Skip to content
All modules
CoreModule 22 of 27120 minutes

Mobile applications

Take an APK apart: the manifest rules that define the attack surface, navigating DEX without decompiling it, and when to stop reading and hook.

Assumes21. Reverse engineering

By the end you can

  • Read an APK's structure from its zip listing and say what each part implies
  • Decode a binary AndroidManifest and identify every exported component
  • State the export rule correctly, including the intent-filter default
  • Follow a string to its load site and a method to its callers inside a DEX
  • Find the native library behind a JNI call and treat it as an ordinary ELF
  • Decide between static reading and runtime hooking, and justify the choice

1. Read

2. Use the tools

In the order they come up while solving. Read what each one does, or go straight to the workspace tab that runs it.

3. Try one now

Generated in your browser and checked in your browser. No account, nothing to download, and a fresh one whenever you want another.

4. Practise on the real thing

Real picoCTF challenges that use these techniques, easiest first. 23 match in total - see the full index.

Common mistakes

The wrong turns this topic reliably produces. Written as the mistake rather than the rule, because the rule is easy to agree with and easy to walk straight past.

  • Reading android:exported as the whole export rule. A component with an intent-filter and no explicit attribute is exported on older targets, which is where the entry point usually is.
  • Decompiling to Java and stopping. The decompiler drops what it cannot express; the smali is authoritative and is often shorter than the argument about it.
  • Looking for the secret in the Java. Anything valuable is regularly in a native library, a resource, or assembled at runtime from pieces.
  • Treating a signed APK as untouchable. Repackaging and re-signing with your own key is routine, and a debuggable rebuild answers in a minute what static reading argues about for an hour.
  • Trusting the DEX string table. Strings are regularly assembled or decrypted at runtime, which is why the load site matters more than the table and why the cross-reference step comes before the reading.

Checkpoint

Given an APK, list every component reachable by another app on the device, and say for each one which rule made it reachable.

Teaching note

The export default is the thing everybody gets wrong: a component with an intent-filter and no android:exported attribute is exported. Teach it as a rule with two cases rather than as a single attribute, or half the class will report a challenge's entry point as private.

Go deeper

The lessons above are written to get you through a challenge. These go after the subject instead. Each one opens our notes on that chapter - what it argues, what to take from it and where it stops - so this is somewhere to read now rather than a book to buy first. Nothing here is affiliate-linked or sold by us.

Every book the curriculum cites has a page in the library.