TCP1P CTF 2023 — Mobile Writeups
Mobile challenge solutions from TCP1P CTF: exported activity exploitation, implicit intent hijacking, and a WebView/JS interface/content provider chain.
Mobile challenge solutions from TCP1P CTF: exported activity exploitation, implicit intent hijacking, and a WebView/JS interface/content provider chain.
Theft of arbitrary files from a non-exported FileProvider via improper setResult() in a third-party welcome screen library.
Part 2: insecure broadcast receivers, implicit intent hijacking, intent redirection to protected components, and WebView file exfiltration.
Part 3: arbitrary code execution via third-party package context loading; vulnerabilities 16-18 listed as stubs.