Lab - Secure Vault

Mobile Hacking Conference CTF

MHC Corp recently hardened their employee portal app. The Secure Vault now validates that any externally supplied URL belongs to an approved corporate hostname before loading it into the WebView.

Objective
  • Find a way to exfiltrate sensitive authentication data and get the flag


Course Lessons