Android Hacking & Securing “Insecure Shop” — Hidden Credentials


fun verifyUserNamePassword(username: String, password: String): Boolean {
if (getUserCreds().containsKey(username)) {
val passwordValue = getUserCreds()[username]
return passwordValue.equals(password)
} else {
return false
private fun getUserCreds(): HashMap<String,String> {
val userCreds = HashMap<String, String>()
userCreds["shopuser"] = "!ns3csh0p"
return userCreds





Daniel Llewellyn

