Large companies are trying to improve the user experience, simplifying everything and increasing performance and connections to IoT's. Today with the operating system installed on the most powerful smartphones, there are advantages and disadvantages. For example, in a Linux, there are positives and negatives. The user who “Roots” the mobile device will have full access to the system to view, edit and delete files and folders from the Android system as well as to install tools for various functions. At this point it is worth mentioning that it is easy to have a smartphone with penetration testing tools and perform scanning , wireless scanning, sniffing, vulnerability scanning and other functions. But how can we convert an Android smartphone into a penetration testing device?
Preparing an Android smartphone to turn it into a penetration testing device
Google Play provides two applications (free and paid) to have the bash terminal of an Android system. Once the application, we will need to perform the “Root” operation to gain full access to the Android system. Therefore, we can install the penetration testing and monitoring tools.
Apt-get is a powerful package management system used to work with Ubuntu to perform the installation of new software, removal of existing software packages, and upgrading existing software packages.
First of all, we will use Linux distributions repositories for penetration testing. With the command “apt-get update”, we will have reliable font tools. Apt-get is a powerful package management system used to work with Ubuntu’s APT (Advanced Packaging Tool) library to perform the installation of new software packages, removal of existing software packages, and upgrading of existing software packages.
Tools we receive after updating the list:
- NMAP: Security Scanner, Port Scanner, and Network Exploration Tool.
- Bettercap: Powerful tool for executing attacks.
- MITM Setoolkit: Allows the execution of many Social Engineering activities.
We will first try the “NMAP” tool on the network where the smartphone is connected.

With NMAP installed, we have several ways to scan the network and test certain services located on servers. One network scan found two network components, but no vulnerable services to attack.
Let's start sniffing the network to find important credentials in applications that don't use encryption for communication. Let's do a test with the tool "bettercap".

We received the login credentials to the access router. In addition to HTTP, we also receive HTTPS. With the weakest link in information security being the user, he will always be subject to attacks and even without realizing it, the digital certificate of the website will be changed to that of the attacker who makes the MITM attack.

We may not use the smartphone 100% like a laptop with thousands of hacking tools. Of course, we will have several limitations, because it is a smartphone. However, we can use the mobile in bridge mode, which is known as “Pivoting”. You can also use a VPS as a command control and use pivot on Android to perform the penetration test.

Another spoofing method, using tools to perform this technique and downloading Apache2 on Android, we can insert a malicious page so that the user can enter their login credentials on the page and thus gain access to it. Once we change the test page from apache and leave the fake Google page for this test, we will enter the email and password to make sure the attack works.

Once the victim enters their credentials on the fake page, they will be redirected to the Google page without realizing they have been “hacked.”.

In this, his credentials have already been recorded and inserted into a plain text file for better viewing. As a result of the connection being lost, the cracker program can silently gain access to your emails and files.

The content of this article, which concerns converting an Android smartphone into a penetration testing device, belongs to Priya James (Cyber Security Enthusiast, Certified Ethical Hacker, Security Blogger, Technical Editor and Author at “GBHackers”). “Secnews” bears no responsibility for it. This article is intended for educational purposes only. The experiment described was tested on any Android smartphone and no external websites were attacked.
The “Author” and “Secnews” will not be held liable in the event of criminal charges being brought against any person who misuses the information on this website in violation of the law. Reproduction of this content, which concerns the conversion of an Android smartphone into a penetration testing device, without permission is strictly prohibited.
