Android Security & Malware
43.4K subscribers
134 photos
20 videos
7 files
2.77K links
Mobile cybersecurity channel
Links: https://linktr.ee/mobilehacker
Contact: [email protected]
Download Telegram
Reverse Engineering of Looney Tunes: Carrot Crazy game
Part 1 - Passwords #retro #GameBoy
https://www.huderlem.com/blog/posts/carrot-crazy-1/
Twitter for Android could allow a bad actor to see nonpublic account information or to control your account (i.e., send Tweets or Direct Messages)
https://privacy.twitter.com/en/blog
Lesser-known Tools for Android Application PenTesting

-Magisk + modules
-DisableFlagSecure
-AdbManager
-ProxyDroid
-pidcat
-resize
https://captmeelo.com/pentest/2019/12/30/lesser-known-tools-for-android-pentest.html
CSRF + XSS + SMS spoofing + Android deep link URL redirection

Great example of chaining low impact vulnerabilities in #TikTok to remotely manipulate account content

-delete user video
-upload user video
-make "private" videos "public"
https://research.checkpoint.com/2020/tik-or-tok-is-tiktok-secure-enough/