TCP1P CTF 2023 — Mobile Writeups
Mobile challenge solutions from TCP1P CTF: exported activity exploitation, implicit intent hijacking, and a WebView/JS interface/content provider chain.
Mobile challenge solutions from TCP1P CTF: exported activity exploitation, implicit intent hijacking, and a WebView/JS interface/content provider chain.
Part 1: InsecureShop walkthrough covering insecure logging, hardcoded credentials, insecure data storage, SSL bypass, and URL validation issues.
Part 2: insecure broadcast receivers, implicit intent hijacking, intent redirection to protected components, and WebView file exfiltration.