A detailed walkthrough of solving KPMG CTF 2025's advanced mobile security challenge by reverse engineering an Android APK, discovering hardcoded Firebase credentials, exploiting authentication misconfigurations to bypass database security rules, and ultimately retrieving the flag through a chain of vulnerabilities including

4m read timeFrom infosecwriteups.com
Post cover image
Table of contents
The ChallengePhase 1: APK Reverse Engineering — Peeling Back the LayersGet Stalin Prevan Crasta’s stories in your inboxDeep Link AnalysisPhase 2: The “Almost Protect” PhenomenonFirebase Database Properly Secured… AlmostExternal Resource DiscoveryPhase 3: The Authentication BypassFirebase Identity Toolkit DiscoveryExploiting Anonymous AuthenticationPhase 4: The Final BreakthroughAuthenticated Database Access

Sort: