AnotherVulnerableApp (AVA)

Another vulnerable app on Android, covers topics:

  • Communication issues
    • Insecure communication
      • HTTP
      • HTTPS without cert validation
    • Secure communication
      • HTTPS
      • Cert pinning
  • Tapjacking
  • Man in the disk

AnotherMaliciousApp (AMA)

Malicious application which exploits weaknesses in the AVA:

  • Tapjacking
  • Man in the disk


  • AwesomeGame, AwesomeGameFake - Dummy applications, assets in AVA and AMA, used to demonstrate Man in the disk vulnerability. Not for direct use.
  • Icons used in the apps come from