Skip to content

Security: VoidCatalyst/android-pentesting

Security

SECURITY.md

Security Policy

About This Repository

This is an educational security research repository. Its content — including vulnerable code samples, exploitation scripts, bypass techniques, and insecure configuration examples — is intentional teaching material. The "vulnerabilities" documented and demonstrated here are features, not bugs. They exist to help security practitioners learn how to identify and remediate real-world Android application weaknesses.

This repository does not ship a product, service, or production application. There is no attack surface beyond the repository content itself.


Supported Scope

Because this is an educational repository and not a deployed product, the scope for security reporting is narrow and specific:

In Scope

Report issues if you find:

  • Accidental credential exposure — a real API key, password, token, private key, certificate, or other sensitive secret committed to the repository in any file
  • Malicious code injection — code in the repository that appears to target maintainers' or contributors' systems rather than serving a documented educational purpose
  • Supply-chain concerns — a linked or referenced external resource (tool download URL, script, external dependency) that has been compromised or redirected to malicious content

Out of Scope

Do not report:

  • Intentionally vulnerable Android apps listed in 07-Android-Vulnerable-Apps/ — these are vulnerable by design for learning purposes
  • Vulnerable code snippets, configuration examples, or technique demonstrations in any guide — these are the educational content of this repository
  • Missing security headers on GitHub Pages or similar static hosting, if used
  • Theoretical vulnerabilities in the tools referenced (Frida, Objection, MobSF, etc.) — report those to the respective upstream projects
  • OWASP MASVS/MASTG compliance gaps in test app examples — the intentionally vulnerable apps are meant to fail these controls

How to Report a Real Security Issue

If you discover an accidental credential commit, malicious code, or supply-chain compromise in this repository:

  1. Do not open a public GitHub issue. This could expose sensitive material further before it is remediated.
  2. Use GitHub's private vulnerability reporting feature on this repository, or:
  3. Contact the maintainer directly at the email address associated with the GitHub account VoidCatalyst.

Please include in your report:

  • A description of what you found and where (file path, commit hash if relevant)
  • Why you believe it is a real credential or real security risk rather than intentional educational content
  • Steps to reproduce or verify the issue

Response Timeline

Stage Target Timeframe
Initial acknowledgement Within 72 hours
Triage and confirmation Within 5 business days
Remediation (if confirmed) Within 7 days for credential rotation; 14 days for other issues
Public disclosure After remediation, at maintainer's discretion

Important Disclaimer

All exploitation techniques, tool usage examples, payload demonstrations, and vulnerability walkthroughs in this repository are provided strictly for educational purposes and must only be used against:

  • Intentionally vulnerable applications (DIVA, InsecureBankv2, OVAA, etc.)
  • Your own applications and devices
  • Systems for which you have explicit written authorization

Unauthorized testing against systems you do not own is illegal in most jurisdictions. The maintainer accepts no liability for misuse of the content in this repository. See the LICENSE for the full disclaimer.

There aren't any published security advisories