payatu / BugBazaar

Android BugBazaar: Your mobile appsec playground to Explore, Exploit, Excel
37 stars 5 forks source link
androidpentesting bugbazaar iospentesting mobile-app mobile-application mobile-development mobileappsecurity security

Android BugBazaar: Your mobile appsec playground to Explore, Exploit, Excel

Welcome to BugBazaar, your gateway to mastering Mobile penetration testing on the Android platform!

📱What is it?

BugBazaar is a comprehensive mobile application intentionally designed to be vulnerable, featuring over 30 vulnerabilities. Developed to emulate real-world scenarios, it includes more than 10 modules and features, each replicating real-world functions and the vulnerabilities surrounding them.

meme

🔍Why?

We've bundled 30+ vulnerabilities into a single application, saving you from downloading multiple apps to learn about mobile application pentesting. We've packed a lot into one.

meme

🎯For whom?

Whether you're a security enthusiast, developer, beginner exploring the mobile pentesting arena, or a professional looking to hone your skills, BugBazaar has something for everyone on the mobile pentesting learning curve.

meme

 

🤔What's in for me?

BugBazaar offers a wide range of vulnerabilities, from "RCE through insecure Dynamic Code Loading" to "One Click Account Takeover via deeplink." We cover "intent Spoofing" to "SQLite db injection," "WebView" bugs to "IPC" misconfigurations in Android  — we've got a lot of things covered.

meme

🤓Never-Ending Learning

What's more exciting? Stay in sync with the evolving landscape! BugBazaar regularly updates with fresh vulnerabilities and captivating challenges. Stay vigilant, stay ahead! Get Started Today!

📷Screenshots

Untitled (1715 x 1080 px)

⚠️Vulnerabilities

WEBVIEW

INTENT

Deep Link

IPC COMPONENTS

Injections

Unintended Data Leakage

Insecure Storage

OTHERS

Runtime exploitation

APP Protection

Core Team

Amit Kumar Prajapat Lead Security Consultant at Payatu- Mobile GitHub LinkedIn Twitter
Vedant Wayal Senior Security Consultant at Payatu - Mobile GitHub LinkedIn Twitter
Akshay Khilari Security Consultant at Payatu- Mobile GitHub LinkedIn