Skip to content

Instantly share code, notes, and snippets.

@groldo
Last active September 12, 2022 09:22
Show Gist options
  • Select an option

  • Save groldo/78cf450fad408d8d5eaad88888e0f93b to your computer and use it in GitHub Desktop.

Select an option

Save groldo/78cf450fad408d8d5eaad88888e0f93b to your computer and use it in GitHub Desktop.

FourGoats

install android 4.4 emulator

sdkmanager "platforms;android-30"
sdkmanager "system-images;android-29;default;x86_64"
sdkmanager --channel=3 emulator
sdkmanager "build-tools;30.0.3" 
sdkmanager "platforms;android-18"
sdkmanager "system-images;android-19;default;x86"

should now look like this:

  Path                                 | Version | Description                 | Location                            
  -------                              | ------- | -------                     | -------                             
  emulator                             | 31.3.10 | Android Emulator            | emulator                            
  patcher;v4                           | 1       | SDK Patch Applier v4        | patcher/v4                          
  platform-tools                       | 33.0.3  | Android SDK Platform-Tools  | platform-tools                      
  platforms;android-19                 | 4       | Android SDK Platform 19     | platforms/android-19                
  system-images;android-19;default;x86 | 6       | Intel x86 Atom System Image | system-images/android-19/default/x86

get fourgoats

mkdir fourgoat && cd fourgoat
wget https://github.com/downloads/jackMannino/OWASP-GoatDroid-Project/OWASP-GoatDroid-0.9.zip
unzip OWASP-GoatDroid-0.9.zip
java -jar OWASP-GoatDroid-0.9/goatdroid-0.9.jar
adb install bla

get burp suite

java -jar burp

create emulator

avdmanager create avd -n fourgoats -k "system-images;android-19;default;x86" -g "default"
./emulator -avd fourgoats -http-proxy http://172.22.150.117:8080 -no-snapshot

start fourgoats and login

start via emulator adjust ip settings via dest submenu

start webserver

start webserver in the OWASP fourgoats gui tab on the right side

login

login with goatdroid:goatdroid

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment