(Damn Insecure and Vulnerable Application) is a purposefully flawed Android application designed to teach developers, QA professionals, and security enthusiasts about common mobile vulnerabilities . By downloading the DIVA APK via GitHub , users gain access to a hands-on laboratory for identifying and exploiting security loopholes like insecure data storage and hardcoded secrets. What is DIVA?
The application includes several intentionally poor coding practices for educational analysis: DIVA - Damn Insecure and Vulnerable App - Payatu
Created by security firm Payatu, DIVA serves as a mobile equivalent to web-based learning tools like DVWA. It provides a series of challenges that cover the OWASP Mobile Top 10 vulnerabilities, making it a foundational tool for anyone starting in Android penetration testing.