{"id":13386264,"url":"https://github.com/xtiankisutsa/awesome-mobile-CTF","last_synced_at":"2025-03-13T10:31:25.198Z","repository":{"id":15776638,"uuid":"78745881","full_name":"xtiankisutsa/awesome-mobile-CTF","owner":"xtiankisutsa","description":"This is a curated list of mobile based CTFs, write-ups and vulnerable apps. Most of them are android based due to the popularity of the platform. ","archived":false,"fork":false,"pushed_at":"2022-06-26T11:20:21.000Z","size":240,"stargazers_count":961,"open_issues_count":1,"forks_count":199,"subscribers_count":55,"default_branch":"master","last_synced_at":"2024-05-20T20:43:12.409Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"lgpl-3.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/xtiankisutsa.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2017-01-12T13:02:50.000Z","updated_at":"2024-05-17T05:53:31.000Z","dependencies_parsed_at":"2022-08-07T08:01:18.882Z","dependency_job_id":null,"html_url":"https://github.com/xtiankisutsa/awesome-mobile-CTF","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/xtiankisutsa%2Fawesome-mobile-CTF","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/xtiankisutsa%2Fawesome-mobile-CTF/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/xtiankisutsa%2Fawesome-mobile-CTF/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/xtiankisutsa%2Fawesome-mobile-CTF/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/xtiankisutsa","download_url":"https://codeload.github.com/xtiankisutsa/awesome-mobile-CTF/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":243386083,"owners_count":20282689,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-07-30T11:01:41.987Z","updated_at":"2025-03-13T10:31:24.866Z","avatar_url":"https://github.com/xtiankisutsa.png","language":null,"funding_links":[],"categories":["Uncategorized","Pre-built Cyber Range Environments and Content","Others","Others (1002)","Other Lists"],"sub_categories":["Uncategorized","TeX Lists"],"readme":"# awesome-mobile-CTF\nThis is a curated list of mobile based CTFs, write-ups and vulnerable mobile apps. Most of them are android based due to the popularity of the platform. \n\nInspired by [android-security-awesome](https://github.com/ashishb/android-security-awesome), [osx-and-ios-security-awesome](https://github.com/ashishb/osx-and-ios-security-awesome) and all the other awesome security lists on [@github](https://github.com/search?utf8=%E2%9C%93\u0026q=awesome+security\u0026type=Repositories\u0026ref=searchresults).\n\n## Mobile CTF challenges\n* [Google CTF 2021](https://github.com/google/google-ctf/tree/master/2021/quals/pwn-tridroid)\n* Google CTF 2020 [writeup 1](https://github.com/google/google-ctf/tree/master/2020/quals/reversing-android), [writeup 2](https://github.com/luker983/google-ctf-2020/tree/master/reversing/android)\n* [HacktivityCon CTF Mobile 2020](https://github.com/csivitu/CTF-Write-ups/blob/master/HacktivityCon%20CTF/Mobile/Mobile%20One/mobile_one.apk)\n* [Trend Micro CTF 2020](https://github.com/Hong5489/TrendMicroCTF2020/blob/main/mobile2/Keybox.apk)\n* [KGB Messenger](https://github.com/tlamb96/kgb_messenger)\n* [ASIS CTF — ShareL Walkthrough](https://medium.com/bugbountywriteup/asis-ctf-sharel-walkthrough-da32f3533b40?)\n* [Android reversing challenges](https://github.com/kiyadesu/android-reversing-challenges)\n* [Android app for IOT CTF](https://github.com/atekippe/SecDSM_April_2019_IOT_CTF_Android_APP)\n* [CyberTruck Challenge 2019 (Detroit USA)](https://github.com/nowsecure/cybertruckchallenge19)\n* [Matryoshka-style Android reversing challenge](https://github.com/o-o-overflow/dc2019q-vitor-public)\n* [Cybertruckchallenge19](https://github.com/nowsecure/cybertruckchallenge19)\n* [You Shall Not Pass - BSides Canberra 2019](https://gitlab.com/cybears/fall-of-cybeartron/tree/master/challenges/rev/youshallnotpass)\n* [Mobile challenges collection](https://drive.google.com/folderview?id=0B7rtSe_PH_fTWDQ0RC1DeWVoVUE\u0026usp=sharing)\n* [BSidesSF 2018 CTF](https://github.com/antojoseph/androidCTF)\n* [h1-702-2018-ctf-wu](https://github.com/luc10/h1-702-2018-ctf-wu)\n* [THC CTF 2018 - Reverse - Android serial](https://github.com/ToulouseHackingConvention/bestpig-reverse-android-serial)\n* [Android crack me challenges](https://github.com/reoky/android-crackme-challenge)\n* [OWASP crack me](https://github.com/OWASP/owasp-mstg/tree/master/Crackmes)\n* [Rednaga Challenges](https://github.com/rednaga/training/tree/master/DEFCON23/challenges)\n* [iOS CTF](https://www.ivrodriguez.com/mobile-ctf)\n* [Android Hacking Event 2017: AES-Decrypt](https://team-sik.org/wp-content/uploads/2017/06/AES-Decrypt.apk_.zip)\n* [Android Hacking Event 2017: Token-Generator](https://team-sik.org/wp-content/uploads/2017/06/Token-Generator.apk_.zip)\n* [Android Hacking Event 2017: Flag-Validator](https://team-sik.org/wp-content/uploads/2017/06/FlagValidator.apk_.zip)\n* [Android Hacking Event 2017: You Can Hide – But You Cannot Run](https://team-sik.org/wp-content/uploads/2017/06/YouCanHideButYouCannotRun.apk_.zip)\n* [Android Hacking Event 2017: Why Should I Pay?](https://team-sik.org/wp-content/uploads/2017/06/WhyShouldIPay.apk_.zip)\n* [Android Hacking Event 2017: Esoteric](https://team-sik.org/wp-content/uploads/2017/06/esoteric.apk_.zip)\n* [Android Hacking Event 2016: StrangeCalculator](https://team-sik.org/wp-content/uploads/2016/06/strangecalculator.apk_.zip)\n* [Android Hacking Event 2016: ReverseMe](https://team-sik.org/wp-content/uploads/2016/06/ReverseMe.apk_.zip)\n* [Android Hacking Event 2016: ABunchOfNative](https://team-sik.org/wp-content/uploads/2016/06/aBunchOfNative.apk_.zip)\n* [Android Hacking Event 2016: DynChallenge](https://team-sik.org/wp-content/uploads/2016/06/dynChallenge.apk_.zip)\n* [PicoCTF-2014: Pickle Jar - 30](http://shell-storm.org/repo/CTF/PicoCTF-2014/Forensics/Pickle%20Jar%20-%2030/)\n* [PicoCTF-2014: Revenge of the Bleichenbacher](http://shell-storm.org/repo/CTF/PicoCTF-2014/crypto/Revenge%20of%20the%20Bleichenbacher%20-%20170/)\n* [Android MIT LL CTF 2013](https://github.com/huyle333/androidmitllctf2013)\n* [Evil Planner Bsides Challenge](https://labs.mwrinfosecurity.com/blog/2013/03/11/bsides-challenge/)\n* [Crack-Mes](http://www.droidsec.org/wiki/#crack-mes)\n* [GreHack-2012 - GrehAndroidMe](http://shell-storm.org/repo/CTF/GreHack-2012/reverse_engineering/100-GrehAndroidMe.apk/)\n* [Hackplayers.com Crackmes (in Spanish so an extra challenge): crackme 1 ](http://www.hackplayers.com/2010/12/reto-android-crackme1.html)\n* [Hackplayers.com Crackmes (in Spanish so an extra challenge): crackme 2](http://www.hackplayers.com/2011/12/reto-14-android-crackme2.html)\n* [Hack.Lu's CTF 2011 Reverse Engineering 300](http://shell-storm.org/repo/CTF/Hacklu-2011/Reversing/Space%20Station%200xB321054A%20(300)/)\n* [Androidcracking.blogspot.com's Crackme’s: cracker 0](http://androidcracking.blogspot.com/2012/01/way-of-android-cracker-0-rewrite.html)\n* [Androidcracking.blogspot.com's Crackme’s: cracker 1](http://androidcracking.blogspot.com/2010/10/way-of-android-cracker-1.html)\n* [Insomnia'hack-2K11](http://shell-storm.org/repo/CTF/Insomnia'hack-2K11/Reverse/validate.apk)\n* [CSAW-2011: Reversing101](http://shell-storm.org/repo/CTF/CSAW-2011/Reversing/Reversing101%20-%20100%20Points/)\n* [Defcon-19-quals: Binary_L33tness](http://shell-storm.org/repo/CTF/Defcon-19-quals/Binary_L33tness/b300/)\n* [Crack me's](https://github.com/as0ler/Android-Examples)\n* [SecuInside: CTF2011](http://big-daddy.fr/repository/CTF2011/SecuInside-CTF/Q7/)\n* [EnoWars-CTF2011: broken_droid](http://big-daddy.fr/repository/CTF2011/EnoWars-CTF/broken_droid/)\n* [Anonim1133](https://github.com/anonim1133/CTF)\n* [Challenge4ctf](https://github.com/CvvT/challenge_for_ctf)\n* [Ctfpro](https://github.com/jhong01/ctfpro)\n* [CTFDroid](https://github.com/rajasaur/CTFDroid)\n* [Android_ctf](https://github.com/artwyman/android_ctf)\n* [Robot CTF Android](https://github.com/KappaEtaKappa/Robot-CTF-android)\n* [Cl.ctfk](https://github.com/CTFK/cl.ctfk)\n* [Cryptax](https://github.com/cryptax/challenges)\n\n## CTF Writeups\n### 2022\n* [NahamCon CTF 2022 Write-up: Click Me! Android challenge](https://infosecwriteups.com/nahamcon-ctf-2022-write-up-click-me-android-challenge-63ccba7cb663)\n* [MRCTF2022-Stuuuuub](https://github.com/LLeavesG/MRCTF2022-Stuuuuub)\n\n### 2021\n* H@cktivityCon 2021 CTF - [writeup 1](https://blog.ikuamike.io/posts/2021/hacktivitycon-2021-ctf/), [writeup 2](https://infosecwriteups.com/h-cktivitycon-2021-ctf-writeup-reactor-android-challenge-85d1d03d4502)\n* [Write-up du CTF Android](https://evabssi.com/write-up-du-ctf-android/)\n* [Cellebrite 2021 CTF – Investigating Heisenberg’s Android Device](https://cellebrite.com/en/part-1-walk-through-of-answers-to-the-2021-ctf-investigating-heisenbergs-android-device/)\n* [Cellebrite 2021 CTF – Marsha’s iPhone (FFS and Backup)](https://cellebrite.com/en/part-3-walk-through-of-answers-to-the-2021-ctf-marshas-iphone-ffs-and-backup/)\n* [Cellebrite 2021 CTF – Beth’s iPhone](https://cellebrite.com/en/part-4-walk-through-of-answers-to-the-2021-ctf-beths-iphone/)\n* [Cellebrite CTF 2021 Writeup](https://medium.com/@williamskosasi/cellebrite-ctf-2021-writeup-b73d821a708)\n* H@cktivitycon 2021 — Mobile challenge writeup - [writeup 1](https://desterhuizen.medium.com/h-cktivitycon-2021-mobile-challenge-writeup-2e1a8b0bc9d6), [writeup 2](https://infosecwriteups.com/h-cktivitycon-2021-ctf-writeup-reactor-android-challenge-85d1d03d4502)\n* [CTF Write-Up: Kryptonite](https://infosecwriteups.com/ctf-write-up-kryptonite-293f2f66c004)\n* [NahamCon 2021 Writeups](https://github.com/Class-3E/NahamCon2021-Writeups/tree/master/Mobile/Resourceful)\n* [BELKASOFT CTF MAY 2021: WRITE-UP](https://belkasoft.com/belkactf-may2021-writeup)\n\n### 2020\n* [Trend Micro CTF 2020 — Keybox writeup](https://tatocaster.medium.com/trend-micro-ctf-2020-keybox-writeup-cf5a69d2d091)\n* STACK the Flags 2020: Mobile Challenges Write Up [writeup 1](https://suntanchicken.medium.com/stack-the-flags-2020-mobile-challenges-write-up-493578091e07), [writeup 2](https://github.com/Hong5489/TrendMicroCTF2020/tree/main/mobile2)\n* [HacktivityCon CTF Mobile Writeup](https://www.goggleheadedhacker.com/blog/post/19)\n* [CyberSpaceKenya CTF](https://blog.ikuamike.io/posts/2020/cyberspacectf-zulumeats3/)\n* [Magnet Virtual Summit 2020 CTF (Anroid)](https://www.stark4n6.com/2020/06/magnet-virtual-summit-2020-ctf-android.html)\n* Magnet Virtual Summit 2020 CTF (iOS) [writeup 1](https://www.stark4n6.com/2020/06/magnet-virtual-summit-2020-ctf-ios.html), [writeup 2](https://dfir300.blogspot.com/2020/06/mvs2020ctf-write-up-ios.html)\n* Google CTF 2020: Android [writeup 1](https://blackbeard666.github.io/pwn_exhibit/content/2020_CTF/GoogleCTF/re_android/android_writeup.html), [writeup 2](https://github.com/vsnrain/ctf-writeups/blob/master/2020/googlectf/README.md)\n* [RaziCTF 2020 WriteUp: Chasing a lock](https://blog.ikuamike.io/posts/2020/razictf-chasingalock-writeup/)\n* [DFA/CCSC Spring 2020 CTF ](https://www.petermstewart.net/dfa-ccsc-spring-2020-ctf-apple-ios-forensics-with-ileapp/)\n* [AppSecIL CTF)](https://github.com/klassiker/ctf-writeups/blob/master/2020/appsec-il/greatsuccess.md)\n* [SunshineCTF 2020 write-up](https://dev.to/igotinfected/spoofing-an-ios-device-tsa-techie-sunshinectf-2020-write-up-2l0c)\n\n### 2019\n* [DroidCon, SEC-T CTF 2019](https://anee.me/droidcon-sec-t-ctf-2019-d796be91bb3f)\n* [You Shall Not Pass - BSides Canberra 2019](https://medium.com/tsscyber/ctf-writeup-you-shall-not-pass-2c7a9254549b)\n* [CyberTruck Challenge 2019 — Android CTF](https://medium.com/bugbountywriteup/cybertruck-challenge-2019-android-ctf-e39c7f796530)\n* [Bsidessf-ctf-2019-mobile-track](https://aadityapurani.com/2019/03/07/bsidessf-ctf-2019-mobile-track/)\n* BsidesSF CTF - Challenge: [Part 1](https://medium.com/@itsc0rg1/bsidessf-ctf-challenge-write-up-part-1-e849bc917d37), [Part 2](https://medium.com/@itsc0rg1/bsidessf-ctf-challenge-write-up-part-2-f8f597be659)\n* [CTF on a Budget - Magnet User Summit 2019 - Mobile](https://www.stark4n6.com/2019/04/ctf-on-budget-magnet-user-summit-2019_9.html)\n\n### 2018\n* [H1 202 2018 / H1 202 CTF](https://corb3nik.github.io/blog/h1-202-2018/h1-202-ctf)\n* [ H1-702 CTF (Capture the Flag)](https://aadityapurani.com/2018/06/25/h1-702-ctf-writeups/#mobile)\n* [BSidesSF 2018 CTF — Android Reversing/Forensic Challenge](https://medium.com/@antojoseph_1995/bsidessf-2018-ctf-android-reversing-forensics-challenge-f5522664b6a2)\n* [Hack the Android4: Walkthrough (CTF Challenge)](https://www.hackingarticles.in/hack-the-android4-walkthrough-ctf-challenge/)\n* [Google CTF Quals 2018](https://w0y.at/writeup/2018/07/02/google-ctf-quals-2018-shall-we-play-a-game.html)\n* [Ilam CTF: Android Reverse WriteUp](https://mstajbakhsh.ir/ilam-ctf-android-reverse-writeup/)\n* 8st SharifCTF Android WriteUps: [Vol I](https://mstajbakhsh.ir/8st-sharifctf-android-writeups-vol/), [Vol II](https://mstajbakhsh.ir/8st-sharifctf-android-writeups-vol-ii/)\n* [ASIS 2018 Finals: Gunshop](https://saarsec.rocks/2018/11/27/Gunshop.html)\n* [H1-202 CTF - Writeup](https://pwning.re/2018/02/23/h1-202-writeup/)\n* [M1Con CTF Write up](https://blog.manchestergreyhats.co.uk/2018/03/28/m1con-ctf-writeup/)\n* [AES decode with Cyberchef](https://blog.manchestergreyhats.co.uk/2018/04/18/aes-decode-with-cyberchef/)\n\n### 2017\n* [BSides San Francisco CTF 2017 : pinlock-150](https://github.com/ctfs/write-ups-2017/tree/10bad9bd24b3f84c761faa4d78e223a3a29b2959/bsidessf-ctf-2017/reversing/pinlock-150)\n* [BSides San Francisco CTF 2017 : flag-receiver-200](https://github.com/ctfs/write-ups-2017/tree/10bad9bd24b3f84c761faa4d78e223a3a29b2959/bsidessf-ctf-2017/reversing/flag-receiver-200)\n* [BSidesSF CTF wrap-up](https://blog.skullsecurity.org/2017/bsidessf-ctf-wrap-up)\n* [itsC0rg1's mobile challenge and BSides SF CTF](https://medium.com/@itsc0rg1/my-mobile-challenge-and-bsides-sf-ctf-f9fc4dfca60)\n* [Insomni'hack Teaser 2017 : mindreader-250](https://github.com/ctfs/write-ups-2017/tree/6a3df5bcece6f952cb60db4a3ae2ce97a189b62d/insomnihack-teaser-2017/mobile/mindreader-250)\n* [2017_labyREnth: mob1_ezdroid](https://github.com/gray-panda/grayrepo/tree/1a0c2e033621af9900932252cda31c14a4fbbce8/2017_labyREnth/chal/mob1_ezdroid)\n* [2017_labyREnth: mob2_routerlocker](https://github.com/gray-panda/grayrepo/tree/1a0c2e033621af9900932252cda31c14a4fbbce8/2017_labyREnth/chal/mob2_routerlocker)\n* [2017_labyREnth: mob3_showmewhatyougot](https://github.com/gray-panda/grayrepo/tree/6a0d2fce53b71135286fac3c323b712af08d6913/2017_labyREnth/chal/mob3_showmewhatyougot)\n* [2017_labyREnth: mob4_androidpan](https://github.com/gray-panda/grayrepo/tree/ffbf17ec172f1624ba6607cc7756ed7b99d95b63/2017_labyREnth/chal/mob4_androidpan)\n* [2017_labyREnth: mob5_iotctf](https://github.com/gray-panda/grayrepo/tree/1a0c2e033621af9900932252cda31c14a4fbbce8/2017_labyREnth/chal/mob5_iotctf)\n\n### 2016\n* [LabyREnth](http://researchcenter.paloaltonetworks.com/2016/09/unit42-labyrenth-capture-the-flag-ctf-mobile-track-solutions/)\n* [2016_labyREnth: mob1_lastchance](https://github.com/gray-panda/grayrepo/tree/f054b5d66af66ff684449dcb8e6c9e146213971b/2016_labyREnth/mob1_lastchance)\n* [2016_labyREnth: mob2_cups](https://github.com/gray-panda/grayrepo/tree/f054b5d66af66ff684449dcb8e6c9e146213971b/2016_labyREnth/mob2_cups)\n* [2016_labyREnth: mob3_watt](https://github.com/gray-panda/grayrepo/tree/f054b5d66af66ff684449dcb8e6c9e146213971b/2016_labyREnth/mob3_watt)\n* [2016_labyREnth: mob4_swip3r](https://github.com/gray-panda/grayrepo/tree/f054b5d66af66ff684449dcb8e6c9e146213971b/2016_labyREnth/mob4_swip3r)\n* [2016_labyREnth: mob5_ioga](https://github.com/gray-panda/grayrepo/tree/f054b5d66af66ff684449dcb8e6c9e146213971b/2016_labyREnth/mob5_ioga)\n* [2016_labyREnth: mob6_ogmob](https://github.com/gray-panda/grayrepo/tree/f054b5d66af66ff684449dcb8e6c9e146213971b/2016_labyREnth/mob6_ogmob)\n* [Holiday hack challenge: Part 01](https://github.com/gray-panda/grayrepo/tree/76925522bb0ce3a9615f0022300d525a958bc260/2016_holidayhackchallenge/01)\n* [Holiday hack challenge: Part 02](https://github.com/gray-panda/grayrepo/tree/76925522bb0ce3a9615f0022300d525a958bc260/2016_holidayhackchallenge/02)\n* [Holiday hack challenge: Part 04a](https://github.com/gray-panda/grayrepo/tree/76925522bb0ce3a9615f0022300d525a958bc260/2016_holidayhackchallenge/04a)\n* [Holiday hack challenge: Part 04b](https://github.com/gray-panda/grayrepo/tree/76925522bb0ce3a9615f0022300d525a958bc260/2016_holidayhackchallenge/04b)\n* [Holiday hack challenge: Part 04c](https://github.com/gray-panda/grayrepo/tree/76925522bb0ce3a9615f0022300d525a958bc260/2016_holidayhackchallenge/04c)\n* [Holiday hack challenge: Part 04d](https://github.com/gray-panda/grayrepo/tree/76925522bb0ce3a9615f0022300d525a958bc260/2016_holidayhackchallenge/04d)\n* [Holiday hack challenge: Part 04e](https://github.com/gray-panda/grayrepo/tree/76925522bb0ce3a9615f0022300d525a958bc260/2016_holidayhackchallenge/04e)\n* [Holiday hack challenge: Part 04f](https://github.com/gray-panda/grayrepo/tree/76925522bb0ce3a9615f0022300d525a958bc260/2016_holidayhackchallenge/04f)\n* [Holiday hack challenge: Part 5](https://github.com/gray-panda/grayrepo/tree/76925522bb0ce3a9615f0022300d525a958bc260/2016_holidayhackchallenge/05)\n* [0ctf-2016](https://github.com/ctfs/write-ups-2016/tree/master/0ctf-2016/mobile)\n* [Google-ctf-2016](https://github.com/ctfs/write-ups-2016/tree/39e9a0e2adca3a3d0d39a6ae24fa51196282aae4/google-ctf-2016/mobile)\n* [Google-ctf-2016: ill intentions 1](https://security.claudio.pt/post/googlectf/)\n* [Google-ctf-2016: ill intentions 2](https://github.com/d3rezz/Google-Capture-The-Flag-2016)\n* [Cyber-security-challenge-belgium-2016-qualifiers](https://github.com/ctfs/write-ups-2016/tree/c35549398f88d3755dc31a8fe995f15ef876ee18/cyber-security-challenge-belgium-2016-qualifiers/Mobile%20Security)\n* [Su-ctf-2016 - android-app-100](https://github.com/ctfs/write-ups-2016/tree/274307f43140bb4a52e0729ecf1282628fb22f5b/su-ctf-2016/reverse/android-app-100)\n* [Hackcon-ctf-2016 - you-cant-see-me-150](https://github.com/ctfs/write-ups-2016/tree/274307f43140bb4a52e0729ecf1282628fb22f5b/hackcon-ctf-2016/reversing/you-cant-see-me-150)\n* [RC3 CTF 2016: My Lil Droid](http://aukezwaan.nl/write-ups/rc3-ctf-2016-my-lil-droid-100-points/)\n* [Cyber Security Challenge 2016: Dexter](https://github.com/ctfs/write-ups-2016/tree/39e9a0e2adca3a3d0d39a6ae24fa51196282aae4/cyber-security-challenge-belgium-2016-qualifiers/Mobile%20Security/Dexter)\n* [Cyber Security Challenge 2016: Phishing is not a crime](https://github.com/ctfs/write-ups-2016/tree/39e9a0e2adca3a3d0d39a6ae24fa51196282aae4/cyber-security-challenge-belgium-2016-qualifiers/Mobile%20Security/Phishing-is-not-a-crime)\n* [google-ctf-2016 : little-bobby-application-250](https://github.com/ctfs/write-ups-2016/tree/39e9a0e2adca3a3d0d39a6ae24fa51196282aae4/google-ctf-2016/mobile/little-bobby-application-250)\n\n### 2015\n* [Rctf-quals-2015](https://github.com/ctfs/write-ups-2015/tree/9b3c290275718ff843c409842d738e6ef3e565fd/rctf-quals-2015/mobile)\n* [Insomni-hack-ctf-2015](https://github.com/ctfs/write-ups-2015/tree/9b3c290275718ff843c409842d738e6ef3e565fd/insomni-hack-ctf-2015/mobile)\n* [0ctf-2015](https://github.com/ctfs/write-ups-2015/tree/9b3c290275718ff843c409842d738e6ef3e565fd/0ctf-2015/mobile)\n* [Cyber-security-challenge-2015](https://github.com/ctfs/write-ups-2015/tree/9b3c290275718ff843c409842d738e6ef3e565fd/cyber-security-challenge-2015/mobile-application-security)\n* [Trend-micro-ctf-2015: offensive-200](https://github.com/ctfs/write-ups-2015/tree/9b3c290275718ff843c409842d738e6ef3e565fd/trend-micro-ctf-2015/analysis/offensive-200)\n* [codegate-ctf-2015: dodocrackme2](https://github.com/ctfs/write-ups-2015/tree/9b3c290275718ff843c409842d738e6ef3e565fd/codegate-ctf-2015/reversing/dodocrackme2)\n* [Seccon-quals-ctf-2015: reverse-engineering-android-apk-1](https://github.com/ctfs/write-ups-2015/tree/9b3c290275718ff843c409842d738e6ef3e565fd/seccon-quals-ctf-2015/binary/reverse-engineering-android-apk-1)\n* [Seccon-quals-ctf-2015 - reverse-engineering-android-apk-2](https://github.com/ctfs/write-ups-2015/tree/9b3c290275718ff843c409842d738e6ef3e565fd/seccon-quals-ctf-2015/unknown/reverse-engineering-android-apk-2)\n* [Pragyan-ctf-2015](https://github.com/ctfs/write-ups-2015/tree/9b3c290275718ff843c409842d738e6ef3e565fd/pragyan-ctf-2015/android)\n* [Volgactf-quals-2015](https://github.com/ctfs/write-ups-2015/tree/9b3c290275718ff843c409842d738e6ef3e565fd/volgactf-quals-2015/web/malware)\n* [Opentoall-ctf-2015: android-oh-no](https://github.com/ctfs/write-ups-2015/tree/9b3c290275718ff843c409842d738e6ef3e565fd/opentoall-ctf-2015/misc/android-oh-no)\n* [32c3-ctf-2015: libdroid-150](https://github.com/ctfs/write-ups-2015/tree/9b3c290275718ff843c409842d738e6ef3e565fd/32c3-ctf-2015/reversing/libdroid-150)\n* [Polictf 2015: crack-me-if-you-can](https://github.com/ctfs/write-ups-2015/tree/9b3c290275718ff843c409842d738e6ef3e565fd/polictf-2015/reversing/crack-me-if-you-can)\n* [Icectf-2015: Husavik](https://github.com/ctfs/write-ups-2015/tree/9b3c290275718ff843c409842d738e6ef3e565fd/icectf-2015/forensics/husavik)\n\n## 2014\n* [Qiwi-ctf-2014: not-so-one-time](https://github.com/ctfs/write-ups-2014/tree/b02bcbb2737907dd0aa39c5d4df1d1e270958f54/qiwi-ctf-2014/not-so-one-time)\n* [Fdfpico-ctf-2014: droid-app-80](https://github.com/ctfs/write-ups-2014/tree/b02bcbb2737907dd0aa39c5d4df1d1e270958f54/pico-ctf-2014/forensics/droid-app-80)\n* [Su-ctf-quals-2014: commercial_application](https://github.com/ctfs/write-ups-2014/tree/b02bcbb2737907dd0aa39c5d4df1d1e270958f54/su-ctf-quals-2014/commercial_application)\n* [defkthon-ctf 2014: web-300](https://github.com/ctfs/write-ups-2014/tree/b02bcbb2737907dd0aa39c5d4df1d1e270958f54/defkthon-ctf/web-300)\n* [secuinside-ctf-prequal-2014: wooyatalk](https://github.com/ctfs/write-ups-2014/tree/b02bcbb2737907dd0aa39c5d4df1d1e270958f54/secuinside-ctf-prequal-2014/wooyatalk)\n* [Qiwi-ctf-2014: easydroid](https://github.com/ctfs/write-ups-2014/tree/b02bcbb2737907dd0aa39c5d4df1d1e270958f54/qiwi-ctf-2014/easydroid)\n* [Qiwi-ctf-2014: stolen-prototype](https://github.com/ctfs/write-ups-2014/tree/b02bcbb2737907dd0aa39c5d4df1d1e270958f54/qiwi-ctf-2014/stolen-prototype)\n* [TinyCTF 2014: Ooooooh! What does this button do?](https://github.com/ctfs/write-ups-2014/tree/b02bcbb2737907dd0aa39c5d4df1d1e270958f54/tinyctf-2014/ooooooh-what-does-this-button-do)\n* [31c3-ctf-2014: Nokia 1337](https://github.com/ctfs/write-ups-2014/tree/b02bcbb2737907dd0aa39c5d4df1d1e270958f54/31c3-ctf-2014/pwn/nokia-1337)\n* [Asis-ctf-finals-2014: numdroid](https://github.com/ctfs/write-ups-2014/tree/b02bcbb2737907dd0aa39c5d4df1d1e270958f54/asis-ctf-finals-2014/numdroid)\n* [PicoCTF-2014: Droid App](http://shell-storm.org/repo/CTF/PicoCTF-2014/Forensics/Droid%20App%20-%2080/)\n* [NDH2k14-wargames: crackme200-ChunkNorris](http://shell-storm.org/repo/CTF/NDH2k14-wargames/crackme200-ChunkNorris/)\n\n## 2013\n* [Hack.lu CTF 2013: Robot Plans](https://github.com/ctfs/write-ups-2013/tree/816de23a940856c10987b5047823de48a192c270/hack-lu-ctf-2013/internals/Robot-Plans)\n* [CSAW Quals CTF 2015: Herpderper](https://github.com/ctfs/write-ups-2013/tree/816de23a940856c10987b5047823de48a192c270/csaw-quals-2013/web/herpderper-300)\n\n## 2012\n* [Atast CTF 2012 Bin 300](http://andromedactf.wordpress.com/2013/01/02/atast-ctf-2012-bin300chall5/)\n\n## Misc\n* [Nuit du Hack's 2k12 \u0026 2k11 (pre-quals and finals) Android Crackme’s 2](http://blog.spiderboy.fr/tag/crackme/)\n\n## Vulnerable Mobile apps:\n### Android\n* [Allsafe](https://github.com/t0thkr1s/allsafe) \n* [InsecureShop](https://github.com/optiv/Insecureshop)\n* [OWASP: OMTG-Hacking-Playground](https://github.com/OWASP/OMTG-Hacking-Playground)\n* [Damn insecure and vulnerable App (DIVA)](http://payatu.com/damn-insecure-and-vulnerable-app/)\n* [Damn-Vulnerable-Bank](https://github.com/rewanth1997/Damn-Vulnerable-Bank)\n* [Damn Vulnerable Hybrid Mobile App (DVHMA)](https://github.com/logicalhacking/DVHMA)\n* [Owasp: Goatdroid Project](https://github.com/jackMannino/OWASP-GoatDroid-Project)\n* [InjuredAndroid](https://github.com/B3nac/InjuredAndroid)\n* [ExploitMe labs by SecurityCompass](http://securitycompass.github.io/AndroidLabs/setup.html)\n* [InsecureBankv2](https://github.com/dineshshetty/Android-InsecureBankv2)\n* [Sieve (Vulnerable ‘Password Manager’ app)](https://github.com/mwrlabs/drozer/releases/download/2.3.4/sieve.apk)\n* [sievePWN](https://github.com/tanprathan/sievePWN)\n* [ExploitMe Mobile Android Labs](http://securitycompass.github.io/AndroidLabs/)\n* [Hacme Bank](http://www.mcafee.com/us/downloads/free-tools/hacme-bank-android.aspx)\n* [Android Labs](https://github.com/SecurityCompass/AndroidLabs)\n* [Digitalbank](https://github.com/CyberScions/Digitalbank)\n* [Dodo vulnerable bank](https://github.com/CSPF-Founder/DodoVulnerableBank)\n* [Oracle android app](https://github.com/dan7800/VulnerableAndroidAppOracle)\n* [Urdu vulnerable app](http://urdusecurity.blogspot.co.ke/2014/08/Exploiting-debuggable-android-apps.html)\n* [MoshZuk](http://imthezuk.blogspot.co.ke/2011/07/creating-vulnerable-android-application.html?m=1) [File](https://dl.dropboxusercontent.com/u/37776965/Work/MoshZuk.apk)\n* [Appknox](https://github.com/appknox/vulnerable-application)\n* [Vuln app](https://github.com/Lance0312/VulnApp)\n* [Damn Vulnerable FirefoxOS Application](https://github.com/arroway/dvfa)\n* [Android security sandbox](https://github.com/rafaeltoledo/android-security)\n\n### iOS\n* [ExploitMe Mobile iPhone Labs](http://securitycompass.github.io/iPhoneLabs/)\n* [Owasp: iGoat](https://github.com/hankbao/owasp-igoat)\n* [Damn Vulnerable iOS App (DVIA)](https://github.com/prateek147/DVIA)\n* [Damn Vulnerable iOS App (DVIA) v2](https://github.com/prateek147/DVIA-v2)\n\n\n## Vulnerable APIs:\n* [Vapi](https://github.com/roottusk/vapi)\n* [VAmPI](https://github.com/erev0s/VAmPI)\n* [Vulnerable-api](https://github.com/mattvaldes/vulnerable-api)\n* [vAPI](https://github.com/jorritfolmer/vulnerable-api)\n\n\n## Vulnerable Web apps:\n### Node\n* [Damn Vulnerable Web Service](https://github.com/snoopysecurity/dvws-node)\n* [Damn Vulnerable NodeJS Application](https://github.com/appsecco/dvna)\n* [Damn Vulnerable Serverless Application](https://github.com/OWASP/DVSA)\n* [OWASP: Juice Shop](https://github.com/bkimminich/juice-shop)\n* [Damn Vulnerable Node Application](https://github.com/isp1r0/DVNA)\n* [Intentionally Vulnerable node.js application](https://github.com/nVisium/node.nV)\n* [Vulnode](https://github.com/dpnishant/vulnode)\n* [OWASP: NodeGoat](https://github.com/OWASP/NodeGoat)\n* [Vulnerable-node](https://github.com/cr0hn/vulnerable-node)\n* [Xtreme Vulnerable Web Application (XVWA)](https://github.com/s4n7h0/xvwa)\n\n### PHP\n* [OWASP: Broken Web Applications(BWA)](https://github.com/chuckfw/owaspbwa/)\n* [Damn Vulnerable Web Application (DVWA)](https://github.com/ethicalhack3r/DVWA)\n* [Damn Vulnerable Web Services(DVWS)](https://github.com/snoopysecurity/dvws)\n* [OWASP Hackademic Challenges](https://github.com/Hackademic/hackademic)\n* [OWASP: Insecure Web App Project](https://sourceforge.net/projects/insecurewebapp/files/)\n* [OWASP: WebGoat](https://github.com/OWASP/OWASPWebGoatPHP)\n* [Bwapp](https://sourceforge.net/projects/bwapp/files/bWAPP/)\n* [Beebox](https://sourceforge.net/projects/bwapp/files/bee-box/)\n* [XVWA - Badly coded web application](https://github.com/s4n7h0/xvwa)\n* [Drunk Admin Web Hacking Challenge](http://bechtsoudis.com/archive/2012/04/02/drunk-admin-web-hacking-challenge/index.html)\n* [Peruggia](https://sourceforge.net/projects/peruggia/files/)\n* [Mutillidae](http://www.irongeek.com/i.php?page=mutillidae/mutillidae-deliberately-vulnerable-php-owasp-top-10)\n* [Btslab](https://github.com/CSPF-Founder/btslab/)\n* [OWASP: Bricks](http://sechow.com/bricks/index.html)\n* [The ButterFly Security Project](http://sourceforge.net/projects/thebutterflytmp/files/)\n* [WackoPicko](https://github.com/adamdoupe/WackoPicko)\n* [Vicnum](https://sourceforge.net/projects/vicnum/files/)\n* [GameOver](https://sourceforge.net/projects/null-gameover/)\n* [LAMPSecurity Training](https://sourceforge.net/projects/lampsecurity/)\n* [Metasploitable](https://download.vulnhub.com/metasploitable/Metasploitable.zip)\n* [Metasploitable 2](https://sourceforge.net/projects/metasploitable/files/)\n* [Metasploitable 3](https://github.com/rapid7/metasploitable3)\n* [Hackazon](https://github.com/rapid7/hackazon)\n* [Twiterlike](https://github.com/sakti/twitterlike)\n* [UltimateLAMP](https://download.vulnhub.com/ultimatelamp/UltimateLAMP-0.2.zip)\n\n## Sql\n* [SQLI-labs](https://github.com/Audi-1/sqli-labs)\n* [Testenv](https://github.com/sqlmapproject/testenv)\n\n### Python\n* [Google Gruyere](http://google-gruyere.appspot.com)\n\n### Java\n* [Owasp: WebGoat](https://github.com/WebGoat/WebGoat)\n* [Puzzlemall](https://code.google.com/p/puzzlemall/)\n* [Hacme Books](http://www.mcafee.com/us/downloads/free-tools/hacmebooks.aspx)\n* [Bodgeit](https://github.com/psiinon/bodgeit)\n* [OWASP: Web Goat](https://github.com/WebGoat/WebGoat)\n\n### Ruby on Rails\n* [Hacme Casino](http://www.mcafee.com/us/downloads/free-tools/hacme-casino.aspx)\n* [RailsGoat](https://github.com/OWASP/railsgoat)\n\n### C++\n* [Hacme Travel](http://www.mcafee.com/us/downloads/free-tools/hacmetravel.aspx) \n\n### .NET\n* [OWASP: WebGoat.NET](https://github.com/jerryhoff/WebGoat.NET)\n* [Hacme Bank](http://www.mcafee.com/us/downloads/free-tools/hacme-bank.aspx)\n* [VulnApp](https://labs.portcullis.co.uk/tools/vulnapp/)\n\n### ColdFusion\n* [Hacme Shipping](http://www.mcafee.com/us/downloads/free-tools/hacmeshipping.aspx)\n\n## Mobile security resources\n* [Mobile app pentest cheatsheet](https://github.com/tanprathan/MobileApp-Pentest-Cheatsheet)\n* [Android security awesome](https://github.com/ashishb/android-security-awesome)\n* [Android security reference](https://github.com/doridori/Android-Security-Reference)\n* [Awesome-linux-android-hacking](https://github.com/pfalcon/awesome-linux-android-hacking)\n* [iOS security awesome](https://github.com/ashishb/osx-and-ios-security-awesome)\n* [awesome-iOS-resource](https://github.com/aozhimin/awesome-iOS-resource)\n* [Mobile security wiki](https://mobilesecuritywiki.com/)\n* [iPhone wiki](https://www.theiphonewiki.com/wiki/Main_Page)\n* [Nyxbone](http://www.nyxbone.com/malware/android_tools.html)\n* [Nowhere](https://n0where.net/best-android-security-resources/)\n* [Secmobi](https://github.com/secmobi/wiki.secmobi.com)\n\n## Infosec resources\n* [OSX-iOS-reverse-engineering](https://github.com/michalmalik/osx-re-101)\n* [OSX-security-awesome](https://github.com/kai5263499/osx-security-awesome)\n* [Awesome-web-hacking](https://github.com/infoslack/awesome-web-hacking)\n* [Awesome-windows-exploitation](https://github.com/enddo/awesome-windows-exploitation)\n* [windows-privesc-check](https://github.com/pentestmonkey/windows-privesc-check)\n* [Awesome-Hacking](https://github.com/Hack-with-Github/Awesome-Hacking)\n* [Awesome-reversing](https://github.com/fdivrp/awesome-reversing)\n* [Aweasome-Frida](https://github.com/dweinstein/awesome-frida)\n* [Awesome-security](https://github.com/sbilly/awesome-security)\n* [Awesome-fuzzing](https://github.com/secfigo/Awesome-Fuzzing)\n* [Awesome-wifi-security](https://github.com/edelahozuah/awesome-wifi-security)\n* [Android vulnerabilities overview](https://github.com/CHEF-KOCH/Android-Vulnerabilities-Overview)\n* [OSX-security-awesome](https://github.com/kai5263499/osx-security-awesome)\n* [Infosec_Reference](https://github.com/rmusser01/Infosec_Reference)\n* [PayloadsAllTheThings](https://github.com/swisskyrepo/PayloadsAllTheThings)\n* [Awesome-malware-analysis](https://github.com/rshipp/awesome-malware-analysis)\n* [Linux-reverse-engineering-101](https://github.com/michalmalik/linux-re-101)\n\n\n## Mobile security standards\n* [OWASP Mobile Security Project](https://www.owasp.org/index.php/OWASP_Mobile_Security_Project)\n* [OWASP Top 10 - 2016](https://www.owasp.org/index.php/Mobile_Top_10_2016-Top_10)\n* [OWASP Mobile Application Security Verification Standard (MASVS)](https://github.com/OWASP/owasp-masvs)\n* [OWASP Mobile Security Testing Guide (MSTG)](https://github.com/OWASP/owasp-mstg)\n\n# Credits\n* http://carnal0wnage.attackresearch.com/2013/08/want-to-break-some-android-apps.html\n* https://www.owasp.org/index.php\n* https://github.com/ctfs\n* http://shell-storm.org/repo/\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fxtiankisutsa%2Fawesome-mobile-CTF","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fxtiankisutsa%2Fawesome-mobile-CTF","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fxtiankisutsa%2Fawesome-mobile-CTF/lists"}