Sign in

Stavro Xhardha

@apksherlock.bsky.social
9 followers 8 following 17 posts

Android developer by day, pentester by night. Website: apksherlock.github.io/apksherlock

PostsRepliesMedia
Stavro Xhardha @apksherlock.bsky.social · 25/05/2026
My neighbor got hacked. So I had to do something about it. I wrote an information guide about non-techies about how to stay safe online. My neighbor is getting it for free. Everybody else pays up: stavro485.gumroad.com/l/taihui?lay...
stavro485.gumroad.com
Ultimate Guide to Staying Safe Online
Stay safe online with this practical bilingual cybersecurity guide for everyday users. This bundle includes two print-ready 50-page A4 guides in English and German, covering passwords, phishing, scams...
000
Stavro Xhardha @apksherlock.bsky.social · 24/05/2026
I just wrote a blog post about how progressive web apps are rendered natively on #Android. dispatchersdotplayground.hashnode.dev/how-do-progr...
dispatchersdotplayground.hashnode.dev
How Chrome Turns PWAs into Native APKs via WebAPKs
Discover how Chrome converts PWAs to Android APKs using WebAPKs. Learn the flow from manifest to intent and its impact on user experience.
010
Stavro Xhardha @apksherlock.bsky.social · 10/05/2025
Good morning to you all
000
Stavro Xhardha @apksherlock.bsky.social · 16/04/2025
Before all this vibe coding noise, a vibe coder was called a code monkey.
000
Stavro Xhardha @apksherlock.bsky.social · 10/04/2025
Testing components in isolation has never actually been my favorite part, whether while developing software or when conducting a penetration test. Read more at blog.apksherlock.com/easy-dynamic...
blog.apksherlock.com
Easy Dynamic Analysis for Android with Drozer
Drozer is one of the first tools I reach for once an .apk qualifies as the system under test. At its core, it’s just ADB commands, Package Manager queries,
000
Stavro Xhardha @apksherlock.bsky.social · 23/03/2025
I was trying to trick an API to give me premium features and this is what the server gave me back.
000
Stavro Xhardha @apksherlock.bsky.social · 16/03/2025
Let's hack a mobile game in Android: The famous 2048. Read more here: #hacking #mobile #android blog.apksherlock.com/lets-hack-a-...
blog.apksherlock.com
Let's hack a Mobile Game
Games are probably the number one reason why I became a programmer. Although I have never worked in a game company before, the most intriguing part for me was finding a way to win easily, as I was way too lazy to discipline myself to become a real to...
010
Reposted by Stavro Xhardha
Demily Pyro 🥐🎀💢 @demilypyro.bsky.social · 10/03/2025
Games don't know how to end anymore nowadays. Devs want you to keep playing them forever. You know how games used to end when I was a kid? We did everything there was to do, there was a climactic last level, and then the credits rolled, and it was just done. And then we did it all again but as Luigi
571423128
Stavro Xhardha @apksherlock.bsky.social · 02/02/2025
I released a new blog post today: The Sneaky Middleman: When Activities Become Your Backdoor to Providers The Sneaky Middleman: When Activities Become Your Backdoor to Providers #android #cybersecurity blog.apksherlock.com/the-sneaky-m...
blog.apksherlock.com
The Sneaky Middleman: When Activities Become Backdoors to Providers
It is not uncommon for content providers to be unexported in inter-process communication (IPC), as the data they manage is often intended to remain internal
000
Stavro Xhardha @apksherlock.bsky.social · 25/01/2025
Today I blogged about Attacking Android Widgets apksherlock.com/2025/01/25/a...
apksherlock.com
Attacking Android Widgets
Alongside Activities, Services, Broadcast Receivers, and Content Providers, Android Widgets also serve as entry points to Android apps, broadening the app’s attack surface even more. The conc…
000
Reposted by Stavro Xhardha
Retro Computers @retrocomps.bsky.social · 24/01/2025
There he is The Setup Wizard
529677
Stavro Xhardha @apksherlock.bsky.social · 20/01/2025
Fun fact: Some Apk decompilers recognise the qualified `this` expressions in Kotlin as leaked email addresses.
000
Stavro Xhardha @apksherlock.bsky.social · 23/12/2024
Reverse engineering Android apps built with React Native. Read my latest blog post. #mobilesecurity apksherlock.com/2024/12/22/r...
apksherlock.com
Reverse Engineering React Native Apps
Cross-platform frameworks are becoming increasingly popular. For mobile apps that do not require extensive interaction with hardware and primarily focus on accessing data sources or interacting wit…
061
Stavro Xhardha @apksherlock.bsky.social · 09/12/2024
My whole childhood in one single picture. It was just fun. You would just buy the game and just play it with all the features included. Now you have to: Buy the game. Buy features. Buy skins. Buy themes. Buy levels. All these in subscriptions.
000
Stavro Xhardha @apksherlock.bsky.social · 30/11/2024
I released a new article: #Android apps as reconnaissance tools. You can read it here: apksherlock.com/2024/11/29/a...
apksherlock.com
Android apps as reconnaissance tools.
When targeting[1] a web surface—whether it’s a web application or a web server API—gathering intelligence and information is a crucial step before constructing payloads for any identified vulnerabi…
000
Stavro Xhardha @apksherlock.bsky.social · 24/11/2024
Like he messed up Twitter. Sure
000
Stavro Xhardha @apksherlock.bsky.social · 24/11/2024
It's 1995 and Angela (played by Sandra Bullock) is freaking out because of a software company pretending to sell antiviruses to the Wall Street business. They know everything about her: Past relationships, parents origins, her birthday, her address and even what she used to smoke. Welcome to 2024.
000
Stavro Xhardha @apksherlock.bsky.social · 21/11/2024
Hi everyone. New at Bluesky. Looking forward to connecting with software engineers, security researchers and pentesters, especially in the field of Android and Automotive. #cybersecurity #software_engineering #android
042