THIS SOFTWARE IS PROVIDED FOR AUTHORIZED SECURITY RESEARCH ONLY.
-
Unauthorized Access is Illegal: Using this tool on devices you do not own or have explicit written authorization to test is a criminal offense under applicable laws.
-
Authorization Required: You MUST have:
- Written permission from the device owner
- Signed authorization agreement
- Clear scope of testing defined
This Proof of Concept demonstrates password reset via Dhizuku Device Owner API. It is intended for:
- Security researchers documenting vulnerabilities
- Penetration testers with proper authorization
- Educational purposes in controlled environments
Previous version: Used local DeviceAdminReceiver with DevicePolicyManager.resetPassword() — limited to API 21-28.
This version: Uses Dhizuku to obtain Device Owner privileges. The password reset operation runs in Dhizuku's process with full Device Owner authority.
┌─────────────────┐ ┌─────────────────┐ ┌─────────────────┐
│ This App │ │ Dhizuku │ │ Android │
│ (Client) │──────▶│ (DO Server) │──────▶│ Framework │
│ │ API │ │ DPM │ │
│ Dhizuku.init() │ │ DeviceOwnerSvc │ │ resetPassword() │
│ bindService() │ │ DPM access │ │ │
└─────────────────┘ └─────────────────┘ └─────────────────┘
Flow:
- App initializes Dhizuku API connection
- Requests permission from Dhizuku
- Binds to
DeviceOwnerService(UserService running in Dhizuku's process) - Calls
resetPassword()through the service — executed with Device Owner privileges
- Dhizuku app installed and activated as Device Owner
- Activate via ADB:
adb shell dpm set-device-owner com.rosan.dhizuku/.server.DhizukuDAReceiver - Or use Shizuku integration
- Activate via ADB:
- Android 8.0+ (API 26+) — required by Dhizuku API
- This app granted permission in Dhizuku
| Feature | Device Admin (old) | Dhizuku Device Owner (new) |
|---|---|---|
| API Level | 21-28 | 26+ |
| Privilege | Device Admin | Device Owner |
| Password reset | Blocked on API 29+ | Works on all versions |
| Setup | User grants admin | ADB/Shizuku activation |
| Scope | Single app | Shared via Dhizuku API |
android-deviceadmin-poc/
├── app/
│ ├── src/main/
│ │ ├── aidl/com/security/poc/deviceadminreset/
│ │ │ └── IDeviceOwnerService.aidl # AIDL interface for UserService
│ │ ├── java/com/security/poc/deviceadminreset/
│ │ │ ├── MainActivity.java # Dhizuku client logic
│ │ │ └── DeviceOwnerService.java # UserService (runs with DO privileges)
│ │ ├── res/
│ │ │ └── layout/
│ │ │ └── activity_main.xml
│ │ └── AndroidManifest.xml
│ └── build.gradle
├── build.gradle
├── settings.gradle
└── README.md
- Android Studio Arctic Fox or later
- Android SDK with API 26+ installed
- Device with Dhizuku installed and activated as Device Owner
- Clone this repository
- Open in Android Studio
- Sync Gradle files
- Build → Build Bundle(s) / APK(s) → Build APK(s)
- Install and activate Dhizuku as Device Owner on the test device
- Install this app
- Open the app and tap "Initialize Dhizuku"
- Grant permission when Dhizuku prompts
- Complete verification steps (PIN + security question)
- Enter new password and confirm reset
By using this software, you agree to:
- Only use on devices you own or have written authorization to test
- Not distribute for malicious purposes
- Report any discovered vulnerabilities responsibly
- Comply with all applicable laws and regulations
This project is provided for educational and authorized security research purposes only.
Last Updated: 2026-06-13