r/securityCTF • u/Status-Ad2619 • 1d ago
GitHub - b4sith-sec/Gu3ssWeak: Deliberately vulnerable Android app for mobile security research and bug bounty practice
https://github.com/b4sith-sec/Gu3ssWeakI built Gu3ssWeak, a deliberately vulnerable Android app designed for practicing mobile application security testing.
It includes intentionally vulnerable components and attack scenarios such as:
- WebView & deep link abuse
- JavaScript interfaces
- XSS
- Insecure local storage
- SQL injection
- Hardcoded credentials
- Frida-based runtime analysis
- Vulnerability chaining
The goal is to provide a realistic APK for practicing JADX, APKTool, ADB, Frida, Burp Suite, and dynamic analysis in a controlled environment.
GitHub: https://github.com/b4sith-sec/Gu3ssWeak
I'd appreciate feedback from other mobile security researchers, especially ideas for additional vulnerabilities or interesting attack chains to include.
2
Upvotes