Resource / Blogs /

DIVA

An introduction to DIVA, an intentionally vulnerable Android application designed for hands-on learning of Android security, secure coding, and penetration testing.
By
Aseem-Jakhar
January 1, 2019
4 mins
Get Tested
Device, firmware and APIs scoped as one system.
Talk to an Expert
White arrow pointing diagonally upward to the right on a black square background.White arrow pointing diagonally upward to the right on a black square background.

Key Takeaways

  • DIVA is an intentionally vulnerable Android application built specifically for security education.
  • It provides a hands-on alternative to theory-heavy Android secure development training.
  • The application can be useful for both secure coding and Android penetration testing practice.
  • DIVA contains 13 challenges covering insecure logging, hardcoding, insecure storage, input validation, and access control.
  • Some vulnerabilities extend into native code, allowing learners to explore both Java- and C-related security issues.
  • The source code is publicly available, helping learners understand not only how vulnerabilities are exploited but also how they are implemented.

What is DIVA?

DIVA (Damn insecure and vulnerable App) is an App intentionally designed to be insecure. We are releasing the Android version of Diva. We thought it would be a nice way to start the year by contributing something to the security community. The aim of the App is to teach developers/QA/security professionals, flaws that are generally present in the Apps due poor or insecure coding practices. If you are reading this, you want to either learn App pentesting or secure coding and I sincerely hope that DIVA solves your purpose. So, sit back and enjoy the ride.

Why name it Diva?

No offense to anyone, but I was bored with the name DV* and decided to name it more fancy

Who can use Diva?

The idea originated, from a developer\’s perspective. The Android security training for developers becomes slightly boring with lot of theory and not much hands-on. SO, I created DIVA for our Android developer training. Diva gamifies secure development learning. With that said, it is an excellent learning tool for aspiring Android penetration testers and security professionals as it gives an insight into app vulnerabilities including the source code. To sum it up:

  1. Android App developers
  2. Android Penetration testers
  3. Security professionals
  4. Students

What is included in Diva?

I tried to put as much vulnerabilities as possible in a short period of time. I am sure I have missed out on some vulnerabilities. Please ping me if you know of a good vulnerability tat can be included in Diva. It covers common vulnerabilities in Android apps ranging from insecure storage, input validation to access control issues. I have also included few vulnerabilities in native code, which makes it more interesting from the perspective of covering both Java and C vulnerabilities. Current Challenges include:

  1. Insecure Logging
  2. Hardcoding Issues – Part 1
  3. Insecure Data Storage – Part 1
  4. Insecure Data Storage – Part 2
  5. Insecure Data Storage – Part 3
  6. Insecure Data Storage – Part 4
  7. Input Validation Issues – Part 1
  8. Input Validation Issues – Part 2
  9. Access Control Issues – Part 1
  10. Access Control Issues – Part 2
  11. Access Control Issues – Part 3
  12. Hardcoding Issues – Part 2
  13. Input Validation Issues – Part 3

Can I contribute?

Yes, you can help us by sending us details of vulnerabilities that we can implement in future versions of Diva. Please send an email to info [at] payatu.com with subject “DIVA Contribution”.

Where can I get Diva?

How to compile Diva?

  • Download the source
  • Open the project in Android Studio
  • For Native library – open command line
    • $ cd /app/src/main/jni
    • $ make (This needs to be done only once, unless you make changes to the native code – in which case run \”make clean && make\”)
    • This will compile the native library and copy all the compiled versions in directory jniLibs which is required when building the app
  • From the menu bar: Build->Make Project or Run->Run App

How to run Diva?

  1. Download the app
  2. On your phone settings. Go to security and check Unknown Sources checkbox. This allows you to install apps outside of play store. You don’t need to do this if you are installing the app on an emulator.
  3. Connect your phone to the computer (make sure USB debugging is enabled on your phone) or run the emulator.
  4. cd
  5. adb install
  6. Start playing.

Feedback and Bug reports?

We would love to hear from you about your experience with Diva. Please send us an email on info [at] payatu.com with Subject “DIVA Feedback” or “DIVA BUG” based on what you want to share. Please include the below in your email

  1. Android version (and API version if possible)
  2. Phone make and model (or Emulator Android/API version if using an emulator)
  3. Feedback/Bug details and steps to reproduce.

‍

Get Tested
Device, firmware and APIs scoped as one system.
Talk to an Expert
White arrow pointing diagonally upward to the right on a black square background.White arrow pointing diagonally upward to the right on a black square background.
Author
Aseem Jakhar
Co-founder & Director - EXPLIoT
Red arrow pointing diagonally upward to the right.Red arrow pointing diagonally upward to the right.
FAQ

Questions Web Application teams ask us.

What is DIVA?
DIVA, or Damn Insecure and Vulnerable App, is an intentionally insecure Android application created to help developers, penetration testers, security professionals, and students learn about common Android application security vulnerabilities.
Who can use DIVA?
DIVA is intended for Android application developers, Android penetration testers, security professionals, and students interested in secure development or mobile application security.
What vulnerabilities are included in DIVA?
DIVA includes challenges covering insecure logging, hardcoded information, insecure data storage, input validation issues, and access control vulnerabilities. It also includes vulnerabilities involving native code.
Where can I download DIVA?
The DIVA Android source code is available on GitHub at the Payatu DIVA Android repository.
Can developers or researchers contribute to DIVA?
Yes. Contributors can suggest vulnerabilities that could be implemented in future versions of DIVA by contacting Payatu using the contribution details provided in the blog.

Keep Reading

For Security Leaders
Agentic AI Security: The Hidden Attack Surface Beyond Prompt Injection
August 25, 2026
10 min
For Security Leaders
Research & disclosures
Binwalk Path Traversal Vulnerability: Turning Firmware Analysis into Code Execution
August 26, 2026
8 min
Guides & tutorials
For Security Leaders
An Introduction to Smali
August 26, 2026
8 min
Dark scene with vertical thin orange lines resembling distant illuminated bars or streaks against a black background and a faint horizontal red glow near the bottom.