7. Deep Link

  1. Methods to find a bug

Steps :

1. Deep Link like CSRF Vulnerability
2. search for scheme and host in manifest file
3. Exploit using ADB

<data android:scheme="http" android:host="www.faithfulcounseling.com"/>
<data android:scheme="https" android:host="www.faithfulcounseling.com"/>
<data android:scheme="betterhelpapp" android:host="betterhelp"/>

Example :-
<data android:scheme="https" android:host="www.faithfulcounseling.com"/>

https://www.faithfulcounseling.com

betterhelpapp://betterhelp

am start -n android.intent.action.VIEW -d "betterhelpapp://betterhelp"
  1. PoC 1

  1. PoC 2

Last updated