Luminix Labs always provide you the best experience of cyber security consultation. Finding application vulnerabilities are our main professional skills. Remember to always secure your digital assets, information and your infrastructure!
๐ Exam- ๐๐ฒ๐ฟ๐๐ถ๐ณ๐ถ๐ฒ๐ฑ ๐ ๐ผ๐ฏ๐ถ๐น๐ฒ ๐ฃ๐ฒ๐ป๐๐ฒ๐๐๐ฒ๐ฟ (๐๐ ๐ฃ๐ฒ๐ป) - ๐๐ป๐ฑ๐ฟ๐ผ๐ถ๐ฑ
๐ Challenge- ๐ ๐ถ๐๐ฐ๐ผ๐ป๐ณ๐ถ๐ด๐๐ฟ๐ฒ๐ฑ ๐๐ป๐ฑ๐ฟ๐ผ๐ถ๐ฑ๐ ๐ฎ๐ป๐ถ๐ณ๐ฒ๐๐.๐ ๐บ๐น
** ๐ณ๐๐๐, ๐ช๐๐๐๐๐๐, ๐น๐๐๐๐๐, ๐๐๐ 3 ๐๐๐๐๐ ๐๐๐๐๐๐๐ ๐๐๐๐ ๐๐๐ 100% ๐ ๐๐๐๐๐๐๐ ๐๐ ๐๐๐ ๐ช๐ด๐ท๐๐- ๐จ๐๐ ๐๐๐๐ ๐๐๐๐!**
๐ตโ ๐๐จ๐ฆ'๐ฌ ๐๐ญ๐๐ญ๐ข๐ ๐๐ง๐๐ฅ๐ฒ๐ฌ๐ข๐ฌ ๐๐๐ฏ๐๐ง๐ญ๐ฎ๐ซ๐!
Tom was knee-deep into an Android application pentest, dissecting lines of code with the finesse of a seasoned detective. As Tom deciphered the intricate details, a subtle intuition hinted at a potential misconfiguration waiting to be unraveled.
Can you help Tom identify security issues within the AndroidManifest.xml file below? Your expertise might just be the key to unraveling the mystery!ย ๐ตโ๐
Comment your answers below ๐
๐จโ๐ปCMPen - Android:-
https://t.co/SWAKbkcoRa
@TheSecOpsGroup -debug enabled (potentially exposing sensitive info)
-cleartext traffic (allowing non-https, MITM possibility)
-hardcoded secret (oAuth secret may lead to be misused)
-backup enabled allowing any sensitive info to be backed up