> For the complete documentation index, see [llms.txt](https://kero0x1.gitbook.io/general/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://kero0x1.gitbook.io/general/mobile-pentest/mobile-hacking-lab/document-viewer.md).

# Document Viewer

Hello everyone , In this blog post , I will try to explain my solution steps for Document Viewer challenge from Mobile Hacking Lab Platform . i hope it will be useful for you

1. install the app and open it
2. **AndroidManifest.xml Examination :**
   1. we have a Main Activity Exported and contain an intent filter with action view and have a lot of schema like : `file - http - https` and the mime type : `application/pdf`

      ![image.png](https://2140186435-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpoPpsF6DyQtOrXy70rxC%2Fuploads%2FQvVlhk0D2VnsAG4jAF3O%2Fimage.png?alt=media)
3. **Let’s analysis the Main activity code :**
   1. **`setLoadButtonListener()` :** This function sets up the button that lets users load a PDF file.
   2. **`handleIntent()` :** Handles incoming intents, such as when a user opens a PDF file directly from another app.
   3. **`renderPdf(Uri uri)` :** This function renders the selected or received PDF file for viewing.
   4. **`requestStoragePermissionAsync(Continuation<? super Boolean> continuation)`** Requests storage permissions .
4. The important function here is the `loadProLibrary()` :

   1. the `Build.SUPPORTED_ABIS[0]` identify the device's architecture (e.g., ARM, x86).
   2. the `(getApplicationContext().getFilesDir(), "native-libraries/" + abi)` : constructs the path to a folder within the app’s internal storage, where native libraries are stored
   3. then constructs the full path to the Pro version of the native library (`libdocviewer_pro.so`)
   4. `System.load(libraryFile.getAbsolutePath())` attempts to load the native library from the constructed path.
   5. If successful, it enables "Pro" features by setting `this.proFeaturesEnabled = true`.

   <figure><img src="https://2140186435-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpoPpsF6DyQtOrXy70rxC%2Fuploads%2FKiS8YrIXbrT2T3sTPzGw%2Fimage.png?alt=media&amp;token=7c5e5410-0cd2-4ac4-b0d7-0779e2a1962e" alt="" width="563"><figcaption></figcaption></figure>
5. After i had decompile the APP i can’t any folder contain the libraries
6. The exploit here is `create a malicious library` and then upload it to the path `/data/data/com.mobilehackinglab.documentviewer/files/native-libraries/x86_64/`
7. when the app try to load this library we will if we found `rce.txt` file has been created then we success and `get RCE`

   ```jsx
   #include <stdlib.h>

   __attribute__((constructor)) void execute_command() {
       system("touch /data/data/com.mobilehackinglab.documentviewer/rce.txt");
   }
   ```
8. Then compiled the `c` code to be a native library with :

   <figure><img src="https://2140186435-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpoPpsF6DyQtOrXy70rxC%2Fuploads%2FSjJGSbmc17URlHrFfSrY%2Fimage.png?alt=media&amp;token=56b679d5-398b-4960-b44b-793d846ebff3" alt="" width="563"><figcaption></figcaption></figure>
9. then Push it to the path : and here we success

   <figure><img src="https://2140186435-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpoPpsF6DyQtOrXy70rxC%2Fuploads%2FLr0wNdWrUkaxmQR8as4b%2Fimage.png?alt=media&amp;token=c3981120-54c2-4a91-8632-0fbdce51311a" alt="" width="563"><figcaption></figcaption></figure>
