GithubHelp home page GithubHelp logo

rickbrian / bugbazaar Goto Github PK

View Code? Open in Web Editor NEW

This project forked from payatu/bugbazaar

0.0 0.0 0.0 54.76 MB

一个不错的项目,有各种检测值得学习一下哈

C++ 0.48% Java 97.43% HTML 1.40% CMake 0.70%

bugbazaar's Introduction

Android BugBazaar: Your mobile appsec playground to Explore, Exploit, Excel

Welcome to BugBazaar, your gateway to mastering Mobile penetration testing on the Android platform!

📱What is it?

BugBazaar is a comprehensive mobile application intentionally designed to be vulnerable, featuring over 30 vulnerabilities. Developed to emulate real-world scenarios, it includes more than 10 modules and features, each replicating real-world functions and the vulnerabilities surrounding them.

meme

🔍Why?

We've bundled 30+ vulnerabilities into a single application, saving you from downloading multiple apps to learn about mobile application pentesting. We've packed a lot into one.

meme

🎯For whom?

Whether you're a security enthusiast, developer, beginner exploring the mobile pentesting arena, or a professional looking to hone your skills, BugBazaar has something for everyone on the mobile pentesting learning curve.

meme

 

🤔What's in for me?

BugBazaar offers a wide range of vulnerabilities, from "RCE through insecure Dynamic Code Loading" to "One Click Account Takeover via deeplink." We cover "intent Spoofing" to "SQLite db injection," "WebView" bugs to "IPC" misconfigurations in Android  — we've got a lot of things covered.

meme

🤓Never-Ending Learning

What's more exciting? Stay in sync with the evolving landscape! BugBazaar regularly updates with fresh vulnerabilities and captivating challenges. Stay vigilant, stay ahead! Get Started Today!

📷Screenshots

Untitled (1715 x 1080 px)

⚠️Vulnerabilities

WEBVIEW

  • XSS
  • OPEN REDIRECTION
  • Stealing User token Via javascript Interface
  • Access of Arbitrary files via insecure Flags
  • Stealing of Arbitrary files via Insecure WebResourceResponse
  • Account Takeover via Steal Session id

INTENT

  • Intent interception
  • Account takeover via intent Spoofing
  • Steal User's Contact via Insecure Pending Intent
  • RCE through insecure Dynamic Code Loading

Deep Link

  • CSRF
  • Deep link hijacking
  • Content Spoofing
  • One Click Account Takeover

IPC COMPONENTS

  • Exported Components
  • Steal User's Contact via typo permission in Content Provider
  • Arbitrary data write to Content provider
  • Access to Protected Components via Recevier

Injections

  • SQL Injection via user input

OTHERS

  • Improper Input Validation
  • Insecure Logging
  • Insecure Storage
  • Unrestricted file upload
  • Firebase Misconfiguration
  • Passcode Bypass
  • Copy paster Buffer
  • Tapjacking
  • hardcoded secrets
  • Improper exception Handling
  • Debuggable
  • Backup enabled
  • Task Hijacking
  • Man in the Disk Attack

APP Protection

  • EASY LEVEL

    • RootBear Library
  • MEDIUM LEVEL

    • Magisk detect
    • Emulator Check
    • FRIDA DETECTION
  • ADVANCE LEVEL - !!! IN PROGRESS WILL UPDATE IN NEXT RELEASE

// MANY MORE BUGS !!! COMING SOON 😎

Core Team

Amit Kumar Prajapat Lead Security Consultant at Payatu- Mobile GitHub LinkedIn Twitter
Vedant Wayal Senior Security Consultant at Payatu - Mobile GitHub LinkedIn Twitter
Akshay Khilari Security Consultant at Payatu- Mobile GitHub LinkedIn

bugbazaar's People

Contributors

banditamit avatar banditvedant avatar banditaparna avatar effortlessdevsec avatar banditakshay avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.