The author has released a new application that enables hosting Android CTF challenges in a controlled environment. This allows for setting up challenges that wouldn't be possible with just a standard APK. For example, challenges can be created to get remote code execution or exploit misconfigured services. The application currently has several features, including real-time device screen viewing, challenge state reset, and app/service restart. It also allows sending broadcast intents, shutting down/rebooting devices, and downloading bug reports. Additionally, it has Frida scripting, file browsing, terminal access, APK management, and logcat viewing capabilities. The application can run in either jailed or full mode, with the latter allowing arbitrary script execution. The source code is available on GitHub, along with a simple example using a dummy application. The application also has a user-friendly web UI. The author is seeking constructive feedback on how to improve the application.
reddit.com
reddit.com
Create attached notes ...
