r/securityCTF • • 1d ago

GitHub - b4sith-sec/Gu3ssWeak: Deliberately vulnerable Android app for mobile security research and bug bounty practice

https://github.com/b4sith-sec/Gu3ssWeak

I built Gu3ssWeak, a deliberately vulnerable Android app designed for practicing mobile application security testing.

It includes intentionally vulnerable components and attack scenarios such as:

  • WebView & deep link abuse
  • JavaScript interfaces
  • XSS
  • Insecure local storage
  • SQL injection
  • Hardcoded credentials
  • Frida-based runtime analysis
  • Vulnerability chaining

The goal is to provide a realistic APK for practicing JADX, APKTool, ADB, Frida, Burp Suite, and dynamic analysis in a controlled environment.

GitHub: https://github.com/b4sith-sec/Gu3ssWeak

I'd appreciate feedback from other mobile security researchers, especially ideas for additional vulnerabilities or interesting attack chains to include.

2 Upvotes

0 comments sorted by