Saturday, March 30, 2013

Root your Nexus 7

So you have a Android based tablet. Awesome and you do IT Security (Cool) what can you do....OH a whole lot, now Google is great and the android market is great too. But, there are some applications that lets just say do not really belong in the market such as...oh, really cool hacking and security tools.

How would you like to Foot Print with a Nexus 7. Yep, no more laptop, here is a little secret when I do foot printing I now use the Nexus 7 as my initial "on-site" or "near on-site" tool, why? Because it is small, concealable and Innocent.

Now remember these tutorials are to teach and what you do with this is YOUR RESPONSIBILITY!

Now the first thing you need to do is what is called ROOT you tablet. Now this term is not really 100% accurate, the real term is "Give yourself and other applications Root Access to the android OS". Sound dangerous, it can be as you may know messing up root access can BRICK your tablet. Well kind of I will show you a little emergency thing you can do. Although I should note i have never had a root access go bad yet.

So if you choose to do what this tutorial is about to outline, do it at your own risk. You have been warned.

Now that the the boring part is over lets get into the tutorial.

First you need to download:

Nexus Root Toolkit v1.6.3


You can find it from the link above. At the time of this writing the latest version was 1.6.3 and it will look for updates on its own. 


Double click the installer and you will see this screen, choose Install. 



Now after the install you will see this screen. Now this is REALLY important make sure you choose the correct device and OS, you can get the OS by going to settings and about Tablet. 

DO NOT MAKE A MISTAKE HERE, if you do I am confident you will have problems. 


For this tutorial I used a Nexus 7 so I choose a Nexus 7.


Latest OS is Jellybean and this is the technical data on it: Android 4.2.2 - Build JDQ39


Next you will see this screen FOLLOW THE DIRECTIONS!


Choose OK


This is the normal update progress bar.



Next this screen will come up, choose OK.


Yet another progress bar for you viewing entertainment. 



OK welcome to the Root Kit Toolkit. Check to make sure the model and all match what you have. If not chose change and correct the error. Remember take your time this is not a race. Do it right the first time and you will be fine. 


Now here is the Emergency Exit I told you about choose BACK-UP first before you move forward. Again FOLLOW the directions. 


Choose a location to save you back-up.


Ouch cropped the screen capture. Now this is regrettably where I need to end due to some technical errors, I deleted the remaining screen captures by accident. 

This back-up takes time, so be patient it is working it is just slow. 

After the back-up is complete choose "Unlock" it will wipe all your data. You will need to re-register the tablet to your Google account, yes you will loose saved games etc. 

After this choose Root and follow the directions. I apologize for the lack of additional screen shots, but let me end with the real meat and potatoes of this tutorial. 

Go to the android market and get the following app.


In the android market search for Pentest Tools

This is a database with links to some GREAT tools you can install but many require root access to work. Some require you to pay, I only use the free ones. 

It is well worth the download and time.  













Behind the Scenes

So if you have any interest in what goes into this blog here is a little bit of behind the scenes. I use Screen Hunter 6 Free edition for all my Windows Screen Shots, for linux I just do print screens and edit them in Adobe Photoshop. Anyhow this is the a short tutorial on install and configuration. You can find it by just searching for "Screen Hunter:.



First Install screen select next.


Here you can choose to add shortcuts or not. I usually just have it start on startup and not put a short cut on the desktop but you can choose whatever suits you.


The ever loved progress bar.


Choose Finish


Now this is the main screen and you need it open to take screen shots. Don't worry it does not show up in screen captures. The main button the one you will use all the time is the circle in the middle saying "Capture Now"


Now in the main screen I use the following settings. 
1) I choose to capture ONLY the active window, this saves me a lot of Photoshop work later on. 
2) I DO NOT include the mouse pointer. (I find it distracting in screen captures)



Now if you choose "TO" 
I make the following changes here. 
1) I choose to save a JPEG
2) I choose a custom folder to save to: You I just call mine Screen Shots

Well that is it for this simple behind the scenes look, again I should have the new Linux Lab up today and will  start to make the new tutorials then. 

Peace Out. 







Updates coming soon...Promise!

Just a quick note more coming to the blog VERY soon.
Set up a new Linux BackTrack Lab (Now having 3 Computers and 2 Wireless Networks), should be complete this weekend.

The story behind the Logos, (if anyone cares) ORS or Occams Razor Security is my IT and IT Security Consulting Company, PGHN is the Parent Company or my personal brand associated with the blog.

Now for the record, I have been doing consulting on and off for many years (over 15 years easy), so I am now at the point in my life where I need to "Settle Down" as far as employment goes, so being the type of person I am. I am doing two what I like to call future job vectors.

1) Try to get ORS to be a viable and "Family Supporting Business"
or
2) Find a challenging position at an organization where I can stay until retirement (like that will ever happen).

So seriously this posting is for potential employers who I have and will send resumes to and to those of you who read the tutorials. If I find the later (challenging position) I will shut down ORS.

Bottom line ORS may or may not last but I (PGHN) will still keep posting tutorials for a VERY long time, I find them fun and challenging to create. For the record each one does take many hours since the use a lot of screen shots and really want you the visitor to really understand what is happening. I want you to become a ethical hacker and not a script kiddie.

So thank you all for the support and reading this blog, I hope you continue.

Peace and as always Happy Hacking.