
vuln-bank-mobile
A deliberately vulnerable mobile banking application designed for practicing mobile security testing. Features common vulnerabilities found in…

A deliberately vulnerable mobile banking application designed for practicing mobile security testing. Features common vulnerabilities found in…

Install and run Metasploit Framework 6 on Android via Termux with automated setup, payload generation (msfvenom), and full msfconsole access for…

Static analysis tool for iOS applications that extracts links, API keys, subdomains, binary info, linked libraries, and strings to aid mobile…

Repository for the Smartphone Pentest Framework (SPF)

Modular Android APK security analysis framework integrating static, dynamic, and reverse engineering tools for comprehensive vulnerability assessment…

Android exploit collection with C-based payloads for mobile device penetration testing and security research.

Damn Vulnerable iOS App (DVIA) is an iOS application that is damn vulnerable. Its main goal is to provide a platform to mobile security…

Curated penetration testing wiki with daily-updated techniques, scripts, and checklists for reconnaissance, web, cloud, mobile, and…

Complete Solution for VAPT/AppSec and Pentesting Guide: Web | Mobile | API | Thick Client | Source Code Review | DevSecOps | Wireless | Network…

Frida scripts for mobile application dynamic-analysis.

Automated SSL/TLS client security testing tool for detecting MITM vulnerabilities in thick clients, mobile apps, and network appliances.

Simple script for testing CVE-2016-2402 and similar flaws

Proof-of-concept exploit for CVE-2020-11990 targeting Apache Cordova applications, demonstrating a remote code execution vulnerability in the mobile…

Proof of concept for CVE-2022-1364 against Alibaba's UC Browser

Unlock the bootloader of any exploitable device vulnerable to CVE-2021-30327

Proof-of-concept exploit for CVE-2021-1965, a WiFi zero-click RCE in Android's MBSSID parsing, causing buffer overflow and device reboot.

Local Root vulnerability- CVE-2019-13272 / Security Bypass Vulnerability – CVE-2019-14287/Google Android - 'Stagefright' Remote Code Execution -…

Proof-of-concept exploit for CVE-2017-0411, a privilege escalation vulnerability in Android's kernel, demonstrating exploitation via Shell script.