
Gu3ssWeak: Deliberately Vulnerable Android App for Mobile Security Research and Bug Bounty Practice
Mobile SecurityVulnerabilitiesPenetration TestingBug BountyAndroidSecurity TestingTrainingCTF
A developer has created Gu3ssWeak, a deliberately vulnerable Android application designed for practicing mobile application security testing. The app includes intentionally vulnerable components such as WebView and deep link abuse, JavaScript interfaces, XSS, insecure local storage, SQL injection, hardcoded credentials, Frida-based runtime analysis, and vulnerability chaining. The project is intended to provide a realistic APK for practicing tools like JADX, APKTool, ADB, Frida, Burp Suite, and dynamic analysis in a controlled environment, and the developer is seeking feedback and suggestions for additional vulnerabilities.