{"id":13649750,"url":"https://github.com/jaiswalakshansh/Vuldroid","last_synced_at":"2025-04-22T15:30:51.624Z","repository":{"id":133868404,"uuid":"291808861","full_name":"jaiswalakshansh/Vuldroid","owner":"jaiswalakshansh","description":"Vuldroid is a Vulnerable Android Application made with security issues in order to demonstrate how they can occur in code","archived":false,"fork":false,"pushed_at":"2021-09-18T08:25:30.000Z","size":18383,"stargazers_count":59,"open_issues_count":1,"forks_count":15,"subscribers_count":3,"default_branch":"master","last_synced_at":"2024-08-02T02:02:26.663Z","etag":null,"topics":["android-application","android-security","application-security","deeplink","vulnerable-application","webview-xss"],"latest_commit_sha":null,"homepage":"","language":"Java","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/jaiswalakshansh.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE.md","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null}},"created_at":"2020-08-31T19:42:37.000Z","updated_at":"2024-07-23T14:20:16.000Z","dependencies_parsed_at":"2024-01-03T04:02:36.368Z","dependency_job_id":null,"html_url":"https://github.com/jaiswalakshansh/Vuldroid","commit_stats":null,"previous_names":[],"tags_count":3,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jaiswalakshansh%2FVuldroid","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jaiswalakshansh%2FVuldroid/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jaiswalakshansh%2FVuldroid/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jaiswalakshansh%2FVuldroid/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/jaiswalakshansh","download_url":"https://codeload.github.com/jaiswalakshansh/Vuldroid/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":223900372,"owners_count":17222028,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["android-application","android-security","application-security","deeplink","vulnerable-application","webview-xss"],"created_at":"2024-08-02T02:00:24.217Z","updated_at":"2024-11-10T00:31:44.480Z","avatar_url":"https://github.com/jaiswalakshansh.png","language":"Java","funding_links":[],"categories":["Mobile Security","Tools","Android"],"sub_categories":["Vulnerable Applications for practice","Labs"],"readme":"\n# Vuldroid\n\t\n  ![Awesome](https://cdn.rawgit.com/sindresorhus/awesome/d7305f38d29fed78fa85652e3a63e154dd8e8829/media/badge.svg) ![supports Android](https://img.shields.io/badge/Android-4630EB.svg?style=flat-square\u0026logo=ANDROID\u0026labelColor=A4C639\u0026logoColor=fff)\u003cp\u003e\u003ca href=\"https://twitter.com/akshanshjaiswl\"\u003e\u003cimg src=\"https://img.shields.io/badge/twitter-%231DA1F2.svg?\u0026style=for-the-badge\u0026logo=twitter\u0026logoColor=white\" height=25\u003e\u003c/a\u003e \u003ca href=\"https://medium.com/@akshanshjaiswal\"\u003e\u003cimg src=\"https://img.shields.io/badge/medium-%2312100E.svg?\u0026style=for-the-badge\u0026logo=medium\u0026logoColor=white\" height=25\u003e\u003c/a\u003e \n\u003c/p\u003e\nVuldroid is a Vulnerable Android Application made with security issues in order to demonstrate how they can occur in code.\n\n\n\u003cimg src=\"https://github.com/jaiswalakshansh/Vuldroid/raw/master/images/logo.png\" align=\"centre\" height=\"600\" width=\"395\"\u003e\u003cimg src=\"https://github.com/jaiswalakshansh/Vuldroid/blob/master/images/screen1.png\" align=\"centre\" height=\"600\" width=\"395\"\u003e\u003cimg src=\"https://github.com/jaiswalakshansh/Vuldroid/blob/master/images/screen3.png\" align=\"right\" height=\"600\" width=\"320\"\u003e\n\n\n\n\n\n## Vulnerabilities Covered:\n- Code Execution via Malicious App\n- Steal Files via Webview using XHR request\n- Steal Files using Fileprovider via Intents\n- Steal Password ResetTokens/MagicLoginLinks\n- Webview Xss via Exported Activity\n- Webview Xss via DeepLink\n- Intent Sniffing Between Two Applications\n- Reading User Email via Broadcasts\n\n## To Get started:\n - Install the APK from the [repository](https://github.com/jaiswalakshansh/Vuldroid/blob/master/Apks/Vuldroid.apk?raw=true) and play around\n - Find the areas where you think this can be exploited\n - I have also written a [blog](https://medium.com/@akshanshjaiswal/vuldroid-app-walkthrough-8f8e4511cad5?sk=45daf0e7fcf7de3f6a92fe8574c070a9) that you can refer as walkthrough but make sure you try yourself first\n - If you want to use your own firebase project for authentication clone the repo and remove the google-services.json and add your project one.\n\n\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fjaiswalakshansh%2FVuldroid","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fjaiswalakshansh%2FVuldroid","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fjaiswalakshansh%2FVuldroid/lists"}