hpAndro1337

hpAndro1337

99 Stars

Repository for download all version of @hpAndro1337 (Android AppSec) application.

RavikumarRamesh
May 27, 2025
99 stars
Category
Vulnerable-labs
GitHub Stars
99
Project Added On
May 27, 2025
Contributors
1

@hpAndro1337 Android Application Security

CTF Style Android Security Challenges ctf.hpandro.raviramesh.info

hpAndro

Android AppSec (Kotlin) app will help you to practice for Android Security points. We do it for the right reasons - to help developers make their apps more secure. The best way to verify that your app follows secure mobile development best practices is to perform security assessments of the app, which can include automated mobile app security testing, fuzzing, manual penetration testing, and more. This application represents some of the knowledge we share with the infosec community. We are trying to build a vulnerable application based on OWASP Mobile Security Testing Guide.

We (@hpAndro and @_RaviRamesh) spend a lot of time attacking android app hacking, breaking encryption, finding bussiness logic flaws, penetration testing, and looking for sensitive data stored insecurely.

We try harder to build vulnerable application for you..

In this application we are covering below points:

  1. HTTP Traffic
  2. HTTP Traffic
  3. HTTPS Traffic
  4. Public Key Pinning
  5. Certificate Pinning Bypass (network_security_config.xml) [Coming Soon…]
  6. Certificate Pinning Bypass (okhttp) [Coming Soon…]
  7. Certificate Pinning Bypass (Cert check) [Coming Soon…]
  8. Certificate Pinning Bypass (Cert Hash match) [Coming Soon…]
  9. Non-HTTP Traffic
  10. TCP Traffic
  11. UDP Traffic
  12. WebSocket Traffic
  13. Web Socket (WS)
  14. Web Socket Secure (WSS)
  15. Root Detection
  16. Root Management Apps
  17. Potentially Dangerous Apps [Available in Master App]
  18. Root Cloaking Apps
  19. Test Keys
  20. Dangerous Props [Available in Master App]
  21. BusyBox Binary
  22. Su Binary [Available in Master App]
  23. Su Exists
  24. RW System [Available in Master App]
  25. SafetyNet [Coming Soon…]
  26. Using running processes [Coming Soon…]
  27. Emulator detection
  28. Virtual Phone Number [Available in Master App]
  29. Device IDs [Available in Master App]
  30. Hardware Specifications [Available in Master App]
  31. QEmu Detection [Available in Master App]
  32. File Based Checking [Available in Master App]
  33. IP Based Checking [Available in Master App]
  34. Package Name [Available in Master App]
  35. Debug Flag [Available in Master App]
  36. Network Operator Name [Available in Master App]
  37. Anti-Debugging detection
  38. PMS Hook Detection [Coming Soon…]
  39. Checking TracerPid [Coming Soon…]
  40. Using Fork and ptrace [Coming Soon…]
  41. Frida Detection [Coming Soon…]
  42. SafetyNet [Coming Soon…]
  43. Debuggable Flag [Coming Soon…]
  44. isDebugger Connected [Available in Master App]
  45. Timer Checks [Coming Soon…]
  46. JDWP-Related Data Structures [Coming Soon…]
  47. Insecure Data Storage
  48. SQLite Databases (Unencrypted)
  49. SQLite Databases (Encrypted) [Available in Master App]
  50. Realm Databases (Unencrypted) [Coming Soon…]
  51. Realm Databases (Encrypted) [Coming Soon…]
  52. Firebase Real-time Databases [Coming Soon…]
  53. Shared Preferences
  54. Internal Storage
  55. External Storage
  56. KeyStore [Available in Master App]
  57. KeyChain [Coming Soon…]
  58. Keyboard Cache [Coming Soon…]
  59. User Interface [Coming Soon…]
  60. App Backup [Coming Soon…]
  61. Screenshots [Coming Soon…]
  62. Memory [Available in Master App]
  63. User Dictionary Cache [Coming Soon…]
  64. Clipboard [Available in Master App]
  65. Activity data
  66. Logs
  67. Informational Logs
  68. Error Logs
  69. Warnings Logs
  70. Debug Logs
  71. Verbose Logs
  72. WTF Logs
  73. Content Providers
    1. SQL Injection
    2. File System Expose [Available in Master App]
  74. Encryption
    1. Message Authentication Codes [Coming Soon…]
    2. Message Digest [Coming Soon…]
    3. Signatures [Coming Soon…]
    4. Custom Implementations [Coming Soon…]
    5. Caesar Cipher
    6. Weak Key Generation [Coming Soon…]
    7. Weak Random Number [Coming Soon…]
    8. Weaker Padding [[Coming Soon…]](https://hp

... Content truncated. Click "See More" to view the full README.

Tool Information

Author

RavikumarRamesh

Project Added On

May 27, 2025

License

Open Source

Tags

security tool