mobileProhard

Infinity Bank

HackTheBox

Task: Flutter Android banking app with RSA+AES encrypted API communication. Solution: Decompiled Dart AOT code with blutter to discover crypto params go in HTTP headers, then exploited IDOR in transfer endpoint to steal from bank's system account.

$ ls tags/ techniques/
idor_exploitationflutter_aot_decompilationrsa_oaep_aes_cbc_hybrid_cryptopin_xor_decodingjwt_alg_none_bypass

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups