mobileProhard
Infinity Bank
HackTheBox
Task: Flutter Android banking app with RSA+AES encrypted API communication. Solution: Decompiled Dart AOT code with blutter to discover crypto params go in HTTP headers, then exploited IDOR in transfer endpoint to steal from bank's system account.
$ ls tags/ techniques/
idor_exploitationflutter_aot_decompilationrsa_oaep_aes_cbc_hybrid_cryptopin_xor_decodingjwt_alg_none_bypass
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [mobile][free]Jigsaw— HackTheBox
- [reverse][Pro]Очень защищенный банк (Super Protected Bank)— duckerz
- [reverse][free]SAW— hackthebox
- [crypto][free]MadMath— hackthebox
- [mobile][free]APKey— HackTheBox