Android Application Penetration Test and Reverse EngineeringAndroid Application Penetration Test and Reverse Engineering
The network for creativity
Join 1.25M professional creatives like you
Connect with clients, get discovered, and run your business 100% commission-free
Creatives on Contra have earned over $150M and we are just getting started
Comprehensive Android application penetration test, reverse engineering analysis, and vulnerability assessment for a production-ready mobile application.
The Objective: A mobile application provider required a full-scope security audit to evaluate their client-side attack surface, verify compliance with the OWASP Mobile Application Security Verification Standard (MASVS Level 2), and uncover critical runtime flaws before public deployment.
The Approach: I executed a hybrid security assessment combining static application security testing (SAST), dynamic instrumentation (DAST), and automated reconnaissance. Every vulnerability was manually validated using tools like Frida, Objection, Jadx-GUI, and Burp Suite to eliminate false positives and scored using standard CVSS 3.1 metrics.
From a single comprehensive audit, I uncovered 19 reproducible findings:
1 High Severity: Insecure local data storage exposing unencrypted user credentials and private API keys in the shared preferences file.
4 Medium Severity: Broken cryptography implementations, insufficient SSL pinning mechanisms permitting Man-in-the-Middle (MitM) attacks, and unprotected exported Activities allowing unauthorized internal intents.
6 Low Severity: Lack of root detection, weak code obfuscation rules, and excessive logging of sensitive debug information via Logcat.
8 Informational: Outdated third-party SDK dependencies and missing compiler exploit mitigation configurations.
Post image
Back to feed
The network for creativity
Join 1.25M professional creatives like you
Connect with clients, get discovered, and run your business 100% commission-free
Creatives on Contra have earned over $150M and we are just getting started