~/research/notes
Mobile
9 posts
2025
Runner Mobile Hacking Labs
In this challenge, you’ll be working with a fictitious app called Run Time, which tracks your steps while running. Your objective is to bypass the app’s protections, inject a …
Captain No Hook Mobile Hacking Labs
Introduction The Captain No Hooks lab provides an in-depth exploration of iOS RASP (Runtime Application Self-Protection) defenses. This comprehensive guide focuses on how we can …
Time Trap Mobile Hacking Labs
Introduction In this challenge, you will explore the vulnerabilities in an internally used application named Time Trap, focusing on Command Injection. Time Trap is a fictional …
Gotham Times Mobile Hacking Labs
Introduction The Gotham Times lab provides an in-depth exploration of iOS webviews and their security implications. This comprehensive guide focuses on how vulnerabilities in …
Flipcoin Wallet Mobile Hacking Lab
Flipcoin Wallet CTF - SQL Injection Challenge In this CTF challenge, I'll explore a SQL Injection vulnerability ( Client Side) in the Flipcoin Wallet iOS app. I'll walk you through …
Breaking Flutter’s RSA Encryption: Reverse Engineering and Hooking Techniques
In my previous post Bypassing MTLS in Flutter, I discussed how MTLS is generaly implemented in the Flutter framework. Depending on how an application is developed, exposing …
2024
Bypass MTLS Flutter
Overview In this blog post, we'll tackle: bypassing mTLS with Flutter due to common mistake ( ¯\(ツ)/¯ ) from developers. Before we continue.. into the specifics, it's essential to …
Decrypt WhatsApp Msgs Android (Investigator)
Overview In this blog post, we'll tackle a compelling challenge: decrypting WhatsApp messages. However, before we dive into the solution, it's crucial to grasp some foundational …
2022
No posts matched your search.