InsecureShop — Android App Exploitation, pt. 1
Part 1: InsecureShop walkthrough covering insecure logging, hardcoded credentials, insecure data storage, SSL bypass, and URL validation issues.
Filter every CVE deep-dive and write-up by title, CVE id, vendor, tag, or body text. Matches are found across all pages, not just this one.
16 posts
Part 1: InsecureShop walkthrough covering insecure logging, hardcoded credentials, insecure data storage, SSL bypass, and URL validation issues.
Part 2: insecure broadcast receivers, implicit intent hijacking, intent redirection to protected components, and WebView file exfiltration.
Part 3: arbitrary code execution via third-party package context loading; vulnerabilities 16-18 listed as stubs.
HackTheBox Pandora: SNMP credential leak → PandoraFMS unauthenticated SQLi to RCE → SUID binary path hijacking for root.
Linux kernel exploitation for K3RN3LCTF 2021: stack buffer overflow in a kernel module, KASLR leak via sread(), ROP chain, and KPTI trampoline bypass.
CoalFire CTF challenge notes covering stack shellcode injection, ret2libc, write-what-where, anti-debug bypass, and Firefox profile forensics.
Nothing matches that.