
vuln-bank-mobile
A deliberately vulnerable mobile banking application designed for practicing mobile security testing. Features common vulnerabilities found in…

A deliberately vulnerable mobile banking application designed for practicing mobile security testing. Features common vulnerabilities found in…

Static analysis tool for iOS applications that extracts links, API keys, subdomains, binary info, linked libraries, and strings to aid mobile…

Repository for the Smartphone Pentest Framework (SPF)

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

Modular Android APK security analysis framework integrating static, dynamic, and reverse engineering tools for comprehensive vulnerability assessment…

Android exploit collection with C-based payloads for mobile device penetration testing and security research.

Damn Vulnerable iOS App (DVIA) is an iOS application that is damn vulnerable. Its main goal is to provide a platform to mobile security…

Curated penetration testing wiki with daily-updated techniques, scripts, and checklists for reconnaissance, web, cloud, mobile, and…

Complete Solution for VAPT/AppSec and Pentesting Guide: Web | Mobile | API | Thick Client | Source Code Review | DevSecOps | Wireless | Network…

Frida scripts for mobile application dynamic-analysis.

Proof-of-concept exploit for an actively exploited Zimbra Collaboration Suite vulnerability, designed for authorized penetration testing and…

Proof-of-concept exploit scripts for CVE-2024-8068 and CVE-2024-8069, focused on authorized penetration testing, educational labs, and defensive…

Automated SSL/TLS client security testing tool for detecting MITM vulnerabilities in thick clients, mobile apps, and network appliances.

Simple script for testing CVE-2016-2402 and similar flaws

Mobile Mouse 3.6.0.4 - Remote Code Execution - CVE-2023-31902

Nmap script to exploit CVE-2023-35078 - Mobile Iron Core

CVE-2025-40602 is a local privilege escalation vulnerability in the appliance management console (AMC) of SonicWall Secure Mobile Access (SMA) 1000…

Documents an OTP verification bypass vulnerability in Ascertia SigningHub, allowing attackers to brute-force OTP codes and impersonate mobile…