Skip to content

RedAlien00/RedAlienShop

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

50 Commits
 
 
 
 
 
 
 
 
 
 

Repository files navigation

RedAlienShop

스크린샷 2024-10-01 오후 6 30 09

RedAlienShop은 취약한 안드로이드 애플리케이션으로, InsecureBankv2에 영감을 받아 제작하였습니다



  • RedAlienShop Android Application :
  • RedAlienShop Server :

  • Android Version : 9 ~ 14

Info & Update

  • Detact가 될 경우, 경고창은 띄우지만 ${\textsf{\color{magenta}앱은 종료되지 않습니다}}$

  • Update - SQLInjection 추가 ( 2024/11/11 )
  • Update - Algorithm 변경 ( 2025/01/14 )
    • Blowfish > AES

Implementation vulnerabilities

  1. Weak Login Credentials
  2. Application Debuggable
  3. Allow Data Backup

  1. Root Detection and Bypass
  2. Emulator Detection and Bypass
  3. Developer Option Detection and Bypass
  4. Frida Detection and Bypass

  1. Exported Activity
  2. Exported Content Provider
  3. Content Provider SQLInjection ${\textsf{\color{magenta}( 추가 - 2024/11/11 )}}$
  4. Insecure Logging
  5. Insecure HTTP connections

  1. Weak Cryptography
  2. Insecure External storage
  3. Insecure Internal storage
  4. Point Tampering Vulnerability

Install and run the server

  1. git clone https://github.com/RedAlien00/RedAlienShop.git
  2. cd RedAlienShop/RedAlienshop_server && pip3.12 install -r requirements.txt
  3. python run.py

Server Connection

스크린샷 2024-10-02 오후 4 51 25

  1. 서버를 실행합니다

스크린샷 2024-10-02 오후 4 54 12

2. 앱을 실행한 후, 우측 상단의 지구 모양 아이콘을 클릭합니다
3. 위의 그림과 같이 IP와 Port를 입력한 후, Submit 버튼을 클릭하면 서버와 연결됩니다

License

Designed and developed by 2024 RedAlien 

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published