← Back
Flag4 - Insecure Shared Preferences | Avishai’s CTF Writeups

Avishai's CTF Writeups

Yalla Balagan! A collection of my CTF writeups and solutions.

View on GitHub

Let’s first have a look at the challenge:

400

When we look at the code, we can see it saves the credentials in none encrypted shared preferences:

We can find this file in the internal storage of the application, the filename is user.xml: