Comprehensive testing capabilities are vital for building robust and secure Android applications in the world of Android cyber tool development.
Our next blog post highlights how Bungeegum enables Android CNO tool developers to align their testing more closely with real-world use cases. While development and testing infrastructure for standard Android applications is quite mature, the unique needs of CNO developers have been underserved. By leveraging Bungeegum, CNO development teams can automate processes that were previously manual, streamlining the creation of robust Android cyber tools.
Imagine the following scenario: You’ve spent months developing an incredible new CNO capability, conducting tests across your entire range of devices (perhaps using Lariat), and you’re ready to confidently deliver your product. However, when you attempt to test it with a real exploit chain and remote code execution (RCE), you realize that your tool doesn’t work when running inside Telegrams’s application process due to SElinux context restrictions.
Traditionally, automated testing involved running binaries from a device’s shell via Android Debug Bridge (ADB). Experienced Android CNO developers know that before delivering a capability, it needs to be tested in the same SELinux context and seccomp sandbox that an initial RCE will land in. This testing is usually performed manually, making it non-scalable, time-consuming, and error-prone.
The run-as command is a convenient approximation of an application context, but it’s important to recognize the differences between the runas_app and untrusted_app SELinux contexts. The runas_app context provides higher privileges and fewer restrictions, which can lead to false positives where the binary works under run-as but fails in a real app environment (untrusted_app). Issues such as stricter sandboxing, SELinux denials, limited resource access, and differences in app lifecycle and environment may not be apparent when testing with run-as alone.
Bungeegum is a Python tool that utilizes Frida, enabling users to easily run code from within a test Android application. This approach automates testing to closely resemble real-world use cases without relying on sensitive exploit chains or custom tooling. When code is executed with Bungeegum, it operates within the application’s context and memory space, mirroring how Android CNO tools are typically used in real-world scenarios.
Bungeegum currently offers two main modes of operation:
In ELF mode, users can specify either a local or remote filepath. The specified file is then called within the dummy Bungeegum Android application using the exec call. Optionally, arguments can be passed to the exec call as well.
bungeegum --remote --elf /system/bin/log --args "hello world"
In this example, the /system/bin/log binary located on the Android device is executed, with the argument “hello world,” resulting in a logcat message of “hello world.”
bungeegum --elf ~/hello
In this example, the hello ELF file is copied into the app’s data directory (i.e. /data/user/0/com.zetier.bungeegum/tmpFile) and then run via the exec call.
In shellcode mode, the contents of the provided shellcode file are copied into the memory space of the test application, and a function pointer pointing to the shellcode is called.
bungeegum --shellcode shellcode.bin
In all three examples, the return code is collected, and returned to the python script if available.
Bungeegum can be used to verify whether an Android executable or shellcode payload can execute within an underprivileged initial access vector, such as untrusted_app. Given that numerous permissions are enforced (e.g., SELinux, seccomp-bpf, UID/GID), which can vary from vendor to vendor in the fragmented Android ecosystem, Bungeegum provides a common interface for robustly testing existing capabilities against specific target devices.
Check out the Bungeegum github page for more info on installation and usage.
This is another tool we’re open sourcing, so we’d love feedback or to work together to add new features.
In conclusion, Bungeegum brings a revolution to testing Android cyber tools by making testing in-memory execution within an untrusted app’s SELinux context easy. It offers an advanced and secure testing approach that empowers low-level Android cyber tool developers to enhance code quality, catch bugs early on, and streamline application development. With Bungeegum’s unique capabilities, teams can confidently level up their testing methods, delivering robust and secure Android cyber tools that can tackle real-world challenges head-on.
*The Android robot is modified from work created and shared by Google and is used according to terms described in the Creative Commons 3.0 Attribution License.
Zetier supported the Game Hacking Village at DEF CON 34 - dwangoAC gives his take of causing a commotion with TASBot
Vulnerability research triage tricks, pattern-matching instincts, and ruthless time-saving habits for every reverse engineer.
Vulnerability research triage tricks, pattern-matching instincts, and ruthless time-saving habits for every reverse engineer.
Hacker origin stories from a few of Zetier's cybersecurity engineers.
TPM packet dissection and analysis in Wireshark using open source scripts and projects with a practical walkthrough using Proxmox.
Can prompt injections hidden in unreachable code still influence LLM's?
Everything you need to know about Offensive Cyberspace Operations and the OCO/CNO resources Zetier cyber engineers rely on.
Keeping the Monsters at Bay with Embedded Systems Digital Forensics
2025 was a successful year for Zetier, with office growth, more "sheeping" unguarded colleague workstations, and fun diet(ary) choices
A case study in identifying real-world stack overflows in Netgear router firmware – without access to source code.
Are low-cost SBCs with 4k output viable for native development, RE, and tinkering?
See what your BDM debugger is actually doing under the hood with our new open-source tool.
You just fired up an old Linux-based appliance. Here's one hacking recipe to get beyond basic local access.
Understand the mechanics, risks, and future of IMSI catching (a.k.a. stealing your cellular ID) in 2025.
Thousands of video game enthusiasts are developing experience in the cybersecurity industry by accident.
One of our engineers obtained free printers on Craigslist, which revealed some intriguing obfuscation.
After competing for several years, a Zetier Cyber Engineer made the podium at the DEFCON 32 HHV CTF.
Check out the contributions our team made – and tools we open-sourced – in 2024.
Frida runs out-of-the-box on many common targets. How hard is it to port Frida to an unsupported platform?
A recently acquired piece of military technology holds secrets about worldwide manufacturing capabilities.
Thousands of military members juggle their reserve commitment and civilian life. Read this post to learn how Zetier makes sure you won’t drop the ball.
Building tshark from source with support for Lua has proven to be a challenge. This tutorial will save you some time and frustration.
Hardware memory busses are sometimes tied together with multiple ICs. Here is how to SMASH them!
Breadcrumbs are left throughout computer systems that hackers can use to track attribution or recover sensitive information. See possible gotchas in this post.
Various topics of interest covering IT, cybersecurity, tech innovations, from GitLab workflows to satellite tech advancements.
Zetier is introducing Snipey, a command-line interface (CLI) tool that extends the capabilities of Snipe-IT.
Highlights from around the internet that we discussed in the office during Dec 2023. Everything from the best deals on collectable turbo-jet engines to Bluetooth CVEs.
Explore the art of using JTAG for efficient NOR flash memory dumps – via our practical guide for hardware enthusiasts & engineers.
Lariat works with Device Farmer to address the challenges of platform fragmentation in Android device testing.
Sharing knowledge is in Zetier’s corporate DNA, and this expresses itself in multiple ways.
Smart load integration with inexpensive power supplies providing protections typically found only in pricier models.
At Zetier’s 2023 annual offsite we met in San Juan Puerto Rico for some corporate business, relationship building, good food, and fun in the sun.
DIY dental X-ray tech for PCB reverse engineering, enabling faster, budget-friendly 3D tomography.
CodeQL is a query language for code analysis, allowing powerful code introspection and data flow queries.
Subscribe now to keep reading and get access to the full archive.