Challenge Overview

A company's internal Android application is being evaluated for potential vulnerabilities as part of a routine security audit. The app, designed to manage employee notes and reminders, is suspected of having weak security measures. Your task is to explore the app's functionality, assess its security, and uncover any hidden flags or vulnerabilities that could expose sensitive data or bypass app protections. Each flag you uncover will give you insight into the app's structure and security, leading you closer to fully securing the application. The target machine is running an Android OS and is accessible at IP 10.10.1.103. It hosts a custom application named "eccappnotes" designed to conceal multiple flags. Participants must connect to the Android device, interact with the app, and use various tools to uncover hidden flags. Each flag discovered helps progress through the challenge, encouraging participants to explore the app's functionality and uncover its secrets systematically.

What You Will Learn

  • Android application reverse engineering, including decompiling the APK with jadx (jadx-gui) to understand app structure, activities, and storage mechanisms.
  • Practical use of Android Debug Bridge (ADB) to interact with the Android device, inspect application directories, and execute privileged debugging commands.
  • Exploiting insecure app configurations using ADB\\u2019s run-as command to access the app's private data directory and extract protected files.
  • Analyzing SQLite databases using tools like sqlite3 to query tables, retrieve stored PIN values, and uncover hidden flags.
  • Applying mobile forensic methodology, systematically examining application storage, local databases, and artifacts to identify sensitive data exposure and security weaknesses on the Android target (10.10.1.103).

Program Curriculum

Join over 1 Million professionals from the most renowned Companies in the world!

certificate

Choose the Pro Plan That Fits Your Learning Journey

Invest in your future with flexible Pro subscription plans. Whether you're starting your cybersecurity journey or expanding your expertise, choose the membership duration that works for you and gain access to our complete learning platform.

Monthly Plans
Annual Plans
Save 20% with our annual plans!

Pro

Ideal for continuous learning, offering extensive resources with 900+ courses and diverse Learning Paths to enhance your skills.

$ 599.00
Billed annually or $69.00 billed monthly

What is included

  • Access to 900+ Premium Short Courses
  • 70+ Structured Learning Paths
  • Validation of Completion with All Courses and Learning Paths
  • New Courses Added Every Month
Early Access Offer

Pro +

Experience immersive learning with Practice Labs and CTF Challenges for comprehensive skill-building.

$ 699.00
Billed annually or $79.00 billed monthly

Everything in Pro and

  • 500+ Practice Labs with Guided Instructions
  • 400+ CTF Challenges with Detailed Walkthroughs
  • New Practice Labs and Challenges Added Every Month

Related CTF Challenges

1 of 49