Skip to content

About

A medium-difficulty Android CTF challenge application testing mobile security, reverse engineering, and cryptographic skills through database forensics and flag decryption.

Topics

Resources

Stars

5 stars

Watchers

0 watching

Forks

Latest commit

ย 

History

23 Commits

Folders and files

Repository files navigation

๐Ÿ›๏ธ Perseus - Android CTF Challenge

License: Educational Flutter SQLite Python Dart Android

A medium-difficulty Android exploitation and forensics CTF challenge for MEDUSA 2.0 cybersecurity competition.

๐Ÿ“ฑ Overview

Perseus is a comprehensive Android CTF challenge that tests participants' skills in mobile security, reverse engineering, cryptography, and digital forensics. Players must navigate the Android filesystem, extract hidden databases, decrypt encrypted data, and ultimately retrieve the flag.

Challenge Details

Attribute Value
Category Mobile / Android Forensics
Difficulty Medium
Event MEDUSA 2.0 (University of Kelaniya)
Author @kavix
Platform Android 5.0+ (API 21+)
APK Size ~20-25 MB
Expected Time 1-4 hours (varies by skill level)

๐ŸŽฏ Challenge Objectives

Players must complete the following tasks to solve the challenge:

  1. โœ… Install the Perseus APK on an Android device/emulator
  2. โœ… Navigate the Android filesystem using ADB
  3. โœ… Locate the hidden SQLite database (obfuscated path)
  4. โœ… Extract the database from the device
  5. โœ… Query the database to find credentials
  6. โœ… Decrypt the encrypted flag using cryptographic principles
  7. โœ… Submit the flag in format: MEDUSA{...}

Skills Tested

  • Android Debug Bridge (ADB) proficiency
  • Android filesystem navigation and forensics
  • SQLite database analysis
  • Cryptography (XOR cipher, SHA-256 hashing)
  • APK reverse engineering
  • Python scripting and cryptographic algorithms
  • Problem-solving and persistence

๐Ÿš€ Quick Start

Prerequisites

  • ADB (Android Debug Bridge) - Device/emulator interaction
  • Android Device or Emulator - API 21+ (Android 5.0 Lollipop)
  • SQLite3 - Database analysis
  • Python 3 - Flag decryption scripts
  • Optional: apktool, jadx for advanced analysis

Installation

# 1. Install ADB (choose your OS)
# macOS
brew install android-platform-tools

# Linux (Debian/Ubuntu)
sudo apt-get install android-tools-adb

# Windows
# Download from https://developer.android.com/tools/releases/platform-tools

# 2. Verify installation
adb --version

# 3. Install the APK
adb install perseus.apk

# 4. Launch the app
adb shell am start -n com.example.perseus/.MainActivity

Getting Started

# Connect to device shell
adb shell

# Navigate to app's external storage
cd /storage/emulated/0/Android/data/com.example.perseus

# List contents
ls -la

# Exit shell
exit

๐Ÿ“‚ Project Structure

perseus/
โ”œโ”€โ”€ assets/
โ”‚   โ”œโ”€โ”€ images/
โ”‚   โ”‚   โ””โ”€โ”€ logo 1 - white.png          # Application logo
โ”‚   โ””โ”€โ”€ config.enc                      # Encrypted SQLite database
โ”‚
โ”œโ”€โ”€ lib/
โ”‚   โ”œโ”€โ”€ main.dart                       # Flutter UI & authentication
โ”‚   โ”œโ”€โ”€ database_helper.dart            # SQLite & encryption logic
โ”‚   โ””โ”€โ”€ event_prefs.dart                # SharedPreferences management
โ”‚
โ”œโ”€โ”€ android/                            # Android native config
โ”œโ”€โ”€ tools/                              # Build utilities
โ”‚
โ”œโ”€โ”€ pubspec.yaml                        # Flutter dependencies
โ”œโ”€โ”€ pubspec.lock                        # Dependency lock file
โ”œโ”€โ”€ analysis_options.yaml               # Dart analysis config
โ”‚
โ”œโ”€โ”€ CTF_PLAYER_GUIDE.md                # Player setup guide
โ”œโ”€โ”€ GUIDE.md                           # Complete solver guide
โ”œโ”€โ”€ IMPLEMENTATION_GUIDE.md            # Technical implementation
โ”œโ”€โ”€ PREREQUISITES.md                   # Requirements & tools
โ”œโ”€โ”€ HINTS.txt                          # Progressive hints
โ”‚
โ””โ”€โ”€ README.md                          # This file

๐Ÿ” Technical Architecture

Database Schema

The SQLite database contains a credentials table:

CREATE TABLE credentials (
    id INTEGER PRIMARY KEY AUTOINCREMENT,
    username TEXT NOT NULL UNIQUE,
    password TEXT NOT NULL
);

-- Test Data
INSERT INTO credentials (username, password) 
VALUES ('admin', 'medusa2024');

Encryption System

Algorithm: XOR cipher with SHA-256 key derivation

1. Key Generation: SHA256(username + password)
2. Plaintext Flag: MEDUSA{round_2_task_is_comp}
3. Encryption: Each byte XOR with corresponding key byte

Example Decryption (Python):

import hashlib

username = "admin"
password = "medusa2024"

# Generate SHA-256 key
key = hashlib.sha256((username + password).encode()).digest()

# Encrypted flag bytes
encrypted = [
    0xfd, 0xd7, 0x6d, 0xbc, 0xaf, 0x0c, 0x9e, 0xd5, 0x89, 0xc3,
    0x87, 0x26, 0x9c, 0xa2, 0x64, 0x15, 0x8a, 0x28, 0xf2, 0xa5,
    0x88, 0x78, 0xf7, 0x8e, 0xd1, 0xd7, 0x82, 0x93
]

# XOR decryption
decrypted = bytes([encrypted[i] ^ key[i % len(key)] for i in range(len(encrypted))])
flag = decrypted.decode('utf-8')

print(f"Flag: {flag}")  # Output: MEDUSA{round_2_task_is_comp}

Application Components

Component Technology Purpose
UI Framework Flutter Cross-platform Android app
Database SQLite 3 Credential storage
Cryptography Dart crypto XOR + SHA-256
Storage External + Internal Database and preferences
Animations Flutter Animations Smooth UI effects

๐Ÿ“‹ Solution Walkthrough

Method 1: Database Extraction (Recommended)

# 1. Connect device and install APK
adb devices
adb install perseus.apk

# 2. Navigate to app storage
adb shell
cd /storage/emulated/0/Android/data/com.example.perseus/files
find . -name "*.db"

# Expected output:
# /storage/emulated/0/Android/data/com.example.perseus/files/logs/com.ecsc-uok.medusa.kavix/config.db

# 3. Extract database
adb pull /storage/emulated/0/Android/data/com.example.perseus/files/logs/com.ecsc-uok.medusa.kavix/config.db

# 4. Analyze database
sqlite3 config.db
sqlite> SELECT * FROM credentials;
# Output: 1|admin|medusa2024

# 5. Decrypt flag using Python script (see above)

Method 2: APK Decompilation

# Decompile APK to extract source code
apktool d perseus.apk -o perseus_decompiled

# Or use jadx for Java decompilation
jadx perseus.apk -d perseus_jadx

# Find encrypted flag and decryption logic in:
# - lib/database_helper.dart
# - assets/config.enc

Method 3: Runtime Manipulation (Advanced)

# Use Frida to hook database operations
pip3 install frida-tools

# Create Frida script to intercept credentials
# See GUIDE.md for complete Frida examples

๐Ÿ’ก Key Features

User Interface

  • ๐ŸŽจ Dark Theme with neon green accents (#39FF14)
  • โœจ Animated Glowing Logo with pulsing effects
  • ๐Ÿ“ Form Validation with error handling
  • ๐ŸŽฏ Shake Animation on authentication failure
  • โœ… Success Page with checkmark animation
  • ๐Ÿ“– Mythology Story Page (Medusa legend)
  • ๐Ÿ“ณ Haptic Feedback (vibration and success impacts)
  • ๐ŸŽฌ Page Transitions with slide + fade animations
  • ๐Ÿ“ฑ Immersive Full-Screen Mode

Backend Features

  • ๐Ÿ” SQLite Database Management with singleton pattern
  • ๐Ÿ“ฆ Asset-Based Database Initialization
  • ๐Ÿ”‘ XOR Encryption/Decryption Logic
  • ๐Ÿ“ฒ SharedPreferences Management
  • ๐ŸŽญ Event Data Storage (Base64 encoded)

๐Ÿ› ๏ธ Dependencies

Flutter/Dart:

dependencies:
  flutter:
    sdk: flutter
  sqflite: ^2.3.0
  path_provider: ^2.1.1
  path: ^1.8.3
  crypto: ^3.0.3
  shared_preferences: ^2.2.2
  cupertino_icons: ^1.0.8

Development:

dev_dependencies:
  flutter_test:
    sdk: flutter
  flutter_lints: ^5.0.0

System Requirements:

  • Flutter SDK 3.9.2+
  • Dart 3.9.2+
  • Android SDK API 21+ (target 34)
  • Java JDK 11+

๐Ÿ“š Documentation

This repository includes comprehensive guides for both players and organizers:

Document Purpose Audience
CTF_PLAYER_GUIDE.md Setup, tools, troubleshooting Players
GUIDE.md Complete solution walkthrough Players (spoilers!)
IMPLEMENTATION_GUIDE.md Architecture and implementation Organizers/Developers
PREREQUISITES.md Detailed requirements and setup New players
HINTS.txt Progressive hints system Players

๐ŸŽฎ Testing Credentials

Valid Login:

Username: admin
Password: medusa2024
Expected Flag: MEDUSA{round_2_task_is_comp}

Invalid Login: Any other username/password combination will trigger an error state with shake animation.


๐Ÿ“Š Challenge Difficulty Progression

Skill Level Estimated Time Approach
Beginner 2-4 hours Follow guide, learn tools
Intermediate 1-2 hours Use hints, some exploration
Advanced 30-60 minutes Minimal guidance needed
Expert <30 minutes Multiple solution methods

๐Ÿ” Common Pitfalls

โŒ Don't:

  • Try to brute force the flag
  • Assume database is in APK assets (it's created at runtime)
  • Skip launching the app (database created on first run)
  • Only check /data/data/ (external storage not accessible)
  • Overlook hidden/obfuscated directory names

โœ… Do:

  • Explore filesystem thoroughly
  • Check both internal and external storage
  • Analyze database files with SQLite tools
  • Look for encoded/encrypted data
  • Read app source code if decompiling

๐Ÿ†˜ Troubleshooting

ADB Issues

# Device not detected
adb kill-server
adb start-server
adb devices

# Device unauthorized
# โ†’ Unlock device and tap "Allow" on authorization prompt

# Device offline
adb reconnect

Installation Issues

# Insufficient storage
# โ†’ Free up at least 200MB on device

# Installation failed
# โ†’ Use: adb install -r perseus.apk (force reinstall)

Database Not Found

# Database files created on first app launch
# โ†’ Launch app and attempt login before extracting

# Permission denied
# โ†’ Use adb pull (external storage is accessible without root)

๐Ÿ“– Learning Resources

Android Development

Mobile Security

Reverse Engineering Tools

  • apktool - APK decompilation
  • jadx - Dex to Java decompiler
  • Frida - Dynamic instrumentation framework
  • objection - Frida-based mobile toolkit

Cryptography


๐Ÿ—๏ธ Building & Development

Setup Development Environment

# Clone repository
git clone https://github.com/kavix/perseus.git
cd perseus

# Get Flutter dependencies
flutter pub get

# Analyze code
flutter analyze

# Run on connected device
flutter run

# Build debug APK
flutter build apk --debug

# Build release APK
flutter build apk --release

Useful Commands

# Check Flutter setup
flutter doctor

# Run tests
flutter test

# Format code
dart format lib/

# Clean build artifacts
flutter clean

โš ๏ธ Security Disclaimer

Educational Purpose Only

This is a CTF challenge application designed for learning and competition. In production environments:

  • โŒ Never store plaintext passwords in databases
  • โŒ Never hardcode encryption keys in source code
  • โŒ Use proper password hashing (bcrypt, argon2)
  • โŒ Use industry-standard encryption (AES, TLS)
  • โŒ Implement proper authentication mechanisms
  • โŒ Follow OWASP Mobile Security guidelines

๐Ÿ“ License

This project is released for educational and CTF competition use only.

For any commercial or non-educational use, please contact the author.


๐Ÿ‘ค Author

kavix - @kavix

  • ๐Ÿ“ง Contact through GitHub
  • ๐ŸŒ MEDUSA CTF 2.0 Organizer
  • ๐Ÿ† Mobile Security Enthusiast

๐Ÿค Contributing

This is a CTF challenge repository. Contributions are welcome for:

  • Bug fixes and improvements
  • Documentation enhancements
  • Tool recommendations
  • Additional solution methods
  • Translations of guides

Please open an issue or pull request with your suggestions!


๐Ÿ“ž Support & Issues

If you encounter technical issues (not related to solving the challenge):

  1. Check Troubleshooting Section - Most issues covered above
  2. Review PREREQUISITES.md - Verify all tools installed correctly
  3. Read CTF_PLAYER_GUIDE.md - Step-by-step setup guide
  4. Open a GitHub Issue - Report bugs and problems
  5. Contact Event Organizers - Reach out through CTF platform

Note: Challenge hints should be requested through official hint system, not direct messages.


๐Ÿ“Š Repository Statistics

Repository: kavix/perseus
Language Composition:
  โ€ข Dart: 42.7%    (Flutter application)
  โ€ข Python: 56.7%  (Documentation & scripts)
  โ€ข Other: 0.6%    (Configuration files)

Lines of Code:
  โ€ข Dart Application: ~2,000+ lines
  โ€ข Documentation: ~25,000+ words
  โ€ข Configuration: ~500+ lines

Created: November 2025
Last Updated: November 2025
Platform: Android 5.0+ (API 21+)
APK Size: 20-25 MB

๐ŸŽ“ Educational Value

This project serves as an excellent resource for learning โœ… Android app development with Flutter โœ… Mobile security and forensics โœ… Reverse engineering techniques โœ… Cryptographic implementations โœ… CTF challenge design and deployment โœ… Security best practices (anti-patterns)


๐Ÿ Ready to Start?

  1. Install prerequisites - Follow PREREQUISITES.md
  2. Read setup guide - Check CTF_PLAYER_GUIDE.md
  3. Install APK - Use adb install command
  4. Start exploring - Navigate Android filesystem
  5. Solve challenge - Extract and decrypt flag
  6. Submit solution - MEDUSA{...}

Good luck, and may Perseus guide your way! ๐Ÿ›๏ธ


Made with โค๏ธ for the MEDUSA 2.0

Back to Top

About

A medium-difficulty Android CTF challenge application testing mobile security, reverse engineering, and cryptographic skills through database forensics and flag decryption.

Topics

Resources

Stars

5 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages