During a red-team engagement, you recover an unattended corporate smartphone running Android 12. The screen is locked and the bootloader is still locked, but USB debugging was left enabled and the device has previously trusted your laptop's ADB RSA key. With only minutes of physical access, which built-in attack vector lets you deploy a backdoored application and obtain a reverse shell without further user interaction?
Send a crafted WAP-Push Service Indication (SI) SMS that forces the device to download and install your application.
Reboot the phone into fastboot mode and flash a modified system image containing your payload.
Transfer the APK via NFC Android Beam and rely on automatic installation when the devices touch.
Use the trusted ADB session to run adb install and silently sideload the malicious APK.
Because the device has already authorized the tester's computer for Android Debug Bridge (ADB) access, all normal ADB commands can be executed even while the screen is locked. The command adb install evil.apk sideloads (and, if desired, launches) the malicious application immediately. Fastboot flashing is blocked by the locked bootloader, WAP-Push SI messages no longer trigger silent installs on modern Android versions, and Android Beam requires user confirmation on an unlocked screen, so those vectors would fail under the stated conditions.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is ADB and how does it work?
Open an interactive chat with Bash
What is an APK, and how does sideloading work?
Open an interactive chat with Bash
Why does the locked bootloader block fastboot flashing?
Open an interactive chat with Bash
What is ADB (Android Debug Bridge)?
Open an interactive chat with Bash
What is sideloading an APK?
Open an interactive chat with Bash
Why is a locked bootloader a security measure?
Open an interactive chat with Bash
Certified Ethical Hacker (CEH)
Mobile Platform, IoT, and OT Hacking
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .