> For the complete documentation index, see [llms.txt](https://wnagzihxa1n.gitbook.io/happy-android-security/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://wnagzihxa1n.gitbook.io/happy-android-security/readme.md).

# 前言

* [前言](/happy-android-security/readme.md)
* [CTF](/happy-android-security/capture_the_flag.md)
  * [2014 NAGA\&PIOWIND APP应用攻防竞赛 Crackme01](/happy-android-security/capture_the_flag/2014nagapiowindapp-ying-yong-gong-fang-jing-sai-crackmel1sign.md)
  * [2014 NAGA\&PIOWIND APP应用攻防竞赛 Crackme02](/happy-android-security/capture_the_flag/2014nagapiowindapp-ying-yong-gong-fang-jing-sai-crackmel2sign.md)
  * [2014 NAGA\&PIOWIND APP应用攻防竞赛 Crackme03](/happy-android-security/capture_the_flag/2014nagapiowindapp-ying-yong-gong-fang-jing-sai-crackmel3sign.md)
  * [2014 NAGA\&PIOWIND APP应用攻防竞赛 Crackme04](/happy-android-security/capture_the_flag/2014nagapiowindapp-ying-yong-gong-fang-jing-sai-crackmel4sign.md)
  * [2015 0CTF Vezel 100](/happy-android-security/capture_the_flag/2015_0ctf_vezel.md)
  * [2015 0CTF Simple 150](/happy-android-security/capture_the_flag/2015_0ctf_simple.md)
  * [2015 XCTF\&RCTF Flag System 100](/happy-android-security/capture_the_flag/2015_xctf_rctf_flagsystem.md)
  * [2015 XCTF\&RCTF Where 300](/happy-android-security/capture_the_flag/2015_xctf_rctf_where.md)
  * [2015 海峡两岸CTF 一个APK逆向试试吧](/happy-android-security/capture_the_flag/2015-hai-xia-liang-an-ctf-yi-ge-apk-ni-xiang-shi-shi-ba.md)
  * [2016 LCTF EASY 100](/happy-android-security/capture_the_flag/2016_lctf_easy.md)
  * [2016 AliCTF Timer 50](/happy-android-security/capture_the_flag/2016_alictf_timer.md)
  * [2016 AliCTF Loop And Loop 100](/happy-android-security/capture_the_flag/2016_alictf_loopandloop.md)
  * [2016 ZCTF Android1 200](/happy-android-security/capture_the_flag/2016_zctf_android.md)
  * [2016 LCTF EASY EASY 200](/happy-android-security/capture_the_flag/2016_lctf_easyeasy.md)
  * [2017 ISCC 全国大学生信息安全与对抗技术竞赛 简单到不行](/happy-android-security/capture_the_flag/2017iscc-quan-guo-da-xue-sheng-xin-xi-an-quan-yu-dui-kang-ji-shu-jing-sai-jian-dan-dao-bu-hang.md)
  * [2017 SSCTF 加密勒索软件 100](/happy-android-security/capture_the_flag/2017ssctf-jia-mi-le-suo-ruan-jian.md)
  * [2017 SSCTF Login 200](/happy-android-security/capture_the_flag/2017_ssctf_login.md)
  * [2017 XCTF\&NJCTF Easy Crack 100](/happy-android-security/capture_the_flag/2017_xctf_njctf_easycrack.md)
  * [2017 XCTF\&NJCTF Safe Box 100](/happy-android-security/capture_the_flag/2017_xctf_njctf_safebox.md)
  * [2017 XCTF\&NJCTF Little Rotator Game 200](/happy-android-security/capture_the_flag/2017_xctf_njctf_littlerotatorgame.md)
  * [2017 陕西省网络安全大赛 拯救鲁班七号 100](/happy-android-security/capture_the_flag/2017-shan-xi-sheng-wang-luo-an-quan-da-sai-zheng-jiu-lu-ban-qi-hao.md)
  * [2017 陕西省网络安全大赛 The Marauders Map 150](/happy-android-security/capture_the_flag/2017-shan-xi-sheng-wang-luo-an-quan-da-sai-themaraudersmap.md)
  * [2017 陕西省网络安全大赛 人民的名义 抓捕赵德汉1 200](/happy-android-security/capture_the_flag/2017-shan-xi-sheng-wang-luo-an-quan-da-sai-ren-min-de-ming-yi-zhua-bu-zhao-de-han-1.md)
  * [2017 陕西省网络安全大赛 人民的名义 抓捕赵德汉2 200](/happy-android-security/capture_the_flag/2017-shan-xi-sheng-wang-luo-an-quan-da-sai-ren-min-de-ming-yi-zhua-bu-zhao-de-han-2.md)
  * [2017 陕西省网络安全大赛 取证密码 200](/happy-android-security/capture_the_flag/2017-shan-xi-sheng-wang-luo-an-quan-da-sai-qu-zheng-mi-ma.md)
* [应用侧安全](/happy-android-security/application_security.md)
  * [任意私有组件启动漏洞的利用](/happy-android-security/application_security/ren-yi-si-you-zu-jian-qi-dong-lou-dong-de-li-yong.md)
  * [\[ByteDance\] \[TikTok\] NotificationBroadcastReceiver导出存在任意私有组件启动结合FileProvider机制与FbSoLoader框架导致本地代码执行漏洞](/happy-android-security/application_security/bytedancetiktokcomzhiliaoappmusically1483notificationbroadcastreceiver-dao-chu-cun-zai-ren-yi-si-you.md)
  * [\[ByteDance\] \[TikTok\] DetailActivity导出存在任意私有组件启动结合FileProvider机制与FbSoLoader框架导致本地代码执行漏洞](/happy-android-security/application_security/bytedancetiktokcomzhiliaoappmusically1483detailactivity-dao-chu-cun-zai-ren-yi-si-you-zu-jian-qi-don.md)
  * [\[ByteDance\] \[TikTok\] WallPaperDataProvider导出存在任意私有文件读取漏洞](/happy-android-security/application_security/bytedancetiktokcomzhiliaoappmusically1483wallpaperdataprovider-dao-chu-cun-zai-ren-yi-si-you-wen-jia.md)
  * [\[Adobe\] \[Acrobat Reader\] AdobeReader处理DeepLink时未正确进行合法性校验导致下载PDF文件过程出现路径穿越可造成远程代码执行](/happy-android-security/application_security/adobeacrobatreadercomadobereader216018197adobereader-chu-li-deeplink-shi-wei-zheng-que-jin-hang-he-f.md)
  * [\[CVE-2019-16253\] \[Samsung\] \[SMT\] SamsungTTSService导出存在任意私有组件调用提权漏洞](/happy-android-security/application_security/cve201916253samsungsmtsamsungttsservice-dao-chu-cun-zai-ren-yi-si-you-zu-jian-tiao-yong-ti-quan-lou.md)
  * [\[CVE-2021-25390\] \[Samsung\] \[Photo Table\] PermissionsRequestActivity存在任意私有组件启动漏洞可获取ContentProvider数据](/happy-android-security/application_security/cve202125390samsungphototablecomandroiddreamsphototablepermissionsrequestactivity-dao-chu-cun-zai-re.md)
  * [\[CVE-2021-25391\] \[Samsung\] \[Secure Folder\] KnoxSettingCheckLockTypeActivity泄露Intent可获取ContentProvider数据](/happy-android-security/application_security/cve202125391samsungsecurefoldercomsamsungknoxsecurefolder160161knoxsettingchecklocktypeactivity-dao.md)
  * [\[CVE-2021-25397\] \[Samsung\] \[TelephonyUI\] PhotoringReceiver导出存在任意文件写漏洞结合动态库加载行为可实现本地任意代码执行](/happy-android-security/application_security/cve202125397samsungtelephonyuicomsamsungandroidapptelephonyui1210237photoringreceiver-dao-chu-cun-za.md)
  * [\[CVE-2021-25410\] \[Samsung\] \[CallBGProvider\] CallBGProvider的调用权限定义为Normal可实现任意私有文件读取](/happy-android-security/application_security/cve202125410samsungcallbgprovidercomsamsungandroidcallbgprovider1200027callbgprovider-de-tiao-yong-q.md)
  * [\[CVE-2021-25413\] \[Samsung\] \[Contacts\] SetProfilePhotoActivity导出存在任意私有组件启动漏洞可获取ContentProvider数据](/happy-android-security/application_security/cve202125413samsungcontactscomsamsungandroidappcontacts1211030setprofilephotoactivity-dao-chu-cun-za.md)
  * [\[CVE-2021-25414\] \[Samsung\] \[Contacts\] SetProfilePhotoActivity导出存在任意私有文件读写漏洞](/happy-android-security/application_security/cve202125414samsungcontactscomsamsungandroidappcontacts1211030setprofilephotoactivity-dao-chu-cun-za.md)
  * [\[CVE-2021-25440\] \[Samsung\] \[FactoryCameraFB\] CameraTestActivity导出存在文件读写权限泄露漏洞](/happy-android-security/application_security/cve202125440samsungfactorycamerafbcomsecfactorycamera3443cameratestactivity-dao-chu-cun-zai-wen-jian.md)
  * [\[CVE-2022-22292\] \[Samsung\] \[Telecom\] 动态注册BroadcastReceiver默认导出存在任意私有组件启动漏洞](/happy-android-security/application_security/cve202222292samsungtelecomcomandroidservertelecom-dong-tai-zhu-ce-broadcastreceiver-mo-ren-dao-chu-c.md)
* [系统侧安全](/happy-android-security/system_security.md)
  * [REDMI 5 Plus Second Space Password Bypass](/happy-android-security/system_security/xiaomi_redmi_5_plus_second_space_password_bypass.md)
  * [【蓝牙】CVE-2017-13258 CVE-2017-13260 CVE-2017-13261 CVE-2017-13262信息泄露](/happy-android-security/system_security/cve201713258cve201713260cve201713261cve201713262-xin-xi-xie-lou.md)
  * [【蓝牙】CVE-2018-9357 BNEP\_Write越界写导致RCE](/happy-android-security/system_security/cve20189357bnepwrite-yue-jie-xie-dao-zhi-rce.md)
  * [【蓝牙】CVE-2018-9358 信息泄露](/happy-android-security/system_security/cve20189358-xin-xi-xie-lou.md)
  * [【蓝牙】CVE-2018-9359 process\_l2cap\_cmd\_L2CAP\_CMD\_INFO\_REQ未判断缓冲区边界造成信息泄露](/happy-android-security/system_security/cve20189359processl2capcmdl2capcmdinforeq-wei-pan-duan-huan-chong-qu-bian-jie-zao-cheng-xin-xi-xie-l.md)
  * [【蓝牙】CVE-2018-9360 process\_l2cap\_cmd\_L2CAP\_CMD\_CONN\_REQ未判断缓冲区边界造成信息泄露](/happy-android-security/system_security/cve20189360processl2capcmdl2capcmdconnreq-wei-pan-duan-huan-chong-qu-bian-jie-zao-cheng-xin-xi-xie-l.md)
  * [【蓝牙】CVE-2018-9361 process\_l2cap\_cmd\_L2CAP\_CMD\_DISC\_REQ未判断缓冲区边界造成信息泄露](/happy-android-security/system_security/cve20189361processl2capcmdl2capcmddiscreq-wei-pan-duan-huan-chong-qu-bian-jie-zao-cheng-xin-xi-xie-l.md)
  * [【蓝牙】CVE-2018-9365 smp\_sm\_event数组越界访问导致RCE](/happy-android-security/system_security/cve20189365smpsmevent-shu-zu-yue-jie-fang-wen-dao-zhi-rce.md)
  * [【蓝牙】CVE-2018-9381 gatts\_process\_read\_by\_type\_req未初始化栈变量导致信息泄露](/happy-android-security/system_security/cve20189381gattsprocessreadbytypereq-wei-chu-shi-hua-zhan-bian-liang-dao-zhi-xin-xi-xie-lou.md)
  * [【NFC】CVE-2018-9584 nfc\_ncif\_set\_config\_status未检测长度越界读写](/happy-android-security/system_security/cve20189584nfcncifsetconfigstatus-wei-jian-ce-chang-du-yue-jie-du-xie.md)
  * [【NFC】CVE-2018-9585\_nfc\_ncif\_proc\_get\_routing未检测长度越界读写](/happy-android-security/system_security/cve20189585nfcncifprocgetrouting-wei-jian-ce-chang-du-yue-jie-du-xie.md)
  * [【蓝牙】CVE-2019-2209 未检测PIN码长度导致越界读造成信息泄露](/happy-android-security/system_security/cve20192209-wei-jian-ce-pin-ma-chang-du-dao-zhi-yue-jie-du-zao-cheng-xin-xi-xie-lou.md)
  * [【NFC】CVE-2019-9358 ce\_t3t\_data\_cback越界读写](/happy-android-security/system_security/cve20199358cet3tdatacback-yue-jie-du-xie.md)
* [内核驱动侧安全](/happy-android-security/driver_security.md)
