An app I am working on at work was recently pen tested. One of the risks that came back in the report was that it has no proper Hook detection. I had implemented the RootBeer library but that was easily avoided.
A Frida script was created by the tester for the Android application to modify the root detection logic at run time. The script hooked into the System.exit method to return false instead of true. This prevented the application from exiting after the application detected that the device has been rooted.
It was recommended by the pen testers that we implement as many different checks as possible in order to deter reverse engineers.
One of those checks is to get the Android application to scan its own memory map file located at
/proc/<pid>/maps
where
<pid>
is the app’s process ID (PID).
I have checked the Android docs and can only find info on handling memory but nothing on scanning the memory. eg. https://developer.android.com/topic/performance/memory
I see you can "get a MemoryInfo object for the device's current memory status". But this only shows the available memory on the system.
Does anyone have a solution to this problem?