Mobile applications
Take an APK apart: the manifest rules that define the attack surface, navigating DEX without decompiling it, and when to stop reading and hook.
Assumes21. Reverse engineering
By the end you can
- Read an APK's structure from its zip listing and say what each part implies
- Decode a binary AndroidManifest and identify every exported component
- State the export rule correctly, including the intent-filter default
- Follow a string to its load site and a method to its callers inside a DEX
- Find the native library behind a JNI call and treat it as an ordinary ELF
- Decide between static reading and runtime hooking, and justify the choice
1. Read
Reversing managed code: .NET, Java, and Python bytecode
When the binary is not machine code but bytecode with names attached, the job stops being disassembly and becomes reading. Decompiling .NET and Java back to source, disassembling .pyc, and what obfuscators actually take away.
Taking an Android app apart
An APK is a zip, and most of what a mobile challenge turns on is in metadata rather than in code. The manifest rules that decide the attack surface, how to navigate DEX without a decompiler, and when to stop reading and start hooking.
2. Use the tools
In the order they come up while solving. Read what each one does, or go straight to the workspace tab that runs it.
- APK and IPA analyzer: manifest, exported components, DEX xrefs
Open an Android APK or an iOS IPA in the browser: the parsed manifest with every exported component, signing scheme, secret scan, and a DEX cross-reference workbench.
Open it in the workspace - Java .class disassembler
Disassemble JVM bytecode, read the constant pool, and recover strings and logic from .class and .jar files.
Open it in the workspace - ZIP archive inspector
Read a ZIP’s central directory and local headers, spot mismatches used to hide files, and check encryption and compression per entry.
Open it in the workspace - ELF, PE and Mach-O binary analyzer
Parse headers, sections, imports, and symbols from Linux, Windows, and macOS binaries, with C++ symbol demangling and gadget discovery.
Open it in the workspace - Strings extractor for binaries and blobs
Pull printable ASCII and UTF-16 strings out of any file, filtered by length, with flag-pattern highlighting.
Open it in the workspace
3. Try one now
Generated in your browser and checked in your browser. No account, nothing to download, and a fresh one whenever you want another.
4. Practise on the real thing
Real picoCTF challenges that use these techniques, easiest first. 23 match in total - see the full index.
Common mistakes
The wrong turns this topic reliably produces. Written as the mistake rather than the rule, because the rule is easy to agree with and easy to walk straight past.
- Reading android:exported as the whole export rule. A component with an intent-filter and no explicit attribute is exported on older targets, which is where the entry point usually is.
- Decompiling to Java and stopping. The decompiler drops what it cannot express; the smali is authoritative and is often shorter than the argument about it.
- Looking for the secret in the Java. Anything valuable is regularly in a native library, a resource, or assembled at runtime from pieces.
- Treating a signed APK as untouchable. Repackaging and re-signing with your own key is routine, and a debuggable rebuild answers in a minute what static reading argues about for an hour.
- Trusting the DEX string table. Strings are regularly assembled or decrypted at runtime, which is why the load site matters more than the table and why the cross-reference step comes before the reading.
Checkpoint
Given an APK, list every component reachable by another app on the device, and say for each one which rule made it reachable.
Teaching note
The export default is the thing everybody gets wrong: a component with an intent-filter and no android:exported attribute is exported. Teach it as a rule with two cases rather than as a single attribute, or half the class will report a challenge's entry point as private.
Go deeper
The lessons above are written to get you through a challenge. These go after the subject instead. Each one opens our notes on that chapter - what it argues, what to take from it and where it stops - so this is somewhere to read now rather than a book to buy first. Nothing here is affiliate-linked or sold by us.
Chapter 23, Hacking Android Apps
Bug Bounty Bootcamp - Vickie Li
The teardown workflow with the manifest read as an attack surface rather than as configuration.
Chapter 14, Attacking Mobile Applications
Practical IoT Hacking - Fotios Chantzis, Ioannis Stais, Paulino Calderon, Evangelos Deirmentzoglou, and Beau Woods
The mobile app as one component of a device ecosystem, including what it stores and what it talks to.
Every book the curriculum cites has a page in the library.