Mohamed reda·Mar 1, 2025How I was able to get two account takeovers via OAuth custom scheme hijacking at the same targetFirst: Deep linking is a method of sending data directly to a native application from an external source. A deep link typically looks like…A response icon1A response icon1
Tobias König·Apr 3, 2022OWASP UnCrackable App for Android Level 2 — WalkthroughThe UnCrackable App for Android Level 2 is a reverse-engineering challenge. It is similar to the first challenge we discussed previously…
Adham A. Makroum·May 17, 2025Flutter TLS Bypass: How to Intercept HTTPS Traffic When all other Frida Scripts FailIn this article, I’ll walk you through my journey in intercepting HTTPS traffic from a APK based on Flutter during a pentesting engagement…A response icon6A response icon6
InInfoSec Write-upsbyYoKo Kho·Feb 21, 2025Exploiting Unsanitized URL Handling & SQL Injection via Deep Links in iOS App: Write-up of FlipcoinBreaking Down Data Exfiltration via Unsanitized External URL Handling and SQL Injection through Deep Links
Happy Jester·Jan 7, 2025Xiaomi 13 Pro Code Execution via GetApps DOM Cross-Site Scripting (XSS)بِسْمِ اللَّـهِ الرَّحْمَـٰنِ الرَّحِيمِA response icon2A response icon2
Mohammad Yaser·Dec 27, 2024Deep Link Hijacking to Full Account Takeover — Complete GuideHow I could Hijack the authentication Deep Link, contains the authentication token for the victim, leading to full account takeoverA response icon1A response icon1
Ahmed Hesham·Aug 5, 2024ASCWG CTF 2024 — Android Challenges Solution & Source Codeبِسْمِ اللَّـهِ الرَّحْمَـٰنِ الرَّحِيم
InInfoSec Write-upsbyHacktivities·Aug 14, 2020Hacker101 CTF: Android Challenge WriteupsIn this article, I will be demonstrating how to solve the Hacker101 CTF (Capture The Flag) challenges for the Android category. Hacker101…A response icon1A response icon1
InInfoSec Write-upsbySandeep Vishwakarma·Nov 3, 2023A step-by-step Android penetration testing guide for beginnersGreetings fellow hackers, my name is Sandy, Security Analyst and Bug bounty hunter.A response icon7A response icon7
Yogasatriautama·Mar 25, 2024Android Pentest: Install Nox Player & Burp SuiteDownload Nox Player at https://www.bignox.com/A response icon1A response icon1
+Ch0pin🕷️·May 31, 2022Pending Intents: A Pentester’s viewFew days ago I came across an interesting case of vulnerability posted at the AndroidInfoSec’s facebook page. Since there are not many…A response icon1A response icon1
Ahmad Halabi·Dec 23, 2023The ART of Chaining VulnerabilitiesDeep Dive into breaking applications and chaining vulnerabilities to hack complete infrastructures.A response icon5A response icon5
Mohamed reda·Nov 3, 2024CyCTF qualification 2024: CyMob-CommanderHello, everyone! Today, I’m gonna explain how I solved the CyMob-Commander CyCTF Qualification 2024.
dnelsaka·May 29, 2024An interesting Bug that I found in Android Mobile ApplicationA response icon2A response icon2