Document Information

Team Member Assesor
Carina Yoehadi - 2702335175 Christoper Limawan, S.Kom, M.Kom
Ichiro Dexther Rewah - 2702368186
Noah Goklas Boanerges - 2702349786
Pilar Nalendra Sarwanto - 2702362604
Zenia Nadia Rifaniputri - 2702343832

Assesment Scope

Enumeration Description
Assesment Type Black-Box
Testing Environment Android API 35 (Rooted)
Used Tools Burpsuites, Postman, Apktool, Bundletool, Apksigner, Zipalign

Executive Summary

This test was conducted to determine the security posture of the Coffee-Portal application by identifying potential risks and vulnerabilities. During the assessment, it was discovered that the application contains hardcoded sensitive information, such as API keys, which could be exploited by an attacker. An attacker can tamper data or see other users’ credentials since most of the time it isn’t encrypted.

Findings / Indicator of Compromise (IoC)

Proof of Concept (POC)

Building and Decompiling The APK