APK Network Security Audit
Budget: $5,000 – $10,000 USD
I own the full rights to the target Android APK and now need a deep-dive security audit focused on its network layer. The job spans two tightly linked parts: first, a static and dynamic reverse-engineering pass to map out every component that touches the WebSocket client; second, a forensic review of several PCAP captures I will provide so we can see what really travels over the wire.
Here is the scope I expect you to follow:
• Decompile the APK (JADX, Ghidra or similar are fine) to trace how the WebSocket sessions are created, authenticated and terminated.
• Run the app in an instrumented environment (Frida, Burp Suite, mitmproxy, Wireshark) and log live traffic, comparing it with my PCAPs to spot discrepancies.
• Identify weaknesses such as plaintext payloads, poor key management, missing TLS validation, token reuse, or hard-coded secrets.
• Supply a concise, reproducible proof-of-concept for every confirmed vulnerability—scripts, modified APK, or annotated captures are all acceptable.
• Finish with a remediation report that prioritises fixes and lists any residual risks.
Acceptance criteria
1. At least one complete call chain diagram that links code paths to observed network frames.
2. A vulnerability matrix (severity, impact, exploitability, recommendation).
3. All tooling commands or scripts necessary for me to reproduce the findings.
When you reply, attach a brief yet detailed project proposal describing your methodology, expected timeline and any specialist tooling you plan to use. I am happy to clarify anything you need before you begin.
Here is the scope I expect you to follow:
• Decompile the APK (JADX, Ghidra or similar are fine) to trace how the WebSocket sessions are created, authenticated and terminated.
• Run the app in an instrumented environment (Frida, Burp Suite, mitmproxy, Wireshark) and log live traffic, comparing it with my PCAPs to spot discrepancies.
• Identify weaknesses such as plaintext payloads, poor key management, missing TLS validation, token reuse, or hard-coded secrets.
• Supply a concise, reproducible proof-of-concept for every confirmed vulnerability—scripts, modified APK, or annotated captures are all acceptable.
• Finish with a remediation report that prioritises fixes and lists any residual risks.
Acceptance criteria
1. At least one complete call chain diagram that links code paths to observed network frames.
2. A vulnerability matrix (severity, impact, exploitability, recommendation).
3. All tooling commands or scripts necessary for me to reproduce the findings.
When you reply, attach a brief yet detailed project proposal describing your methodology, expected timeline and any specialist tooling you plan to use. I am happy to clarify anything you need before you begin.