 | fi
46 |
47 | if [ -f "$HOME/.mavenrc" ] ; then
48 | . "$HOME/.mavenrc"
49 | fi
50 |
51 | fi
52 |
53 | # OS specific support. $var _must_ be set to either true or false.
54 | cygwin=false;
55 | darwin=false;
56 | mingw=false
57 | case "`uname`" in
58 | CYGWIN*) cygwin=true ;;
59 | MINGW*) mingw=true;;
60 | Darwin*) darwin=true
61 | # Use /usr/libexec/java_home if available, otherwise fall back to /Library/Java/Home
62 | # See https://developer.apple.com/library/mac/qa/qa1170/_index.html
63 | if [ -z "$JAVA_HOME" ]; then
64 | if [ -x "/usr/libexec/java_home" ]; then
65 | export JAVA_HOME="`/usr/libexec/java_home`"
66 | else
67 | export JAVA_HOME="/Library/Java/Home"
68 | fi
69 | fi
70 | ;;
71 | esac
72 |
73 | if [ -z "$JAVA_HOME" ] ; then
74 | if [ -r /etc/gentoo-release ] ; then
75 | JAVA_HOME=`java-config --jre-home`
76 | fi
77 | fi
78 |
79 | if [ -z "$M2_HOME" ] ; then
80 | ## resolve links - $0 may be a link to maven's home
81 | PRG="$0"
82 |
83 | # need this for relative symlinks
84 | while [ -h "$PRG" ] ; do
85 | ls=`ls -ld "$PRG"`
86 | link=`expr "$ls" : '.*-> \(.*\)$'`
87 | if expr "$link" : '/.*' > /dev/null; then
88 | PRG="$link"
89 | else
90 | PRG="`dirname "$PRG"`/$link"
91 | fi
92 | done
93 |
94 | saveddir=`pwd`
95 |
96 | M2_HOME=`dirname "$PRG"`/..
97 |
98 | # make it fully qualified
99 | M2_HOME=`cd "$M2_HOME" && pwd`
100 |
101 | cd "$saveddir"
102 | # echo Using m2 at $M2_HOME
103 | fi
104 |
105 | # For Cygwin, ensure paths are in UNIX format before anything is touched
106 | if $cygwin ; then
107 | [ -n "$M2_HOME" ] &&
108 | M2_HOME=`cygpath --unix "$M2_HOME"`
109 | [ -n "$JAVA_HOME" ] &&
110 | JAVA_HOME=`cygpath --unix "$JAVA_HOME"`
111 | [ -n "$CLASSPATH" ] &&
112 | CLASSPATH=`cygpath --path --unix "$CLASSPATH"`
113 | fi
114 |
115 | # For Mingw, ensure paths are in UNIX format before anything is touched
116 | if $mingw ; then
117 | [ -n "$M2_HOME" ] &&
118 | M2_HOME="`(cd "$M2_HOME"; pwd)`"
119 | [ -n "$JAVA_HOME" ] &&
120 | JAVA_HOME="`(cd "$JAVA_HOME"; pwd)`"
121 | fi
122 |
123 | if [ -z "$JAVA_HOME" ]; then
124 | javaExecutable="`which javac`"
125 | if [ -n "$javaExecutable" ] && ! [ "`expr \"$javaExecutable\" : '\([^ ]*\)'`" = "no" ]; then
126 | # readlink(1) is not available as standard on Solaris 10.
127 | readLink=`which readlink`
128 | if [ ! `expr "$readLink" : '\([^ ]*\)'` = "no" ]; then
129 | if $darwin ; then
130 | javaHome="`dirname \"$javaExecutable\"`"
131 | javaExecutable="`cd \"$javaHome\" && pwd -P`/javac"
132 | else
133 | javaExecutable="`readlink -f \"$javaExecutable\"`"
134 | fi
135 | javaHome="`dirname \"$javaExecutable\"`"
136 | javaHome=`expr "$javaHome" : '\(.*\)/bin'`
137 | JAVA_HOME="$javaHome"
138 | export JAVA_HOME
139 | fi
140 | fi
141 | fi
142 |
143 | if [ -z "$JAVACMD" ] ; then
144 | if [ -n "$JAVA_HOME" ] ; then
145 | if [ -x "$JAVA_HOME/jre/sh/java" ] ; then
146 | # IBM's JDK on AIX uses strange locations for the executables
147 | JAVACMD="$JAVA_HOME/jre/sh/java"
148 | else
149 | JAVACMD="$JAVA_HOME/bin/java"
150 | fi
151 | else
152 | JAVACMD="`\\unset -f command; \\command -v java`"
153 | fi
154 | fi
155 |
156 | if [ ! -x "$JAVACMD" ] ; then
157 | echo "Error: JAVA_HOME is not defined correctly." >&2
158 | echo " We cannot execute $JAVACMD" >&2
159 | exit 1
160 | fi
161 |
162 | if [ -z "$JAVA_HOME" ] ; then
163 | echo "Warning: JAVA_HOME environment variable is not set."
164 | fi
165 |
166 | CLASSWORLDS_LAUNCHER=org.codehaus.plexus.classworlds.launcher.Launcher
167 |
168 | # traverses directory structure from process work directory to filesystem root
169 | # first directory with .mvn subdirectory is considered project base directory
170 | find_maven_basedir() {
171 |
172 | if [ -z "$1" ]
173 | then
174 | echo "Path not specified to find_maven_basedir"
175 | return 1
176 | fi
177 |
178 | basedir="$1"
179 | wdir="$1"
180 | while [ "$wdir" != '/' ] ; do
181 | if [ -d "$wdir"/.mvn ] ; then
182 | basedir=$wdir
183 | break
184 | fi
185 | # workaround for JBEAP-8937 (on Solaris 10/Sparc)
186 | if [ -d "${wdir}" ]; then
187 | wdir=`cd "$wdir/.."; pwd`
188 | fi
189 | # end of workaround
190 | done
191 | echo "${basedir}"
192 | }
193 |
194 | # concatenates all lines of a file
195 | concat_lines() {
196 | if [ -f "$1" ]; then
197 | echo "$(tr -s '\n' ' ' < "$1")"
198 | fi
199 | }
200 |
201 | BASE_DIR=`find_maven_basedir "$(pwd)"`
202 | if [ -z "$BASE_DIR" ]; then
203 | exit 1;
204 | fi
205 |
206 | ##########################################################################################
207 | # Extension to allow automatically downloading the maven-wrapper.jar from Maven-central
208 | # This allows using the maven wrapper in projects that prohibit checking in binary data.
209 | ##########################################################################################
210 | if [ -r "$BASE_DIR/.mvn/wrapper/maven-wrapper.jar" ]; then
211 | if [ "$MVNW_VERBOSE" = true ]; then
212 | echo "Found .mvn/wrapper/maven-wrapper.jar"
213 | fi
214 | else
215 | if [ "$MVNW_VERBOSE" = true ]; then
216 | echo "Couldn't find .mvn/wrapper/maven-wrapper.jar, downloading it ..."
217 | fi
218 | if [ -n "$MVNW_REPOURL" ]; then
219 | jarUrl="$MVNW_REPOURL/org/apache/maven/wrapper/maven-wrapper/3.1.0/maven-wrapper-3.1.0.jar"
220 | else
221 | jarUrl="https://repo.maven.apache.org/maven2/org/apache/maven/wrapper/maven-wrapper/3.1.0/maven-wrapper-3.1.0.jar"
222 | fi
223 | while IFS="=" read key value; do
224 | case "$key" in (wrapperUrl) jarUrl="$value"; break ;;
225 | esac
226 | done < "$BASE_DIR/.mvn/wrapper/maven-wrapper.properties"
227 | if [ "$MVNW_VERBOSE" = true ]; then
228 | echo "Downloading from: $jarUrl"
229 | fi
230 | wrapperJarPath="$BASE_DIR/.mvn/wrapper/maven-wrapper.jar"
231 | if $cygwin; then
232 | wrapperJarPath=`cygpath --path --windows "$wrapperJarPath"`
233 | fi
234 |
235 | if command -v wget > /dev/null; then
236 | if [ "$MVNW_VERBOSE" = true ]; then
237 | echo "Found wget ... using wget"
238 | fi
239 | if [ -z "$MVNW_USERNAME" ] || [ -z "$MVNW_PASSWORD" ]; then
240 | wget "$jarUrl" -O "$wrapperJarPath" || rm -f "$wrapperJarPath"
241 | else
242 | wget --http-user=$MVNW_USERNAME --http-password=$MVNW_PASSWORD "$jarUrl" -O "$wrapperJarPath" || rm -f "$wrapperJarPath"
243 | fi
244 | elif command -v curl > /dev/null; then
245 | if [ "$MVNW_VERBOSE" = true ]; then
246 | echo "Found curl ... using curl"
247 | fi
248 | if [ -z "$MVNW_USERNAME" ] || [ -z "$MVNW_PASSWORD" ]; then
249 | curl -o "$wrapperJarPath" "$jarUrl" -f
250 | else
251 | curl --user $MVNW_USERNAME:$MVNW_PASSWORD -o "$wrapperJarPath" "$jarUrl" -f
252 | fi
253 |
254 | else
255 | if [ "$MVNW_VERBOSE" = true ]; then
256 | echo "Falling back to using Java to download"
257 | fi
258 | javaClass="$BASE_DIR/.mvn/wrapper/MavenWrapperDownloader.java"
259 | # For Cygwin, switch paths to Windows format before running javac
260 | if $cygwin; then
261 | javaClass=`cygpath --path --windows "$javaClass"`
262 | fi
263 | if [ -e "$javaClass" ]; then
264 | if [ ! -e "$BASE_DIR/.mvn/wrapper/MavenWrapperDownloader.class" ]; then
265 | if [ "$MVNW_VERBOSE" = true ]; then
266 | echo " - Compiling MavenWrapperDownloader.java ..."
267 | fi
268 | # Compiling the Java class
269 | ("$JAVA_HOME/bin/javac" "$javaClass")
270 | fi
271 | if [ -e "$BASE_DIR/.mvn/wrapper/MavenWrapperDownloader.class" ]; then
272 | # Running the downloader
273 | if [ "$MVNW_VERBOSE" = true ]; then
274 | echo " - Running MavenWrapperDownloader.java ..."
275 | fi
276 | ("$JAVA_HOME/bin/java" -cp .mvn/wrapper MavenWrapperDownloader "$MAVEN_PROJECTBASEDIR")
277 | fi
278 | fi
279 | fi
280 | fi
281 | ##########################################################################################
282 | # End of extension
283 | ##########################################################################################
284 |
285 | export MAVEN_PROJECTBASEDIR=${MAVEN_BASEDIR:-"$BASE_DIR"}
286 | if [ "$MVNW_VERBOSE" = true ]; then
287 | echo $MAVEN_PROJECTBASEDIR
288 | fi
289 | MAVEN_OPTS="$(concat_lines "$MAVEN_PROJECTBASEDIR/.mvn/jvm.config") $MAVEN_OPTS"
290 |
291 | # For Cygwin, switch paths to Windows format before running java
292 | if $cygwin; then
293 | [ -n "$M2_HOME" ] &&
294 | M2_HOME=`cygpath --path --windows "$M2_HOME"`
295 | [ -n "$JAVA_HOME" ] &&
296 | JAVA_HOME=`cygpath --path --windows "$JAVA_HOME"`
297 | [ -n "$CLASSPATH" ] &&
298 | CLASSPATH=`cygpath --path --windows "$CLASSPATH"`
299 | [ -n "$MAVEN_PROJECTBASEDIR" ] &&
300 | MAVEN_PROJECTBASEDIR=`cygpath --path --windows "$MAVEN_PROJECTBASEDIR"`
301 | fi
302 |
303 | # Provide a "standardized" way to retrieve the CLI args that will
304 | # work with both Windows and non-Windows executions.
305 | MAVEN_CMD_LINE_ARGS="$MAVEN_CONFIG $@"
306 | export MAVEN_CMD_LINE_ARGS
307 |
308 | WRAPPER_LAUNCHER=org.apache.maven.wrapper.MavenWrapperMain
309 |
310 | exec "$JAVACMD" \
311 | $MAVEN_OPTS \
312 | $MAVEN_DEBUG_OPTS \
313 | -classpath "$MAVEN_PROJECTBASEDIR/.mvn/wrapper/maven-wrapper.jar" \
314 | "-Dmaven.home=${M2_HOME}" \
315 | "-Dmaven.multiModuleProjectDirectory=${MAVEN_PROJECTBASEDIR}" \
316 | ${WRAPPER_LAUNCHER} $MAVEN_CONFIG "$@"
317 |
--------------------------------------------------------------------------------
/mvnw.cmd:
--------------------------------------------------------------------------------
1 | @REM ----------------------------------------------------------------------------
2 | @REM Licensed to the Apache Software Foundation (ASF) under one
3 | @REM or more contributor license agreements. See the NOTICE file
4 | @REM distributed with this work for additional information
5 | @REM regarding copyright ownership. The ASF licenses this file
6 | @REM to you under the Apache License, Version 2.0 (the
7 | @REM "License"); you may not use this file except in compliance
8 | @REM with the License. You may obtain a copy of the License at
9 | @REM
10 | @REM https://www.apache.org/licenses/LICENSE-2.0
11 | @REM
12 | @REM Unless required by applicable law or agreed to in writing,
13 | @REM software distributed under the License is distributed on an
14 | @REM "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
15 | @REM KIND, either express or implied. See the License for the
16 | @REM specific language governing permissions and limitations
17 | @REM under the License.
18 | @REM ----------------------------------------------------------------------------
19 |
20 | @REM ----------------------------------------------------------------------------
21 | @REM Maven Start Up Batch script
22 | @REM
23 | @REM Required ENV vars:
24 | @REM JAVA_HOME - location of a JDK home dir
25 | @REM
26 | @REM Optional ENV vars
27 | @REM M2_HOME - location of maven2's installed home dir
28 | @REM MAVEN_BATCH_ECHO - set to 'on' to enable the echoing of the batch commands
29 | @REM MAVEN_BATCH_PAUSE - set to 'on' to wait for a keystroke before ending
30 | @REM MAVEN_OPTS - parameters passed to the Java VM when running Maven
31 | @REM e.g. to debug Maven itself, use
32 | @REM set MAVEN_OPTS=-Xdebug -Xrunjdwp:transport=dt_socket,server=y,suspend=y,address=8000
33 | @REM MAVEN_SKIP_RC - flag to disable loading of mavenrc files
34 | @REM ----------------------------------------------------------------------------
35 |
36 | @REM Begin all REM lines with '@' in case MAVEN_BATCH_ECHO is 'on'
37 | @echo off
38 | @REM set title of command window
39 | title %0
40 | @REM enable echoing by setting MAVEN_BATCH_ECHO to 'on'
41 | @if "%MAVEN_BATCH_ECHO%" == "on" echo %MAVEN_BATCH_ECHO%
42 |
43 | @REM set %HOME% to equivalent of $HOME
44 | if "%HOME%" == "" (set "HOME=%HOMEDRIVE%%HOMEPATH%")
45 |
46 | @REM Execute a user defined script before this one
47 | if not "%MAVEN_SKIP_RC%" == "" goto skipRcPre
48 | @REM check for pre script, once with legacy .bat ending and once with .cmd ending
49 | if exist "%USERPROFILE%\mavenrc_pre.bat" call "%USERPROFILE%\mavenrc_pre.bat" %*
50 | if exist "%USERPROFILE%\mavenrc_pre.cmd" call "%USERPROFILE%\mavenrc_pre.cmd" %*
51 | :skipRcPre
52 |
53 | @setlocal
54 |
55 | set ERROR_CODE=0
56 |
57 | @REM To isolate internal variables from possible post scripts, we use another setlocal
58 | @setlocal
59 |
60 | @REM ==== START VALIDATION ====
61 | if not "%JAVA_HOME%" == "" goto OkJHome
62 |
63 | echo.
64 | echo Error: JAVA_HOME not found in your environment. >&2
65 | echo Please set the JAVA_HOME variable in your environment to match the >&2
66 | echo location of your Java installation. >&2
67 | echo.
68 | goto error
69 |
70 | :OkJHome
71 | if exist "%JAVA_HOME%\bin\java.exe" goto init
72 |
73 | echo.
74 | echo Error: JAVA_HOME is set to an invalid directory. >&2
75 | echo JAVA_HOME = "%JAVA_HOME%" >&2
76 | echo Please set the JAVA_HOME variable in your environment to match the >&2
77 | echo location of your Java installation. >&2
78 | echo.
79 | goto error
80 |
81 | @REM ==== END VALIDATION ====
82 |
83 | :init
84 |
85 | @REM Find the project base dir, i.e. the directory that contains the folder ".mvn".
86 | @REM Fallback to current working directory if not found.
87 |
88 | set MAVEN_PROJECTBASEDIR=%MAVEN_BASEDIR%
89 | IF NOT "%MAVEN_PROJECTBASEDIR%"=="" goto endDetectBaseDir
90 |
91 | set EXEC_DIR=%CD%
92 | set WDIR=%EXEC_DIR%
93 | :findBaseDir
94 | IF EXIST "%WDIR%"\.mvn goto baseDirFound
95 | cd ..
96 | IF "%WDIR%"=="%CD%" goto baseDirNotFound
97 | set WDIR=%CD%
98 | goto findBaseDir
99 |
100 | :baseDirFound
101 | set MAVEN_PROJECTBASEDIR=%WDIR%
102 | cd "%EXEC_DIR%"
103 | goto endDetectBaseDir
104 |
105 | :baseDirNotFound
106 | set MAVEN_PROJECTBASEDIR=%EXEC_DIR%
107 | cd "%EXEC_DIR%"
108 |
109 | :endDetectBaseDir
110 |
111 | IF NOT EXIST "%MAVEN_PROJECTBASEDIR%\.mvn\jvm.config" goto endReadAdditionalConfig
112 |
113 | @setlocal EnableExtensions EnableDelayedExpansion
114 | for /F "usebackq delims=" %%a in ("%MAVEN_PROJECTBASEDIR%\.mvn\jvm.config") do set JVM_CONFIG_MAVEN_PROPS=!JVM_CONFIG_MAVEN_PROPS! %%a
115 | @endlocal & set JVM_CONFIG_MAVEN_PROPS=%JVM_CONFIG_MAVEN_PROPS%
116 |
117 | :endReadAdditionalConfig
118 |
119 | SET MAVEN_JAVA_EXE="%JAVA_HOME%\bin\java.exe"
120 | set WRAPPER_JAR="%MAVEN_PROJECTBASEDIR%\.mvn\wrapper\maven-wrapper.jar"
121 | set WRAPPER_LAUNCHER=org.apache.maven.wrapper.MavenWrapperMain
122 |
123 | set DOWNLOAD_URL="https://repo.maven.apache.org/maven2/org/apache/maven/wrapper/maven-wrapper/3.1.0/maven-wrapper-3.1.0.jar"
124 |
125 | FOR /F "usebackq tokens=1,2 delims==" %%A IN ("%MAVEN_PROJECTBASEDIR%\.mvn\wrapper\maven-wrapper.properties") DO (
126 | IF "%%A"=="wrapperUrl" SET DOWNLOAD_URL=%%B
127 | )
128 |
129 | @REM Extension to allow automatically downloading the maven-wrapper.jar from Maven-central
130 | @REM This allows using the maven wrapper in projects that prohibit checking in binary data.
131 | if exist %WRAPPER_JAR% (
132 | if "%MVNW_VERBOSE%" == "true" (
133 | echo Found %WRAPPER_JAR%
134 | )
135 | ) else (
136 | if not "%MVNW_REPOURL%" == "" (
137 | SET DOWNLOAD_URL="%MVNW_REPOURL%/org/apache/maven/wrapper/maven-wrapper/3.1.0/maven-wrapper-3.1.0.jar"
138 | )
139 | if "%MVNW_VERBOSE%" == "true" (
140 | echo Couldn't find %WRAPPER_JAR%, downloading it ...
141 | echo Downloading from: %DOWNLOAD_URL%
142 | )
143 |
144 | powershell -Command "&{"^
145 | "$webclient = new-object System.Net.WebClient;"^
146 | "if (-not ([string]::IsNullOrEmpty('%MVNW_USERNAME%') -and [string]::IsNullOrEmpty('%MVNW_PASSWORD%'))) {"^
147 | "$webclient.Credentials = new-object System.Net.NetworkCredential('%MVNW_USERNAME%', '%MVNW_PASSWORD%');"^
148 | "}"^
149 | "[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12; $webclient.DownloadFile('%DOWNLOAD_URL%', '%WRAPPER_JAR%')"^
150 | "}"
151 | if "%MVNW_VERBOSE%" == "true" (
152 | echo Finished downloading %WRAPPER_JAR%
153 | )
154 | )
155 | @REM End of extension
156 |
157 | @REM Provide a "standardized" way to retrieve the CLI args that will
158 | @REM work with both Windows and non-Windows executions.
159 | set MAVEN_CMD_LINE_ARGS=%*
160 |
161 | %MAVEN_JAVA_EXE% ^
162 | %JVM_CONFIG_MAVEN_PROPS% ^
163 | %MAVEN_OPTS% ^
164 | %MAVEN_DEBUG_OPTS% ^
165 | -classpath %WRAPPER_JAR% ^
166 | "-Dmaven.multiModuleProjectDirectory=%MAVEN_PROJECTBASEDIR%" ^
167 | %WRAPPER_LAUNCHER% %MAVEN_CONFIG% %*
168 | if ERRORLEVEL 1 goto error
169 | goto end
170 |
171 | :error
172 | set ERROR_CODE=1
173 |
174 | :end
175 | @endlocal & set ERROR_CODE=%ERROR_CODE%
176 |
177 | if not "%MAVEN_SKIP_RC%"=="" goto skipRcPost
178 | @REM check for post script, once with legacy .bat ending and once with .cmd ending
179 | if exist "%USERPROFILE%\mavenrc_post.bat" call "%USERPROFILE%\mavenrc_post.bat"
180 | if exist "%USERPROFILE%\mavenrc_post.cmd" call "%USERPROFILE%\mavenrc_post.cmd"
181 | :skipRcPost
182 |
183 | @REM pause the script if MAVEN_BATCH_PAUSE is set to 'on'
184 | if "%MAVEN_BATCH_PAUSE%"=="on" pause
185 |
186 | if "%MAVEN_TERMINATE_CMD%"=="on" exit %ERROR_CODE%
187 |
188 | cmd /C exit /B %ERROR_CODE%
189 |
--------------------------------------------------------------------------------
/out/artifacts/AndroidTest/AndroidTest.jar:
--------------------------------------------------------------------------------
https://raw.githubusercontent.com/Bamboo-fly/Android-Vulnerability-Analysis/e2f7d7f81419a816a77aa1b9f4439d7c0ce18179/out/artifacts/AndroidTest/AndroidTest.jar
--------------------------------------------------------------------------------
/out/artifacts/AndroidTest/apk-parser-2.5.3.jar:
--------------------------------------------------------------------------------
https://raw.githubusercontent.com/Bamboo-fly/Android-Vulnerability-Analysis/e2f7d7f81419a816a77aa1b9f4439d7c0ce18179/out/artifacts/AndroidTest/apk-parser-2.5.3.jar
--------------------------------------------------------------------------------
/out/artifacts/AndroidTest/javafx-base-17.0.2-win.jar:
--------------------------------------------------------------------------------
https://raw.githubusercontent.com/Bamboo-fly/Android-Vulnerability-Analysis/e2f7d7f81419a816a77aa1b9f4439d7c0ce18179/out/artifacts/AndroidTest/javafx-base-17.0.2-win.jar
--------------------------------------------------------------------------------
/out/artifacts/AndroidTest/javafx-base-17.0.2.jar:
--------------------------------------------------------------------------------
https://raw.githubusercontent.com/Bamboo-fly/Android-Vulnerability-Analysis/e2f7d7f81419a816a77aa1b9f4439d7c0ce18179/out/artifacts/AndroidTest/javafx-base-17.0.2.jar
--------------------------------------------------------------------------------
/out/artifacts/AndroidTest/javafx-controls-17.0.2-win.jar:
--------------------------------------------------------------------------------
https://raw.githubusercontent.com/Bamboo-fly/Android-Vulnerability-Analysis/e2f7d7f81419a816a77aa1b9f4439d7c0ce18179/out/artifacts/AndroidTest/javafx-controls-17.0.2-win.jar
--------------------------------------------------------------------------------
/out/artifacts/AndroidTest/javafx-controls-17.0.2.jar:
--------------------------------------------------------------------------------
https://raw.githubusercontent.com/Bamboo-fly/Android-Vulnerability-Analysis/e2f7d7f81419a816a77aa1b9f4439d7c0ce18179/out/artifacts/AndroidTest/javafx-controls-17.0.2.jar
--------------------------------------------------------------------------------
/out/artifacts/AndroidTest/javafx-fxml-17.0.2-win.jar:
--------------------------------------------------------------------------------
https://raw.githubusercontent.com/Bamboo-fly/Android-Vulnerability-Analysis/e2f7d7f81419a816a77aa1b9f4439d7c0ce18179/out/artifacts/AndroidTest/javafx-fxml-17.0.2-win.jar
--------------------------------------------------------------------------------
/out/artifacts/AndroidTest/javafx-fxml-17.0.2.jar:
--------------------------------------------------------------------------------
https://raw.githubusercontent.com/Bamboo-fly/Android-Vulnerability-Analysis/e2f7d7f81419a816a77aa1b9f4439d7c0ce18179/out/artifacts/AndroidTest/javafx-fxml-17.0.2.jar
--------------------------------------------------------------------------------
/out/artifacts/AndroidTest/javafx-graphics-17.0.2-win.jar:
--------------------------------------------------------------------------------
https://raw.githubusercontent.com/Bamboo-fly/Android-Vulnerability-Analysis/e2f7d7f81419a816a77aa1b9f4439d7c0ce18179/out/artifacts/AndroidTest/javafx-graphics-17.0.2-win.jar
--------------------------------------------------------------------------------
/out/artifacts/AndroidTest/javafx-graphics-17.0.2.jar:
--------------------------------------------------------------------------------
https://raw.githubusercontent.com/Bamboo-fly/Android-Vulnerability-Analysis/e2f7d7f81419a816a77aa1b9f4439d7c0ce18179/out/artifacts/AndroidTest/javafx-graphics-17.0.2.jar
--------------------------------------------------------------------------------
/pom.xml:
--------------------------------------------------------------------------------
1 |
2 |
5 | 4.0.0
6 |
7 | com.example
8 | AndroidTest
9 | 1.0-SNAPSHOT
10 | AndroidTest
11 |
12 |
13 | UTF-8
14 | 5.8.2
15 |
16 |
17 |
18 |
19 | net.dongliu
20 | apk-parser
21 | 2.5.3
22 |
23 |
24 |
25 | org.openjfx
26 | javafx-controls
27 | 17.0.2
28 |
29 |
30 | org.openjfx
31 | javafx-fxml
32 | 17.0.2
33 |
34 |
35 |
36 | org.junit.jupiter
37 | junit-jupiter-api
38 | ${junit.version}
39 | test
40 |
41 |
42 | org.junit.jupiter
43 | junit-jupiter-engine
44 | ${junit.version}
45 | test
46 |
47 |
48 |
49 |
50 |
51 |
52 | org.apache.maven.plugins
53 | maven-compiler-plugin
54 | 3.10.1
55 |
56 | 11
57 | 11
58 |
59 |
60 |
61 | org.openjfx
62 | javafx-maven-plugin
63 | 0.0.8
64 |
65 |
66 |
67 | default-cli
68 |
69 | com.example.androidtest/com.example.androidtest.HelloApplication
70 | app
71 | app
72 | app
73 | true
74 | true
75 | true
76 |
77 |
78 |
79 |
80 |
81 |
82 |
--------------------------------------------------------------------------------
/src/main/java/com/example/androidtest/HelloApplication.java:
--------------------------------------------------------------------------------
1 | package com.example.androidtest;
2 |
3 | import javafx.application.Application;
4 | import javafx.fxml.FXMLLoader;
5 | import javafx.scene.Parent;
6 | import javafx.scene.Scene;
7 | import javafx.scene.image.Image;
8 | import javafx.stage.Stage;
9 |
10 | import java.io.IOException;
11 |
12 | public class HelloApplication extends Application {
13 |
14 | private static Stage stages;
15 | @Override
16 | public void start(Stage stage) {
17 |
18 | stages=stage;
19 |
20 | try {
21 | FXMLLoader fxmlLoader = new FXMLLoader(getClass().getResource("login-view.fxml"));
22 | //加载fxml文件
23 | Parent root = fxmlLoader.load();
24 | //创建场景
25 | Scene scene = new Scene(root, 400 , 300);
26 |
27 | //场景 添加到 舞台
28 | stage.setTitle("安卓隐私检测平台");
29 | stage.getIcons().add(new Image("E:\\FXproject\\demo\\src\\main\\resources\\com.example.img\\img.png"));
30 | stage.setScene(scene);
31 | stage.show();
32 |
33 | } catch (IOException e) {
34 | // TODO Auto-generated catch block
35 | e.printStackTrace();
36 | }
37 | }
38 |
39 | public static void closeFooPane() {
40 | stages.close(); // 显示页面
41 | }
42 |
43 | public static void main(String[] args) {
44 | launch();
45 | }
46 | }
--------------------------------------------------------------------------------
/src/main/java/com/example/androidtest/TestPage.java:
--------------------------------------------------------------------------------
1 | package com.example.androidtest;
2 |
3 | import javafx.collections.FXCollections;
4 | import javafx.collections.ObservableList;
5 | import javafx.fxml.FXMLLoader;
6 | import javafx.geometry.Side;
7 | import javafx.scene.Scene;
8 | import javafx.scene.chart.PieChart;
9 | import javafx.scene.control.Button;
10 | import javafx.scene.control.Label;
11 | import javafx.scene.control.Tab;
12 | import javafx.scene.control.TabPane;
13 | import javafx.scene.image.Image;
14 | import javafx.scene.image.ImageView;
15 | import javafx.scene.layout.AnchorPane;
16 | import javafx.scene.layout.Background;
17 | import javafx.scene.layout.BorderPane;
18 | import javafx.scene.layout.StackPane;
19 | import javafx.scene.paint.Color;
20 | import javafx.scene.shape.Circle;
21 | import javafx.stage.Stage;
22 |
23 | import java.io.IOException;
24 |
25 | public class TestPage extends AnchorPane {
26 | private static TestPage testPage;
27 | private Stage stage;
28 |
29 | private TestPage() throws IOException{
30 | // FXMLLoader fxmlLoader = new FXMLLoader(HelloApplication.class.getResource("hello-view.fxml"));
31 | // stage = new Stage();
32 | // stage.setTitle("FOO管理");
33 | // stage.setScene(new Scene(fxmlLoader.load(), 500, 250));
34 |
35 | stage = new Stage();
36 |
37 | PieChart pieChart = new PieChart();
38 | pieChart.setData(getChartData());
39 | pieChart.setTitle("Title");
40 | pieChart.setLegendSide(Side.LEFT);
41 | pieChart.setClockwise(false);
42 | pieChart.setLabelsVisible(false);
43 | StackPane root = new StackPane();
44 | root.getChildren().add(pieChart);
45 |
46 |
47 | FXMLLoader fxmlLoader = new FXMLLoader(HelloApplication.class.getResource("load-view.fxml"));
48 | //创建选项卡面板
49 | TabPane tabPane = new TabPane();
50 | //创建不带标题的选项卡标题
51 | Tab tab1 = new Tab();
52 | tab1.setText("apk应用导入");
53 | //设置选项卡tab1不可被关闭
54 | tab1.setClosable(false);
55 | //将圆添加到选项卡tab1上
56 | tab1.setContent(fxmlLoader.load());
57 |
58 |
59 | Tab tab2 = new Tab("分析记录");
60 | tab2.setClosable(false);
61 | FXMLLoader fxmlLoader2 = new FXMLLoader(HelloApplication.class.getResource("analyse-view2.fxml"));
62 | tab2.setContent(fxmlLoader2.load());
63 | Scene scene = new Scene(tabPane,800,500);
64 | //将两个选项卡添加到选项卡面板上
65 | tabPane.getTabs().addAll(tab1,tab2);
66 |
67 | stage.setTitle("安卓隐私检测平台");
68 | stage.getIcons().add(new Image("E:\\FXproject\\demo\\src\\main\\resources\\com.example.img\\img.png"));
69 | stage.setScene(scene);
70 | }
71 |
72 | private ObservableList getChartData() {
73 | ObservableList answer = FXCollections.observableArrayList();
74 | answer.addAll(new PieChart.Data("java", 17),
75 | new PieChart.Data("JavaFx",31),
76 | new PieChart.Data("Swing",10),
77 | new PieChart.Data("IO",20),
78 | new PieChart.Data("NIO",21)
79 | );
80 | return answer;
81 | }
82 |
83 | public Stage getStage() {
84 | return this.stage;
85 | }
86 |
87 | // 外部调用方法
88 | public static void showFooPane() {
89 | try {
90 | testPage = new TestPage(); // 构造实例
91 | } catch (IOException e) {
92 | throw new RuntimeException(e);
93 | }
94 | testPage.getStage().show(); // 显示页面
95 | }
96 | }
97 |
--------------------------------------------------------------------------------
/src/main/java/controller/AnalyseViewController.java:
--------------------------------------------------------------------------------
1 | package controller;
2 |
3 | import com.example.androidtest.HelloApplication;
4 | import javafx.collections.FXCollections;
5 | import javafx.collections.ObservableList;
6 | import javafx.event.ActionEvent;
7 | import javafx.event.EventHandler;
8 | import javafx.fxml.FXML;
9 | import javafx.fxml.FXMLLoader;
10 | import javafx.fxml.Initializable;
11 | import javafx.scene.chart.PieChart;
12 | import javafx.scene.control.Button;
13 | import javafx.scene.control.ListView;
14 | import javafx.stage.FileChooser;
15 | import utils.ApkUtils;
16 | import utils.DataAnalyseUtils;
17 |
18 | import java.io.File;
19 | import java.io.IOException;
20 | import java.net.URL;
21 | import java.util.ArrayList;
22 | import java.util.List;
23 | import java.util.ResourceBundle;
24 |
25 | public class AnalyseViewController implements Initializable {
26 |
27 | private List quanxian;
28 |
29 | private List loudong;
30 |
31 | private String filename;
32 |
33 | @FXML
34 | private ListView list;
35 |
36 | @FXML
37 | private ListView list1;
38 |
39 | @FXML
40 | private Button beginbutton;
41 |
42 | @FXML
43 | protected void begin(ActionEvent event){
44 | beginbutton.setOnAction(new EventHandler() {
45 | @Override
46 | public void handle(ActionEvent actionEvent) {
47 | quanxian=null;
48 | loudong=null;
49 | FXMLLoader fxmlLoader = new FXMLLoader(HelloApplication.class.getResource("analyse-view2.fxml"));
50 | FileChooser fileChooser = new FileChooser();
51 | FileChooser.ExtensionFilter extFilter = new FileChooser.ExtensionFilter("APK files (*.apk)", "*.apk");
52 | fileChooser.getExtensionFilters().add(extFilter);
53 | File file = null;
54 | file = fileChooser.showOpenDialog(fxmlLoader.getRoot());
55 | // ArrayList list = ApkUtils.getData(file.toString());
56 |
57 | try {
58 | quanxian = DataAnalyseUtils.dangerous(file.toString());
59 | loudong = DataAnalyseUtils.loudong(file.toString());
60 | list.setItems(getChartData(quanxian));
61 | list1.setItems(getChartData(loudong));
62 | System.out.println(quanxian);
63 | System.out.println(loudong);
64 | } catch (IOException e) {
65 | throw new RuntimeException(e);
66 | }
67 | }
68 | });
69 | }
70 |
71 | private ObservableList getChartData(List arrayList) {
72 | list.setEditable(false);
73 | ObservableList answer = FXCollections.observableArrayList();
74 | answer.addAll(arrayList);
75 | return answer;
76 | }
77 |
78 | @Override
79 | public void initialize(URL url, ResourceBundle resourceBundle) {}
80 |
81 |
82 |
83 |
84 |
85 | }
86 |
--------------------------------------------------------------------------------
/src/main/java/controller/HelloController.java:
--------------------------------------------------------------------------------
1 | package controller;
2 |
3 | import javafx.fxml.FXML;
4 | import javafx.scene.control.Label;
5 |
6 | public class HelloController {
7 | @FXML
8 | private Label welcomeText;
9 |
10 | @FXML
11 | protected void onHelloButtonClick() {
12 | welcomeText.setText("Welcome to JavaFX Application!");
13 | }
14 | }
--------------------------------------------------------------------------------
/src/main/java/controller/LoadViewController.java:
--------------------------------------------------------------------------------
1 | package controller;
2 |
3 | import com.example.androidtest.HelloApplication;
4 | import javafx.collections.FXCollections;
5 | import javafx.collections.ObservableList;
6 | import javafx.event.ActionEvent;
7 | import javafx.event.EventHandler;
8 | import javafx.fxml.FXML;
9 | import javafx.fxml.FXMLLoader;
10 | import javafx.fxml.Initializable;
11 | import javafx.geometry.Side;
12 | import javafx.scene.chart.PieChart;
13 | import javafx.scene.control.Button;
14 | import javafx.scene.control.ComboBox;
15 | import javafx.scene.image.Image;
16 | import javafx.scene.image.ImageView;
17 | import javafx.scene.layout.VBox;
18 | import javafx.scene.text.Text;
19 | import javafx.stage.FileChooser;
20 | import utils.ApkUtils;
21 |
22 | import java.io.File;
23 | import java.io.IOException;
24 | import java.net.URL;
25 | import java.util.ArrayList;
26 | import java.util.ResourceBundle;
27 |
28 | public class LoadViewController implements Initializable {
29 |
30 | @Override
31 | public void initialize(URL url, ResourceBundle resourceBundle) {}
32 |
33 | @FXML
34 | private PieChart piechart;
35 |
36 | @FXML
37 | private Button load;
38 |
39 | @FXML
40 | private ComboBox box;
41 |
42 | @FXML
43 | private Text text1,text2,text3,text4,text5;
44 |
45 | @FXML
46 | private ImageView icon;
47 |
48 | @FXML
49 | protected void chose(){
50 | load.setOnAction(new EventHandler(){
51 | @Override
52 | public void handle(ActionEvent arg0) {
53 | FXMLLoader fxmlLoader = new FXMLLoader(HelloApplication.class.getResource("load-view.fxml"));
54 | FileChooser fileChooser = new FileChooser();
55 | FileChooser.ExtensionFilter extFilter = new FileChooser.ExtensionFilter("APK files (*.apk)", "*.apk");
56 | fileChooser.getExtensionFilters().add(extFilter);
57 | File file = null;
58 | file = fileChooser.showOpenDialog(fxmlLoader.getRoot());
59 | ArrayList list = ApkUtils.getData(file.toString());
60 |
61 | text1.setText(list.get(0));
62 | text2.setText(list.get(1));
63 | text3.setText(list.get(2));
64 | text4.setText(list.get(3));
65 | text5.setText(list.get(4));
66 | icon.setImage(new Image("E:\\.png"));
67 |
68 | list.get(5);
69 |
70 | piechart.setData(getChartData());
71 | piechart.setTitle("漏洞分析");
72 | piechart.setLegendSide(Side.BOTTOM);
73 | piechart.setClockwise(false);
74 | piechart.setLabelsVisible(false);
75 | //在这里获取了柱状图数据
76 | }
77 | });
78 | //在这里获取了基本信息
79 | }
80 |
81 | private ObservableList getChartData() {
82 | ObservableList answer = FXCollections.observableArrayList();
83 | answer.addAll(new PieChart.Data("活动组件漏洞", 17),
84 | new PieChart.Data("服务漏洞",31),
85 | new PieChart.Data("数据安全漏洞",10)
86 | );
87 | return answer;
88 | }
89 |
90 | }
91 |
--------------------------------------------------------------------------------
/src/main/java/controller/LoginController.java:
--------------------------------------------------------------------------------
1 | package controller;
2 |
3 | import com.example.androidtest.HelloApplication;
4 | import com.example.androidtest.TestPage;
5 | import javafx.event.ActionEvent;
6 | import javafx.fxml.FXML;
7 | import javafx.fxml.Initializable;
8 | import javafx.scene.control.PasswordField;
9 | import javafx.scene.control.TextField;
10 | import javafx.scene.text.Text;
11 |
12 | import java.net.URL;
13 | import java.util.ResourceBundle;
14 |
15 | public class LoginController implements Initializable {
16 | //实现 Initializable接口方法
17 | @Override
18 | public void initialize(URL location, ResourceBundle resources) {
19 | // TODO Auto-generated method stub
20 |
21 | }
22 |
23 | //声明提示text组件
24 | @FXML
25 | private Text actiontarget;
26 |
27 | @FXML
28 | private TextField username;
29 |
30 | @FXML
31 | private PasswordField password;
32 |
33 | //登陆按钮点击事件
34 | @FXML protected void handleSubmitButtonAction(ActionEvent event) {
35 | System.out.println(username.getText()+" "+password.getText());
36 | if (username.getText().equals("111")&&password.getText().equals("111")){
37 | actiontarget.setText("登录成功");
38 | TestPage.showFooPane();
39 | HelloApplication.closeFooPane();
40 | }else {
41 | actiontarget.setText("登陆失败");
42 | }
43 | }
44 |
45 | @FXML protected void handleSubmitButtonAction2(ActionEvent event) {
46 | actiontarget.setText("还没写呃");
47 | }
48 | }
49 |
--------------------------------------------------------------------------------
/src/main/java/module-info.java:
--------------------------------------------------------------------------------
1 | module com.example.androidtest {
2 | requires javafx.controls;
3 | requires javafx.fxml;
4 | requires net.dongliu.apkparser;
5 |
6 |
7 | opens com.example.androidtest to javafx.fxml;
8 | exports com.example.androidtest;
9 | exports controller;
10 | opens controller to javafx.fxml;
11 | }
--------------------------------------------------------------------------------
/src/main/java/utils/ApkUtils.java:
--------------------------------------------------------------------------------
1 | package utils;
2 |
3 | import net.dongliu.apk.parser.ApkFile;
4 | import net.dongliu.apk.parser.bean.ApkMeta;
5 |
6 | import java.io.*;
7 | import java.util.ArrayList;
8 | import java.util.zip.ZipEntry;
9 | import java.util.zip.ZipFile;
10 | import java.util.zip.ZipInputStream;
11 |
12 | /**
13 | * 获取apk的包名、版本名、版本号、图标等信息
14 | */
15 | public class ApkUtils {
16 |
17 |
18 | // 文件名称
19 | private static String name = "";
20 | // apk的绝对地址
21 | private static String apk = null;
22 | // 拷贝图标的存放位置
23 | private static String fileName = "E:\\" + name + ".png";
24 |
25 | public static ArrayList getData(String s){
26 | System.out.println("寄"+s);
27 | apk=s;
28 | ArrayList list=new ArrayList<>() ;
29 | try {
30 | File file = new File(apk);
31 | if (file.exists() && file.isFile()) {
32 | ApkFile apkFile = new ApkFile(file);
33 | ApkMeta apkMeta = apkFile.getApkMeta();
34 | // 拷贝出的icon文件名 根据需要可以随便改
35 | name = apkMeta.getLabel();
36 |
37 | System.out.println("应用名称 :" + apkMeta.getLabel());
38 | list.add(apkMeta.getLabel());
39 | System.out.println("包名 :" + apkMeta.getPackageName());
40 | list.add(apkMeta.getPackageName());
41 | System.out.println("版本号 :" + apkMeta.getVersionName());
42 | list.add(apkMeta.getVersionName());
43 | System.out.println("图标 :" + apkMeta.getIcon());
44 | list.add(apkMeta.getIcon());
45 | System.out.println("大小 :" + (double) (file.length() * 100 / 1024 / 1024) / 100 + " MB");
46 | list.add((double) (file.length() * 100 / 1024 / 1024) / 100 + " MB");
47 |
48 | list.add(apkFile.getManifestXml());
49 |
50 | // 拷贝图标
51 | saveBit(apkMeta.getIcon());
52 |
53 | return list;
54 | }
55 | } catch (Exception e) {
56 | e.printStackTrace();
57 | }
58 | return list;
59 | }
60 |
61 | // 拷贝图标
62 | public static void saveBit(String Icon) throws IOException {
63 | ZipInputStream zin = null;
64 |
65 | try {
66 | // 访问apk 里面的文件
67 | ZipFile zf = new ZipFile(apk);
68 | InputStream in = new BufferedInputStream(new FileInputStream(apk));
69 | zin = new ZipInputStream(in);
70 | ZipEntry ze;
71 | while ((ze = zin.getNextEntry()) != null) {
72 | if (ze.getName().equals(Icon)) {
73 | // 拷贝出图标
74 | System.out.println("拷贝开始");
75 | InputStream inStream = zf.getInputStream(ze);
76 |
77 | ByteArrayOutputStream outStream = new ByteArrayOutputStream();
78 | //创建一个Buffer字符串
79 | byte[] buffer = new byte[1024];
80 | //每次读取的字符串长度,如果为-1,代表全部读取完毕
81 | int len = 0;
82 | //使用一个输入流从buffer里把数据读取出来
83 | while ((len = inStream.read(buffer)) != -1) {
84 | //用输出流往buffer里写入数据,中间参数代表从哪个位置开始读,len代表读取的长度
85 | outStream.write(buffer, 0, len);
86 | }
87 | //关闭输入流
88 | inStream.close();
89 | //把outStream里的数据写入内存
90 |
91 | //得到图片的二进制数据,以二进制封装得到数据,具有通用性
92 | byte[] data = outStream.toByteArray();
93 | //new一个文件对象用来保存图片,默认保存当前工程根目录
94 | File imageFile = new File(fileName);
95 | //创建输出流
96 | FileOutputStream fileOutStream = new FileOutputStream(imageFile);
97 | //写入数据
98 | fileOutStream.write(data);
99 | System.out.println(imageFile);
100 | fileOutStream.close();
101 | outStream.close();
102 | }
103 | }
104 | in.close();
105 | zf.close();
106 | } catch (Exception e) {
107 | e.printStackTrace();
108 | } finally {
109 | zin.closeEntry();
110 | }
111 | }
112 | }
113 |
114 |
--------------------------------------------------------------------------------
/src/main/java/utils/DataAnalyseUtils.java:
--------------------------------------------------------------------------------
1 | package utils;
2 |
3 | import java.io.*;
4 | import java.util.*;
5 |
6 | public class DataAnalyseUtils {
7 |
8 | private static List quanxian=new ArrayList<>();
9 |
10 | private static List loudong=new ArrayList<>();
11 |
12 | //获取危险权限方法
13 | public static List dangerous(String apkpath) throws IOException {
14 | ArrayList list = ApkUtils.getData(apkpath);
15 | String AndroidMainXml = list.get(5);
16 | String str = "src/main/resources/com/example/androidtest/危险权限.txt";
17 |
18 | FileInputStream fin = new FileInputStream(str);
19 | InputStreamReader reader = new InputStreamReader(fin);
20 | BufferedReader buffReader = new BufferedReader(reader);
21 | String strTmp = "";
22 | while((strTmp = buffReader.readLine())!=null){
23 | List list3 = Arrays.asList(strTmp.split(" "));
24 | for (int i=0;i loudong(String apkpath) throws IOException {
39 | ArrayList list = ApkUtils.getData(apkpath);
40 | String AndroidMainXml = list.get(5);
41 | String str = "src/main/resources/com/example/androidtest/漏洞.txt";
42 |
43 | FileInputStream fin = new FileInputStream(str);
44 | InputStreamReader reader = new InputStreamReader(fin);
45 | BufferedReader buffReader = new BufferedReader(reader);
46 | String strTmp = "";
47 | while((strTmp = buffReader.readLine())!=null){
48 | List list3 = Arrays.asList(strTmp.split(" "));
49 | for (int i=0;i
2 |
3 |
4 |
5 |
6 |
7 |
8 |
9 |
10 |
11 |
12 |
13 |
14 |
15 |
16 |
17 |
18 |
19 |
20 |
21 |
22 |
23 |
24 |
25 |
26 |
27 |
28 |
29 |
--------------------------------------------------------------------------------
/src/main/resources/com/example/androidtest/hello-view.fxml:
--------------------------------------------------------------------------------
1 |
2 |
3 |
4 |
5 |
6 |
7 |
8 |
9 |
10 |
11 |
12 |
13 |
14 |
15 |
16 |
17 |
18 |
19 |
20 |
21 |
22 |
23 |
24 |
--------------------------------------------------------------------------------
/src/main/resources/com/example/androidtest/img.png:
--------------------------------------------------------------------------------
https://raw.githubusercontent.com/Bamboo-fly/Android-Vulnerability-Analysis/e2f7d7f81419a816a77aa1b9f4439d7c0ce18179/src/main/resources/com/example/androidtest/img.png
--------------------------------------------------------------------------------
/src/main/resources/com/example/androidtest/load-view.fxml:
--------------------------------------------------------------------------------
1 |
2 |
3 |
4 |
5 |
6 |
7 |
8 |
9 |
10 |
11 |
12 |
13 |
14 |
15 |
16 |
17 |
18 |
19 |
20 |
21 |
22 |
23 |
24 |
25 |
26 |
27 |
32 |
33 |
34 |
35 |
36 |
37 |
38 |
39 |
40 |
45 |
46 |
47 |
48 |
49 |
50 |
51 |
52 |
53 |
54 |
59 |
60 |
61 |
62 |
63 |
64 |
65 |
66 |
67 |
72 |
73 |
74 |
75 |
76 |
77 |
78 |
79 |
80 |
85 |
86 |
87 |
88 |
89 |
90 |
91 |
92 |
93 |
94 |
95 |
100 |
101 |
102 |
103 |
104 |
105 |
106 |
107 |
108 |
109 |
110 |
111 |
112 |
--------------------------------------------------------------------------------
/src/main/resources/com/example/androidtest/login-view.fxml:
--------------------------------------------------------------------------------
1 |
2 |
3 |
4 |
5 |
6 |
7 |
8 |
9 |
10 |
11 |
12 |
13 |
14 |
15 |
16 |
17 |
18 |
19 |
20 |
21 |
22 |
23 |
24 |
25 |
26 |
27 |
28 |
29 |
30 |
31 |
32 |
33 |
34 |
35 |
36 |
37 |
38 |
39 |
40 |
41 |
42 |
43 |
44 |
45 |
46 |
47 |
48 |
49 |
50 |
51 |
52 |
53 |
54 |
55 |
56 |
57 |
58 |
59 |
60 |
61 |
62 |
--------------------------------------------------------------------------------
/src/main/resources/com/example/androidtest/login_css.css:
--------------------------------------------------------------------------------
1 |
2 | /**
3 | * 设置舞台背景图片
4 | */
5 | /*.root { -fx-background-image: url("img.png");}*/
6 |
7 | /**
8 | * 设置风格标签
9 | * */
10 | .label{
11 | -fx-font-size: 12px;
12 | -fx-font-weight: bold;
13 | -fx-text-fill: #333333;
14 | -fx-effect: dropshadow( gaussian , rgba(255,255,255,0.5) , 0,0,0,1 );
15 | }
16 |
17 | #welcomeText{
18 | -fx-font-size: 50px;
19 | }
20 |
21 | /*
22 | *设置标题文本样式
23 | */
24 | #title{
25 | -fx-font-size: 50px;
26 | -fx-font-family: "Arial Blackt";
27 | -fx-fill: #818181;
28 | -fx-effect: innershadow( three-pass-box , rgba(0,0,0,0.7) , 6, 0.0 , 0 , 2 );
29 | }
30 |
31 | /**
32 | * 设置提示文本样式
33 | * */
34 | #actiontarget {
35 | -fx-fill: FIREBRICK;
36 | -fx-font-weight: bold;
37 | -fx-effect: dropshadow( gaussian , rgba(255,255,255,0.5) , 0,0,0,1 );
38 | }
39 |
40 | /**
41 | * 设置登陆按钮样式
42 | */
43 | .button {
44 | -fx-text-fill: white;
45 | -fx-font-family: "Arial Narrow";
46 | -fx-font-weight: bold;
47 | -fx-background-color: linear-gradient(#61a2b1, #2A5058);
48 | -fx-effect: dropshadow( three-pass-box , rgba(0,0,0,0.6) , 5, 0.0 , 0 , 1 );
49 | }
50 |
51 | /*设置登陆按钮悬停样式 */
52 | .button:hover { -fx-background-color: linear-gradient(#2A5058, #61a2b1);}
--------------------------------------------------------------------------------
/src/main/resources/com/example/androidtest/危险权限.txt:
--------------------------------------------------------------------------------
1 | CALENDAR(日历) READ_CALENDAR WRITE_CALENDAR
2 | CAMERA(相机) CAMERA
3 | CONTACTS(联系人) READ_CONTACTS WRITE_CONTACTS GET_ACCOUNTS
4 | LOCATION(位置) ACCESS_FINE_LOCATION ACCESS_COARSE_LOCATION
5 | MICROPHONE(麦克风) RECORD_AUDIO
6 | PHONE(手机) READ_PHONE_STATE CALL_PHONE READ_CALL_LOG WRITE_CALL_LOG ADD_VOICEMAIL USE_SIP PROCESS_OUTGOING_CALLS
7 | SENSORS(传感器) BODY_SENSORS
8 | SMS(短信) SEND_SMS RECEIVE_SMS READ_SMS RECEIVE_WAP_PUSH RECEIVE_MMS
9 | STORAGE(存储卡) READ_EXTERNAL_STORAGE WRITE_EXTERNAL_STORAGE
--------------------------------------------------------------------------------
/src/main/resources/com/example/androidtest/危险权限组.txt:
--------------------------------------------------------------------------------
1 | CALENDAR(日历) CAMERA(相机) CONTACTS(联系人) LOCATION(位置) MICROPHONE(麦克风) PHONE(手机) SENSORS(传感器) SMS(短信) STORAGE(存储卡)
--------------------------------------------------------------------------------
/src/main/resources/com/example/androidtest/漏洞.txt:
--------------------------------------------------------------------------------
1 | Admin越权风险 android.permission.BIND_DEVICE_ADMIN
2 | 组件暴露风险 exported="true"
3 | 数据备份风险 allowBackup="true"
4 | 调试开启风险 debuggable="true"
--------------------------------------------------------------------------------