Skip to content

Milestones

List view

  • No due date
    8/8 issues closed
  • No due date
  • drozer Console --- * Remove an error message about missing javac and/or dx when running some modules. * Fixed a bug where running `ls` after `module install` would return an empty list. * Fixed a bug where trying to `unset` or `echo` an undefined variable would cause the console to crash. * Fixed a number of bugs with autocompletion, particularly of file paths. * Fixed a bug where `drozer exploit build <exploit> --payload ` would offer unsupported payloads in autocompletion suggestions. * Bundled an OS X version of `aapt`, allowing the exploitation tools to run on Mac. (#99) * Fixed a bug where running `permissions` on an agent with context, that wasn't called `com.mwr.dz` would return an incorrect list. * Allow drozer modules to be installed without requiring an active console session. * Indicate when a drozer session is in a limited agent (without Context) by showing 'dz-limited' as the prompt. drozer Agent --- * Allow the embedded server and endpoint connections to be controlled without leaving the main drozer screen. (#78) * Allow the drozer server to be started by an implicit Intent for the pwn:// scheme. * Allow the agent to re-enable the embedded server/endpoints when it recovers from an unclean exit. * Fix a bug where log messages were not updated for an endpoint connection. * Fix a bug where an incorrect port number could be shown for the embedded server on the main drozer screen. * Replace 'default' ANDROID_IDs (assigned to some emulators) with random values, so devices can be uniquely identified. * Persist the ANDROID_ID (unique identifier) for a device where we have generated one at random. * Allow the ANDROID_ID (unique identifier) for a device to be changed through the agent GUI. drozer Server --- * Support the use of regular expressions as the path specified for an uploaded resource. * Support the setting of custom headers in the HTTP header returned for an uploaded resource. * Fixed a bug in some versions of Twisted that caused bind shells returned by weasel to be dropped. drozer Modules --- * Support filtering packages by human name and intent filter action in `app.package.info`. * Replaced the libjackpal terminal with a native Java shell, so `shell.start` runs under a limited agent. * Fixed a misleading error message that was returned if `module install` was run without a working Internet connection. * Fixed a bug that prevented some modules being installed, because they were incorrectly identified as already installed. * Improved the readability in the output of `app.provider.finduri`. * Fixed a bug in `scanner.misc.weburls` where random characters could be pre-pended to the URL. * Support a return type of 'Potentially Vulnerable' from a VulnerabilityScanner module.

    Due by January 8, 2014
    3/3 issues closed
  • No due date
    8/8 issues closed
  • No due date
  • No due date
    6/6 issues closed
  • Due by February 7, 2013
    8/8 issues closed
  • Due by December 14, 2012
    4/4 issues closed