Skip to content

jaiswalakshansh/Vuldroid

master
Switch branches/tags

Name already in use

A tag already exists with the provided branch name. Many Git commands accept both tag and branch names, so creating this branch may cause unexpected behavior. Are you sure you want to create this branch?
Code

Latest commit

 

Git stats

Files

Permalink
Failed to load latest commit information.
Type
Name
Latest commit message
Commit time
 
 
 
 
 
 
 
 

Vuldroid

Awesome supports Android

Vuldroid is a Vulnerable Android Application made with security issues in order to demonstrate how they can occur in code.

Vulnerabilities Covered:

  • Code Execution via Malicious App
  • Steal Files via Webview using XHR request
  • Steal Files using Fileprovider via Intents
  • Steal Password ResetTokens/MagicLoginLinks
  • Webview Xss via Exported Activity
  • Webview Xss via DeepLink
  • Intent Sniffing Between Two Applications
  • Reading User Email via Broadcasts

To Get started:

  • Install the APK from the repository and play around
  • Find the areas where you think this can be exploited
  • I have also written a blog that you can refer as walkthrough but make sure you try yourself first
  • If you want to use your own firebase project for authentication clone the repo and remove the google-services.json and add your project one.

About

Vuldroid is a Vulnerable Android Application made with security issues in order to demonstrate how they can occur in code

Topics

Resources

License

Stars

Watchers

Forks

Packages

No packages published

Languages