InjuredAndroid : A Vulnerable Android Application

InjuredAndroid is a vulnerable Android application with ctf examples based on bug bounty findings, exploitation concepts, and pure creativity.

Setup for a physical device

  • Download injuredandroid.apk from Github
  • Enable USB debugging on your Android test phone.
  • Connect your phone and your pc with a usb cable.
  • Install via adb. adb install injuredandroid.apk. Note: You need to use the absolute path to the .apk file or be in the same directory.

Also Read – NFStream : A Flexible Network Data Analysis Framework

Setup for an Android Emulator using Android Studio

  • Download the apk file.
  • Start the emulator from Android Studio (I recommend downloading an emulator with Google APIs so root adb can be enabled).
  • Drag and drop the .apk file on the emulator and injuredandroid.apk will install.

Tips and CTF Overview

De-compiling the Android app is highly recommended.

  • XSSTEST is just for fun and to raise awareness on how WebViews can be made vulnerable to XSS.
  • The login flags just need the flag submitted.
  • The flags without a submit that demonstrate concepts will automatically register in the “Flags Overview” Activity.
  • The last two flags don’t register because there currently isn’t a remote verification method (I plan to change this in a future update). This was done to prevent using previous flag methods to skip the exploitation techniques.
  • There is one flag with a Pentesterlab 1 month gift key. The key is stored in a self destructing note after It’s read, do not close the browser tab before copying the url.
  • The exclamatory buttons on the bottom right will give users up to three tips for each flag.
R K

Recent Posts

Shadow-rs : Harnessing Rust’s Power For Kernel-Level Security Research

shadow-rs is a Windows kernel rootkit written in Rust, demonstrating advanced techniques for kernel manipulation…

1 week ago

ExecutePeFromPngViaLNK – Advanced Execution Of Embedded PE Files via PNG And LNK

Extract and execute a PE embedded within a PNG file using an LNK file. The…

2 weeks ago

Red Team Certification – A Comprehensive Guide To Advancing In Cybersecurity Operations

Embark on the journey of becoming a certified Red Team professional with our definitive guide.…

3 weeks ago

CVE-2024-5836 / CVE-2024-6778 : Chromium Sandbox Escape via Extension Exploits

This repository contains proof of concept exploits for CVE-2024-5836 and CVE-2024-6778, which are vulnerabilities within…

3 weeks ago

Rust BOFs – Unlocking New Potentials In Cobalt Strike

This took me like 4 days (+2 days for an update), but I got it…

3 weeks ago

MaLDAPtive – Pioneering LDAP SearchFilter Parsing And Security Framework

MaLDAPtive is a framework for LDAP SearchFilter parsing, obfuscation, deobfuscation and detection. Its foundation is…

3 weeks ago