> For the complete documentation index, see [llms.txt](https://kero0x1.gitbook.io/general/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://kero0x1.gitbook.io/general/mobile-pentest/mobile-hacking-lab/food-store.md).

# Food Store

Hello everyone , In this blog post , I will try to explain my solution steps for Food Store challenge from Mobile Hacking Lab Platform . i hope it will be useful for you

1. after install app then we have 2 Options login if we have an account and sign if we don’t have

   <img src="https://2140186435-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpoPpsF6DyQtOrXy70rxC%2Fuploads%2FHKnxuakfrWXwOCCduSz6%2Fimage.png?alt=media" alt="image.png" width="268">
2. lets analyse the `AndroidManifest.xml`

   <figure><img src="https://2140186435-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpoPpsF6DyQtOrXy70rxC%2Fuploads%2F7z84ErNfXCaG4Y7627yl%2Fimage.png?alt=media&amp;token=35d92c17-165b-4064-9ef0-3803013f9479" alt="" width="563"><figcaption></figcaption></figure>
3. we have 3 Activities( Main , signup , login ) and 1 provider :
4. **Main activity Component :**
   1. it check for if user input username , it login with guest and if there is no address : application submit the order with unknown address
   2. then the The app retrieves user information (`USERNAME`, `USER_CREDIT`, `IS_PRO_USER`, and `USER_ADDRESS`) from the `Intent` used to start the activity.

      <figure><img src="https://2140186435-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpoPpsF6DyQtOrXy70rxC%2Fuploads%2FSf9onc8jg6SJWSTDqIKS%2Fimage.png?alt=media&amp;token=34dbbcf8-b2c3-45b0-be46-221cad05ce07" alt="" width="563"><figcaption></figcaption></figure>
5. **login Activity Component :**
   1. it use DBHelper
   2. and then determine if the user put username and password (not null)
   3. if the credential is correct , App will create an intent with all user data to start the activity
   4. if the user has no account then app will start signup activity

      <figure><img src="https://2140186435-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpoPpsF6DyQtOrXy70rxC%2Fuploads%2Fy1Yjm0JYTxLj0lWOHTBA%2Fimage.png?alt=media&amp;token=4fcbfe95-8210-4378-934a-79cb9d64e7da" alt="" width="563"><figcaption></figcaption></figure>
6. **Signup Component :**
   1. When the `signupBtn` is clicked, the `onCreate$lambda$0` method is called, which performs the actual user registration logic (validation, adding the user to the database, and showing a Toast message).
   2. it take the data from user like : username , password , address and if the 3 fields ≠ null ⇒ App will create a new user and show this message `User Registered Successfully`
   3. If all fields are filled, a new `User` object is created with the provided information. The `DBHelper` class is used to add the user to the database.
7. **DBHelper Class Structure :**
   1. when we start the DB for the first time , it exec this command : `db.execSQL("CREATE TABLE users (\n id INTEGER PRIMARY KEY AUTOINCREMENT,\n username TEXT,\n password TEXT,\n address TEXT,\n isPro INTEGER\n \n \n)");`
   2. **`adduser()` :** it take a user parameter , then encode the password and store the name then exec this command to store user data : `"INSERT INTO users (username, password, address, isPro) VALUES ('" + Username + "', '" + encodedPassword + "', '" + encodedAddress + "', 0)`
   3. **`when isPro = 0`** here it mean application create a regular user with limit features
   4. `getUserByUsername(String Username)`: This method retrieves a user based on the username , Password and address are decoded from Base64 and show in plain text

      <figure><img src="https://2140186435-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpoPpsF6DyQtOrXy70rxC%2Fuploads%2FYUycHdo41PDV1XhTpFtg%2Fimage.png?alt=media&amp;token=0877febe-ae24-4648-ad7a-005f44300267" alt="" width="563"><figcaption></figcaption></figure>
8. The exploit here is : inject sql query that have a `isPro=1` ⇒ it mean we will create a pro account with encoded password and address
   1. `INSERT INTO users (username, password, address, isPro) VALUES ('keroPro', 'MTIzNA==', 'Y2Fpcm8=', 1)`
   2. i have already access the database and then insert the query to create an account

      <figure><img src="https://2140186435-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpoPpsF6DyQtOrXy70rxC%2Fuploads%2FjLnBlKOSbrqhkKYqMVRG%2Fimage.png?alt=media&amp;token=a3fd11b0-1dc7-463b-a003-9185c21f8b21" alt="" width="563"><figcaption></figcaption></figure>
9. it’s already success but i can’t do login because may be the app is have a problem or my emulator doesn’t show all gui

   <figure><img src="https://2140186435-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpoPpsF6DyQtOrXy70rxC%2Fuploads%2FTqsGjyMTraTO2c9qTzNs%2Fimage.png?alt=media&amp;token=a755f99b-e695-4879-b627-523a23a6968f" alt="" width="455"><figcaption></figcaption></figure>
