A medium-difficulty Android exploitation and forensics CTF challenge for MEDUSA 2.0 cybersecurity competition.
Perseus is a comprehensive Android CTF challenge that tests participants' skills in mobile security, reverse engineering, cryptography, and digital forensics. Players must navigate the Android filesystem, extract hidden databases, decrypt encrypted data, and ultimately retrieve the flag.
| Attribute | Value |
|---|---|
| Category | Mobile / Android Forensics |
| Difficulty | Medium |
| Event | MEDUSA 2.0 (University of Kelaniya) |
| Author | @kavix |
| Platform | Android 5.0+ (API 21+) |
| APK Size | ~20-25 MB |
| Expected Time | 1-4 hours (varies by skill level) |
Players must complete the following tasks to solve the challenge:
- โ Install the Perseus APK on an Android device/emulator
- โ Navigate the Android filesystem using ADB
- โ Locate the hidden SQLite database (obfuscated path)
- โ Extract the database from the device
- โ Query the database to find credentials
- โ Decrypt the encrypted flag using cryptographic principles
- โ
Submit the flag in format:
MEDUSA{...}
- Android Debug Bridge (ADB) proficiency
- Android filesystem navigation and forensics
- SQLite database analysis
- Cryptography (XOR cipher, SHA-256 hashing)
- APK reverse engineering
- Python scripting and cryptographic algorithms
- Problem-solving and persistence
- ADB (Android Debug Bridge) - Device/emulator interaction
- Android Device or Emulator - API 21+ (Android 5.0 Lollipop)
- SQLite3 - Database analysis
- Python 3 - Flag decryption scripts
- Optional: apktool, jadx for advanced analysis
# 1. Install ADB (choose your OS)
# macOS
brew install android-platform-tools
# Linux (Debian/Ubuntu)
sudo apt-get install android-tools-adb
# Windows
# Download from https://developer.android.com/tools/releases/platform-tools
# 2. Verify installation
adb --version
# 3. Install the APK
adb install perseus.apk
# 4. Launch the app
adb shell am start -n com.example.perseus/.MainActivity# Connect to device shell
adb shell
# Navigate to app's external storage
cd /storage/emulated/0/Android/data/com.example.perseus
# List contents
ls -la
# Exit shell
exitperseus/
โโโ assets/
โ โโโ images/
โ โ โโโ logo 1 - white.png # Application logo
โ โโโ config.enc # Encrypted SQLite database
โ
โโโ lib/
โ โโโ main.dart # Flutter UI & authentication
โ โโโ database_helper.dart # SQLite & encryption logic
โ โโโ event_prefs.dart # SharedPreferences management
โ
โโโ android/ # Android native config
โโโ tools/ # Build utilities
โ
โโโ pubspec.yaml # Flutter dependencies
โโโ pubspec.lock # Dependency lock file
โโโ analysis_options.yaml # Dart analysis config
โ
โโโ CTF_PLAYER_GUIDE.md # Player setup guide
โโโ GUIDE.md # Complete solver guide
โโโ IMPLEMENTATION_GUIDE.md # Technical implementation
โโโ PREREQUISITES.md # Requirements & tools
โโโ HINTS.txt # Progressive hints
โ
โโโ README.md # This file
The SQLite database contains a credentials table:
CREATE TABLE credentials (
id INTEGER PRIMARY KEY AUTOINCREMENT,
username TEXT NOT NULL UNIQUE,
password TEXT NOT NULL
);
-- Test Data
INSERT INTO credentials (username, password)
VALUES ('admin', 'medusa2024');Algorithm: XOR cipher with SHA-256 key derivation
1. Key Generation: SHA256(username + password)
2. Plaintext Flag: MEDUSA{round_2_task_is_comp}
3. Encryption: Each byte XOR with corresponding key byte
Example Decryption (Python):
import hashlib
username = "admin"
password = "medusa2024"
# Generate SHA-256 key
key = hashlib.sha256((username + password).encode()).digest()
# Encrypted flag bytes
encrypted = [
0xfd, 0xd7, 0x6d, 0xbc, 0xaf, 0x0c, 0x9e, 0xd5, 0x89, 0xc3,
0x87, 0x26, 0x9c, 0xa2, 0x64, 0x15, 0x8a, 0x28, 0xf2, 0xa5,
0x88, 0x78, 0xf7, 0x8e, 0xd1, 0xd7, 0x82, 0x93
]
# XOR decryption
decrypted = bytes([encrypted[i] ^ key[i % len(key)] for i in range(len(encrypted))])
flag = decrypted.decode('utf-8')
print(f"Flag: {flag}") # Output: MEDUSA{round_2_task_is_comp}| Component | Technology | Purpose |
|---|---|---|
| UI Framework | Flutter | Cross-platform Android app |
| Database | SQLite 3 | Credential storage |
| Cryptography | Dart crypto | XOR + SHA-256 |
| Storage | External + Internal | Database and preferences |
| Animations | Flutter Animations | Smooth UI effects |
# 1. Connect device and install APK
adb devices
adb install perseus.apk
# 2. Navigate to app storage
adb shell
cd /storage/emulated/0/Android/data/com.example.perseus/files
find . -name "*.db"
# Expected output:
# /storage/emulated/0/Android/data/com.example.perseus/files/logs/com.ecsc-uok.medusa.kavix/config.db
# 3. Extract database
adb pull /storage/emulated/0/Android/data/com.example.perseus/files/logs/com.ecsc-uok.medusa.kavix/config.db
# 4. Analyze database
sqlite3 config.db
sqlite> SELECT * FROM credentials;
# Output: 1|admin|medusa2024
# 5. Decrypt flag using Python script (see above)# Decompile APK to extract source code
apktool d perseus.apk -o perseus_decompiled
# Or use jadx for Java decompilation
jadx perseus.apk -d perseus_jadx
# Find encrypted flag and decryption logic in:
# - lib/database_helper.dart
# - assets/config.enc# Use Frida to hook database operations
pip3 install frida-tools
# Create Frida script to intercept credentials
# See GUIDE.md for complete Frida examples- ๐จ Dark Theme with neon green accents (#39FF14)
- โจ Animated Glowing Logo with pulsing effects
- ๐ Form Validation with error handling
- ๐ฏ Shake Animation on authentication failure
- โ Success Page with checkmark animation
- ๐ Mythology Story Page (Medusa legend)
- ๐ณ Haptic Feedback (vibration and success impacts)
- ๐ฌ Page Transitions with slide + fade animations
- ๐ฑ Immersive Full-Screen Mode
- ๐ SQLite Database Management with singleton pattern
- ๐ฆ Asset-Based Database Initialization
- ๐ XOR Encryption/Decryption Logic
- ๐ฒ SharedPreferences Management
- ๐ญ Event Data Storage (Base64 encoded)
Flutter/Dart:
dependencies:
flutter:
sdk: flutter
sqflite: ^2.3.0
path_provider: ^2.1.1
path: ^1.8.3
crypto: ^3.0.3
shared_preferences: ^2.2.2
cupertino_icons: ^1.0.8Development:
dev_dependencies:
flutter_test:
sdk: flutter
flutter_lints: ^5.0.0System Requirements:
- Flutter SDK 3.9.2+
- Dart 3.9.2+
- Android SDK API 21+ (target 34)
- Java JDK 11+
This repository includes comprehensive guides for both players and organizers:
| Document | Purpose | Audience |
|---|---|---|
| CTF_PLAYER_GUIDE.md | Setup, tools, troubleshooting | Players |
| GUIDE.md | Complete solution walkthrough | Players (spoilers!) |
| IMPLEMENTATION_GUIDE.md | Architecture and implementation | Organizers/Developers |
| PREREQUISITES.md | Detailed requirements and setup | New players |
| HINTS.txt | Progressive hints system | Players |
Valid Login:
Username: admin
Password: medusa2024
Expected Flag: MEDUSA{round_2_task_is_comp}
Invalid Login: Any other username/password combination will trigger an error state with shake animation.
| Skill Level | Estimated Time | Approach |
|---|---|---|
| Beginner | 2-4 hours | Follow guide, learn tools |
| Intermediate | 1-2 hours | Use hints, some exploration |
| Advanced | 30-60 minutes | Minimal guidance needed |
| Expert | <30 minutes | Multiple solution methods |
โ Don't:
- Try to brute force the flag
- Assume database is in APK assets (it's created at runtime)
- Skip launching the app (database created on first run)
- Only check
/data/data/(external storage not accessible) - Overlook hidden/obfuscated directory names
โ Do:
- Explore filesystem thoroughly
- Check both internal and external storage
- Analyze database files with SQLite tools
- Look for encoded/encrypted data
- Read app source code if decompiling
# Device not detected
adb kill-server
adb start-server
adb devices
# Device unauthorized
# โ Unlock device and tap "Allow" on authorization prompt
# Device offline
adb reconnect# Insufficient storage
# โ Free up at least 200MB on device
# Installation failed
# โ Use: adb install -r perseus.apk (force reinstall)# Database files created on first app launch
# โ Launch app and attempt login before extracting
# Permission denied
# โ Use adb pull (external storage is accessible without root)- apktool - APK decompilation
- jadx - Dex to Java decompiler
- Frida - Dynamic instrumentation framework
- objection - Frida-based mobile toolkit
# Clone repository
git clone https://github.com/kavix/perseus.git
cd perseus
# Get Flutter dependencies
flutter pub get
# Analyze code
flutter analyze
# Run on connected device
flutter run
# Build debug APK
flutter build apk --debug
# Build release APK
flutter build apk --release# Check Flutter setup
flutter doctor
# Run tests
flutter test
# Format code
dart format lib/
# Clean build artifacts
flutter cleanEducational Purpose Only
This is a CTF challenge application designed for learning and competition. In production environments:
- โ Never store plaintext passwords in databases
- โ Never hardcode encryption keys in source code
- โ Use proper password hashing (bcrypt, argon2)
- โ Use industry-standard encryption (AES, TLS)
- โ Implement proper authentication mechanisms
- โ Follow OWASP Mobile Security guidelines
This project is released for educational and CTF competition use only.
For any commercial or non-educational use, please contact the author.
kavix - @kavix
- ๐ง Contact through GitHub
- ๐ MEDUSA CTF 2.0 Organizer
- ๐ Mobile Security Enthusiast
This is a CTF challenge repository. Contributions are welcome for:
- Bug fixes and improvements
- Documentation enhancements
- Tool recommendations
- Additional solution methods
- Translations of guides
Please open an issue or pull request with your suggestions!
If you encounter technical issues (not related to solving the challenge):
- Check Troubleshooting Section - Most issues covered above
- Review PREREQUISITES.md - Verify all tools installed correctly
- Read CTF_PLAYER_GUIDE.md - Step-by-step setup guide
- Open a GitHub Issue - Report bugs and problems
- Contact Event Organizers - Reach out through CTF platform
Note: Challenge hints should be requested through official hint system, not direct messages.
Repository: kavix/perseus
Language Composition:
โข Dart: 42.7% (Flutter application)
โข Python: 56.7% (Documentation & scripts)
โข Other: 0.6% (Configuration files)
Lines of Code:
โข Dart Application: ~2,000+ lines
โข Documentation: ~25,000+ words
โข Configuration: ~500+ lines
Created: November 2025
Last Updated: November 2025
Platform: Android 5.0+ (API 21+)
APK Size: 20-25 MB
This project serves as an excellent resource for learning โ Android app development with Flutter โ Mobile security and forensics โ Reverse engineering techniques โ Cryptographic implementations โ CTF challenge design and deployment โ Security best practices (anti-patterns)
- Install prerequisites - Follow PREREQUISITES.md
- Read setup guide - Check CTF_PLAYER_GUIDE.md
- Install APK - Use adb install command
- Start exploring - Navigate Android filesystem
- Solve challenge - Extract and decrypt flag
- Submit solution - MEDUSA{...}
Good luck, and may Perseus guide your way! ๐๏ธ
Made with โค๏ธ for the MEDUSA 2.0