InsecureShop — Android App Exploitation, pt. 1
Part 1: InsecureShop walkthrough covering insecure logging, hardcoded credentials, insecure data storage, SSL bypass, and URL validation issues.
Part 1: InsecureShop walkthrough covering insecure logging, hardcoded credentials, insecure data storage, SSL bypass, and URL validation issues.
Part 2: insecure broadcast receivers, implicit intent hijacking, intent redirection to protected components, and WebView file exfiltration.
Part 3: arbitrary code execution via third-party package context loading; vulnerabilities 16-18 listed as stubs.