logo

Poking Around in Android Memory

ID: 28dbcd8a-0af8-591d-ae13-2fc99bc93ed5

STIX ID: report--28dbcd8a-0af8-591d-ae13-2fc99bc93ed5

Feed Name: SensePost Blog

Date Published: 2013-02-11

Date Updated: 2026-04-29

...
...

This report outlines a practical technique to extract sensitive information from Android applications by dumping and analyzing Dalvik heap memory (hprof) using DDMS, converting to standard hprof, and mining it with strings/grep. The author demonstrates that credentials, payment card data, tokens, and full JSON API responses can be recovered from memory even when network traffic cannot be intercepted due to HTTPS and certificate pinning, using examples from a mobile wallet and a banking app. The piece emphasizes the security implications and potential for session theft, positioning memory analysis as a powerful alternative to network interception for understanding app behavior and data exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.