安全分析报告: 多多买菜司机 v6.9.3

安全分数


安全分数 46/100

风险评级


等级

  1. A
  2. B
  3. C
  4. F

严重性分布 (%)


隐私风险

2

用户/设备跟踪器


调研结果

高危 5
中危 29
信息 3
安全 2
关注 20

高危 如果一个应用程序使用WebView.loadDataWithBaseURL方法来加载一个网页到WebView,那么这个应用程序可能会遭受跨站脚本攻击

如果一个应用程序使用WebView.loadDataWithBaseURL方法来加载一个网页到WebView,那么这个应用程序可能会遭受跨站脚本攻击
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x05h-Testing-Platform-Interaction.md#static-analysis-7

Files:
meco/webkit/WebView.java, line(s) 837,405
mecox/provider/impl/a/b.java, line(s) 1616,36,98,197,202,207,212,217,222,227,232,238,243,248,254,259,264,269,274,279,284,289,294,300,305,310,426,436,461,466,471,476,496,501,506,511,516,526,549,1462
mecox/webkit/WebView.java, line(s) 449,109

高危 使用弱加密算法

使用弱加密算法
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x04g-Testing-Cryptography.md#identifying-insecure-andor-deprecated-cryptographic-algorithms-mstg-crypto-4

Files:
com/heytap/mcssdk/i/b.java, line(s) 11
com/xunmeng/pinduoduo/basekit/http/dns/m/a.java, line(s) 40,59

高危 应用程序使用带PKCS5/PKCS7填充的加密模式CBC。此配置容易受到填充oracle攻击。

应用程序使用带PKCS5/PKCS7填充的加密模式CBC。此配置容易受到填充oracle攻击。
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x04g-Testing-Cryptography.md#identifying-insecure-andor-deprecated-cryptographic-algorithms-mstg-crypto-4

Files:
com/xunmeng/pinduoduo/vita/patch/inner/a.java, line(s) 75
com/xunmeng/tms/map/l/c.java, line(s) 29

高危 不安全的Web视图实现。Web视图忽略SSL证书错误并接受任何SSL证书。此应用程序易受MITM攻击

不安全的Web视图实现。Web视图忽略SSL证书错误并接受任何SSL证书。此应用程序易受MITM攻击
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x05g-Testing-Network-Communication.md#webview-server-certificate-verification

Files:
io/flutter/plugins/webviewflutter/FlutterWebViewClient.java, line(s) 54,253,52,251

中危 应用程序存在Janus漏洞

应用程序使用了v1签名方案进行签名,如果只使用v1签名方案,那么它就容易受到安卓5.0-8.0上的Janus漏洞的攻击。在安卓5.0-7.0上运行的使用了v1签名方案的应用程序,以及同时使用了v2/v3签名方案的应用程序也同样存在漏洞。

中危 应用程序可以安装在有漏洞的已更新 Android 版本上

Android 5.0-5.0.2, [minSdk=21]
该应用程序可以安装在具有多个未修复漏洞的旧版本 Android 上。这些设备不会从 Google 接收合理的安全更新。支持 Android 版本 => 10、API 29 以接收合理的安全更新。

中危 Service (com.xunmeng.tms.goldfinger.PddAccessibilityService) 受权限保护, 但是应该检查权限的保护级别。

Permission: android.permission.BIND_ACCESSIBILITY_SERVICE [android:exported=true]
发现一个 Service被共享给了设备上的其他应用程序,因此让它可以被设备上的任何其他应用程序访问。它受到一个在分析的应用程序中没有定义的权限的保护。因此,应该在定义它的地方检查权限的保护级别。如果它被设置为普通或危险,一个恶意应用程序可以请求并获得这个权限,并与该组件交互。如果它被设置为签名,只有使用相同证书签名的应用程序才能获得这个权限。

中危 Activity (com.xunmeng.tms.wxapi.WXPayEntryActivity) 未被保护。

[android:exported=true]
发现 Activity与设备上的其他应用程序共享,因此使其对设备上的任何其他应用程序都可访问。

中危 Service (com.vivo.push.sdk.service.CommandClientService) 未被保护。

[android:exported=true]
发现 Service与设备上的其他应用程序共享,因此使其对设备上的任何其他应用程序都可访问。

中危 Activity设置了TaskAffinity属性

(com.xunmeng.pinduoduo.apm.crash.activity.EmptyActivity)
如果设置了 taskAffinity,其他应用程序可能会读取发送到属于另一个任务的 Activity 的 Intent。为了防止其他应用程序读取发送或接收的 Intent 中的敏感信息,请始终使用默认设置,将 affinity 保持为包名

中危 Broadcast Receiver (com.xunmeng.pinduoduo.push.xiaomi.XiaomiPushReceiver) 未被保护。

[android:exported=true]
发现 Broadcast Receiver与设备上的其他应用程序共享,因此使其对设备上的任何其他应用程序都可访问。

中危 Service (com.huawei.hms.support.api.push.service.HmsMsgService) 未被保护。

[android:exported=true]
发现 Service与设备上的其他应用程序共享,因此使其对设备上的任何其他应用程序都可访问。

中危 Content Provider (com.huawei.hms.support.api.push.PushProvider) 未被保护。

[android:exported=true]
发现 Content Provider与设备上的其他应用程序共享,因此使其对设备上的任何其他应用程序都可访问。

中危 Service (com.xunmeng.pinduoduo.push.oppo.OppoPushService) 受权限保护, 但是应该检查权限的保护级别。

Permission: com.coloros.mcs.permission.SEND_MCS_MESSAGE [android:exported=true]
发现一个 Service被共享给了设备上的其他应用程序,因此让它可以被设备上的任何其他应用程序访问。它受到一个在分析的应用程序中没有定义的权限的保护。因此,应该在定义它的地方检查权限的保护级别。如果它被设置为普通或危险,一个恶意应用程序可以请求并获得这个权限,并与该组件交互。如果它被设置为签名,只有使用相同证书签名的应用程序才能获得这个权限。

中危 Service (com.xunmeng.pinduoduo.push.oppo.OppoAppPushService) 受权限保护, 但是应该检查权限的保护级别。

Permission: com.heytap.mcs.permission.SEND_MCS_MESSAGE [android:exported=true]
发现一个 Service被共享给了设备上的其他应用程序,因此让它可以被设备上的任何其他应用程序访问。它受到一个在分析的应用程序中没有定义的权限的保护。因此,应该在定义它的地方检查权限的保护级别。如果它被设置为普通或危险,一个恶意应用程序可以请求并获得这个权限,并与该组件交互。如果它被设置为签名,只有使用相同证书签名的应用程序才能获得这个权限。

中危 Broadcast Receiver (com.xunmeng.pinduoduo.push.vivo.VivoPushReceiver) 未被保护。

[android:exported=true]
发现 Broadcast Receiver与设备上的其他应用程序共享,因此使其对设备上的任何其他应用程序都可访问。

中危 Activity设置了TaskAffinity属性

(com.jarvan.fluwx.wxapi.FluwxWXEntryActivity)
如果设置了 taskAffinity,其他应用程序可能会读取发送到属于另一个任务的 Activity 的 Intent。为了防止其他应用程序读取发送或接收的 Intent 中的敏感信息,请始终使用默认设置,将 affinity 保持为包名

中危 Activity设置了TaskAffinity属性

(com.xunmeng.tms.wxapi.WXEntryActivity)
如果设置了 taskAffinity,其他应用程序可能会读取发送到属于另一个任务的 Activity 的 Intent。为了防止其他应用程序读取发送或接收的 Intent 中的敏感信息,请始终使用默认设置,将 affinity 保持为包名

中危 Activity-Alias (com.xunmeng.tms.wxapi.WXEntryActivity) 未被保护。

[android:exported=true]
发现 Activity-Alias与设备上的其他应用程序共享,因此使其对设备上的任何其他应用程序都可访问。

中危 Service (com.xiaomi.mipush.sdk.PushMessageHandler) 受权限保护, 但是应该检查权限的保护级别。

Permission: com.xiaomi.xmsf.permission.MIPUSH_RECEIVE [android:exported=true]
发现一个 Service被共享给了设备上的其他应用程序,因此让它可以被设备上的任何其他应用程序访问。它受到一个在分析的应用程序中没有定义的权限的保护。因此,应该在定义它的地方检查权限的保护级别。如果它被设置为普通或危险,一个恶意应用程序可以请求并获得这个权限,并与该组件交互。如果它被设置为签名,只有使用相同证书签名的应用程序才能获得这个权限。

中危 Activity (com.xiaomi.mipush.sdk.NotificationClickedActivity) 未被保护。

[android:exported=true]
发现 Activity与设备上的其他应用程序共享,因此使其对设备上的任何其他应用程序都可访问。

中危 应用程序使用SQLite数据库并执行原始SQL查询。原始SQL查询中不受信任的用户输入可能会导致SQL注入。敏感信息也应加密并写入数据库

应用程序使用SQLite数据库并执行原始SQL查询。原始SQL查询中不受信任的用户输入可能会导致SQL注入。敏感信息也应加密并写入数据库
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x04h-Testing-Code-Quality.md#injection-flaws-mstg-arch-2-and-mstg-platform-2

Files:
am_okdownload/f/j/c.java, line(s) 8,9,66
com/tencent/wcdb/database/SQLiteDatabase.java, line(s) 4,479
com/tencent/wcdb/room/db/WCDBDatabase.java, line(s) 5,212
com/xunmeng/mbasic/report/h/f/a.java, line(s) 7,8,9,182
com/xunmeng/mbasic/report/h/f/b.java, line(s) 5,6,16
h/h/a/c.java, line(s) 7,600
h/k/b/b/s/b.java, line(s) 4,5,23

中危 MD5是已知存在哈希冲突的弱哈希

MD5是已知存在哈希冲突的弱哈希
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x04g-Testing-Cryptography.md#identifying-insecure-andor-deprecated-cryptographic-algorithms-mstg-crypto-4

Files:
am_okdownload/f/c.java, line(s) 246
com/bumptech/glide/util/Util.java, line(s) 316
com/xunmeng/pinduoduo/apm/common/utils/b.java, line(s) 262
com/xunmeng/pinduoduo/apm/common/utils/d.java, line(s) 180
com/xunmeng/pinduoduo/arch/config/internal/h.java, line(s) 36,52
com/xunmeng/pinduoduo/arch/vita/utils/VitaUtils.java, line(s) 170
com/xunmeng/pinduoduo/basekit/commonutil/b.java, line(s) 31
com/xunmeng/pinduoduo/common_upgrade/i/b.java, line(s) 17
com/xunmeng/pinduoduo/g/a/d/j.java, line(s) 38
com/xunmeng/pinduoduo/k/e/e.java, line(s) 38
com/xunmeng/pinduoduo/k/j/e/e.java, line(s) 9
com/xunmeng/pinduoduo/pddmap/MapYamlLoader.java, line(s) 267
com/xunmeng/pinduoduo/s/a/b/b.java, line(s) 26,39
com/xunmeng/pinduoduo/secure/e.java, line(s) 1075
com/xunmeng/pinduoduo/secure/i/f.java, line(s) 29
com/xunmeng/tms/map/l/c.java, line(s) 49
h/k/b/b/m.java, line(s) 239
org/jcodec/common/tools/MD5.java, line(s) 22
xmg/mobilebase/kenit/loader/shareutil/SharePatchFileUtil.java, line(s) 292,546

中危 应用程序使用不安全的随机数生成器

应用程序使用不安全的随机数生成器
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x04g-Testing-Cryptography.md#weak-random-number-generators

Files:
com/ryanheise/just_audio/AudioPlayer.java, line(s) 61
com/xunmeng/ddmc/apm_impl/ApmApiImpl.java, line(s) 28
com/xunmeng/pinduoduo/apm/crash/core/a.java, line(s) 28
com/xunmeng/pinduoduo/app_lego/v8/preload/y0.java, line(s) 10
com/xunmeng/pinduoduo/arch/config/internal/g.java, line(s) 24
com/xunmeng/pinduoduo/arch/config/internal/l/c.java, line(s) 14
com/xunmeng/pinduoduo/arch/config/u/g.java, line(s) 43
com/xunmeng/pinduoduo/arch/vita/VitaManagerImpl.java, line(s) 73
com/xunmeng/pinduoduo/g/a/d/c.java, line(s) 15
com/xunmeng/pinduoduo/lego/v8/list/f.java, line(s) 7
com/xunmeng/pinduoduo/lego/v8/utils/f.java, line(s) 13
com/xunmeng/pinduoduo/o/b.java, line(s) 41
com/xunmeng/pinduoduo/o/d/a.java, line(s) 13
com/xunmeng/tms/appinfo_stat/b.java, line(s) 7
com/xunmeng/tms/base/util/y.java, line(s) 17
com/xunmeng/tms/location/report/LocationReportService.java, line(s) 21
com/xunmeng/tms/scan/sdk/uploadscan/c.java, line(s) 5
com/xunmeng/tms/z/a/a.java, line(s) 7
xmg/mobilebase/kenit/loader/shareutil/ShareLoadReport.java, line(s) 19

中危 文件可能包含硬编码的敏感信息,如用户名、密码、密钥等

文件可能包含硬编码的敏感信息,如用户名、密码、密钥等
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x05d-Testing-Data-Storage.md#checking-memory-for-sensitive-data-mstg-storage-10

Files:
com/bumptech/glide/disklrucache/relation/WebImageRequestInfo.java, line(s) 19
com/huawei/remoteLoader/client/ARTargetLibraryInfo.java, line(s) 7
com/xunmeng/basiccomponent/titan/AbstractTitanInterface.java, line(s) 7
com/xunmeng/basiccomponent/titan/RequestChannelSelector.java, line(s) 13
com/xunmeng/basiccomponent/titan/Titan.java, line(s) 73,74,84,85
com/xunmeng/basiccomponent/titan/api/TitanApiRequest.java, line(s) 126
com/xunmeng/basiccomponent/titan/api/helper/ApiNetChannelSelector.java, line(s) 17,18
com/xunmeng/basiccomponent/titan/profiler/LongLinkBackGroundStatusMonitor.java, line(s) 18
com/xunmeng/basiccomponent/titan/service/NetLogRecordConfig.java, line(s) 9
com/xunmeng/mbasic/storage/kvstore/e.java, line(s) 51,57,78,119,125,131,137,19,84,89,94,99,104,109
com/xunmeng/pinduoduo/arch/config/internal/ab/a.java, line(s) 27
com/xunmeng/pinduoduo/arch/config/internal/abexp/AbExpTrackConfigModel.java, line(s) 206
com/xunmeng/pinduoduo/arch/config/internal/abexp/e.java, line(s) 70
com/xunmeng/pinduoduo/arch/vita/inner/AutoDownloadCompHelper.java, line(s) 48
com/xunmeng/pinduoduo/arch/vita/utils/SafeUtils.java, line(s) 15
com/xunmeng/pinduoduo/basekit/http/dns/DnsConfigInfo.java, line(s) 218
com/xunmeng/pinduoduo/bridge/Constants$ExpAbItem.java, line(s) 37
com/xunmeng/pinduoduo/common_upgrade/f/b.java, line(s) 64,90
com/xunmeng/pinduoduo/common_upgrade/upgrade/bean/PatchExpInfo.java, line(s) 19
com/xunmeng/pinduoduo/g/a/a/b.java, line(s) 395
com/xunmeng/pinduoduo/k/j/e/b.java, line(s) 29
com/xunmeng/pinduoduo/o/b.java, line(s) 218
com/xunmeng/tms/utils/p.java, line(s) 59
io/flutter/app/FlutterActivityDelegate.java, line(s) 33
io/flutter/embedding/android/FlutterActivityAndFragmentDelegate.java, line(s) 31,32
io/flutter/embedding/android/FlutterActivityLaunchConfigs.java, line(s) 16,18,19,3,4,17
io/flutter/embedding/engine/loader/ApplicationInfoLoader.java, line(s) 14,13
io/flutter/embedding/engine/loader/FlutterLoader.java, line(s) 33,38,36,37,39,41,42,40,43,46
io/flutter/embedding/engine/systemchannels/SettingsChannel.java, line(s) 12
io/flutter/plugin/editing/SpellCheckPlugin.java, line(s) 18,20,21
meco/util/SoftInputHelper.java, line(s) 22
org/jcodec/containers/mxf/model/KLV.java, line(s) 55
top/kikt/imagescanner/core/entity/e.java, line(s) 48

中危 IP地址泄露

IP地址泄露


Files:
com/huawei/hiar/BuildConfig.java, line(s) 8
com/huawei/hmf/tasks/BuildConfig.java, line(s) 7
com/xunmeng/basiccomponent/titan/jni/DataStructure/StGslbConfig.java, line(s) 50,92,120,50,92,120,50,92,120,50,92,120
com/xunmeng/basiccomponent/titan/util/IpStackHelper.java, line(s) 82
com/xunmeng/mbasic/network/p/d.java, line(s) 280
com/xunmeng/pinduoduo/basekit/http/dns/DnsConfigInfo.java, line(s) 81,80
com/xunmeng/pinduoduo/basekit/http/dns/HttpDns.java, line(s) 37,50,63,38,51,64,39,52,65,40,53,66,41,54,67,42,55,68,43,56,69,44,57,70
com/xunmeng/pinduoduo/push/hms/HuaweiHmsPushChannel.java, line(s) 195
com/xunmeng/tms/app/provider/j.java, line(s) 73,73,73,71,68,73
com/xunmeng/tms/helper/g/d.java, line(s) 5
com/xunmeng/tms/helper/g/f.java, line(s) 4,3,6,5
l/b/d/c.java, line(s) 47
m/a/c/d/b/a.java, line(s) 222
meco/util/MecoComponentUtil.java, line(s) 16
org/jcodec/containers/mxf/MXFCodec.java, line(s) 48,56,40,46,51,52,43,55,39,58,41,42,38,61,44,54,50,59,45,64,65,66,60
org/jcodec/containers/mxf/MXFConst.java, line(s) 86,35,55,85,50,56,71,72,67,68,54,59,51,66,65,61,73,70,69,75,76,77,78,79,80,81,82,83,84,74,34,60,33
xmg/mobilebase/kenit/loader/BuildConfig.java, line(s) 6
xmg/mobilebase/kenit/loader/shareutil/ShareConstants.java, line(s) 142
xmg/mobilebase/kenit/loader/shareutil/ShareKenitInternals.java, line(s) 442,443,743

中危 应用程序可以读取/写入外部存储器,任何应用程序都可以读取写入外部存储器的数据

应用程序可以读取/写入外部存储器,任何应用程序都可以读取写入外部存储器的数据
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x05d-Testing-Data-Storage.md#external-storage

Files:
com/mr/flutter/plugin/filepicker/b.java, line(s) 227
com/mr/flutter/plugin/filepicker/c.java, line(s) 96
com/xunmeng/pinduoduo/secure/i/b.java, line(s) 171,172
com/xunmeng/tms/base/util/q.java, line(s) 370,547,549
com/xunmeng/tms/k/d/c.java, line(s) 5
h/a/b/e.java, line(s) 58
h/d/a/a/b.java, line(s) 30,33
h/i/a/a.java, line(s) 181
io/flutter/plugins/pathprovider/PathProviderPlugin.java, line(s) 91,100
top/kikt/imagescanner/core/utils/DBUtils.java, line(s) 690,986

中危 SHA-1是已知存在哈希冲突的弱哈希

SHA-1是已知存在哈希冲突的弱哈希
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x04g-Testing-Cryptography.md#identifying-insecure-andor-deprecated-cryptographic-algorithms-mstg-crypto-4

Files:
com/xunmeng/pinduoduo/q/f/b.java, line(s) 57
com/xunmeng/pinduoduo/q/g/c.java, line(s) 73
i/a/a/a/a.java, line(s) 126
xmg/mobilebase/kenit/android/dex/i.java, line(s) 384

中危 不安全的Web视图实现。可能存在WebView任意代码执行漏洞

不安全的Web视图实现。可能存在WebView任意代码执行漏洞
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x05h-Testing-Platform-Interaction.md#testing-javascript-execution-in-webviews-mstg-platform-5

Files:
io/flutter/plugins/webviewflutter/FlutterWebView.java, line(s) 266,305

中危 应用程序创建临时文件。敏感信息永远不应该被写进临时文件

应用程序创建临时文件。敏感信息永远不应该被写进临时文件


Files:
com/jarvan/fluwx/io/ImagesIOIml.java, line(s) 98
com/xunmeng/pinduoduo/t/e/d.java, line(s) 534
org/jcodec/testing/TestTool.java, line(s) 29,30,31

中危 应用程序包含隐私跟踪程序

此应用程序有多个2隐私跟踪程序。跟踪器可以跟踪设备或用户,是终端用户的隐私问题。

中危 此应用可能包含硬编码机密信息

从应用程序中识别出以下机密确保这些不是机密或私人信息
"debug_view_network_api" : "查看网络请求抓包"
"debug_api_detail" : "API详情页"
"debug_no_match_api" : "没有搜索到api"
"debug_check_api_request" : "API请求查看"
15f0ba00a3ac7af3ac884c072b1011a077bd77c097f40164b2f8598abd83860c
41C923866AB4CAD6B7AD578081582E020797A6CBDF4FFF78CE8396B38937D7F5
nmDYVF3FN8VKfyoAKS1vRQlXKslPf45oQSOgIWbC/jsQz+tp4etnJ98VUtKNm4Vsq
1465fa205397b876faa6f0a9958e5590e40fcc7faa4fb7c2c8677521fb5fb658
e7ffcde74b3ee6c00714cc1f75bfd3b6
8ad2eb58-fb06-4036-956a-da63b55fceae
bfff8fd04433487d6a8aa60c1a29767a9fc2bbb05e420f713a13b992891d3893
Y29tLmdyZWVucG9pbnQuYW5kcm9pZC5tYzEwMDg2LmFjdGl2aXR5
E3268F6106BA8B665A1A962DDEA1459D2A46972F1F2440329B390B895749AD45
56C77128D98C18D91B4CFDFFBC25EE9103D4758EA2ABAD826A90F3457D460EB4
7431e5f4c3c1ce4690774f0b61e05440883ba9a01ed00ba6abd7806ed3b118cf
152A402BFCDF2CD548054D2275B39C7FCA3EC0978078B0F0EA76E561A6C7433E
FABCF5197CDD7F458AC33832D3284021DB2425FD6BEA7A2E69B7486E8F51F9CC
f71d2229cd0a0732bc1fcfeb40d9d83dbb0f77f35bdee99969d67ee9b8ad148e6b63533ab1bd0933dbb3d3844abc4b33ed071a56529284b34f9c31eb1e341b3a
37D51006C512EAAB626421F1EC8C92013FC5F82AE98EE533EB4619B8DEB4D06C
b676f2eddae8775cd36cb0f63cd1d4603961f49e6265ba013a2f0307b6d0b804
44b545aa8a25e65a73ca15dc27fc36d24c1cb9953a066539b11582dc487b4833
4B03F45807AD70F21BFC2CAE71C9FDE4604C064CF5FFB686BAE5DBAAD7FDD34C
16a09e667f3bcc908b2fb1366ea957d3e3adec17512775099da2f590b0667322a
43df5774b03e7fef5fe40d931a7bedf1bb2e6b42738c4e6d3841103d3aa7f339
5d56499be4d2e08bcfcad08a3e38723d50503bde706948e42f55603019e528ae
4ff460d54b9c86dabfbcfc5712e0400d2bed3fbc4d4fbdaa86e06adcd2a9ad7a
70B922BFDA0E3F4A342E4EE22D579AE598D071CC5EC9C30F123680340388AEA5
4348a0e9444c78cb265e058d5e8944b4d84f9662bd26db257f8934a443c70161
62dd0be9b9f50a163ea0f8e75c053b1eca57ea55c8688f647c6881f2c8357b95
507941C74460A0B47086220D4E9932572AB5D1B5BBCB8980AB1CB17651A844D2
F09B122C7114F4A09BD4EA4F4A99D558B46E4C25CD81140D29C05613914C3841
3c4fb0b95ab8b30032f432b86f535fe172c185d0fd39865837cf36187fa6f428
2a575471e31340bc21581cbd2cf13e158463203ece94bcf9d3cc196bf09a5472
063e4afac491dfd332f3089b8542e94617d893d7fe944e10a7937ee29d9693c0
AE4457B40D9EDA96677B0D3C92D57B5177ABD7AC1037958356D1E094518BE5F2
8560f91c3624daba9570b5fea0dbe36ff11a8323be9486854fb3f34a5571198d
B0B1730ECBC7FF4505142C49F1295E6EDA6BCAED7E2C68C5BE91B5A11001F024
69DDD7EA90BB57C93E135DC85EA6FCD5480B603239BDC454FC758B2A26CF7F79
e793c9b02fd8aa13e21c31228accb08119643b749c898964b1746d46c3d4cbd2
7e37cb8b4c47090cab36551ba6f45db840680fba166a952db100717f43053fc2
5edb7ac43b82a06a8761e8d7be4979ebf2611f7dd79bf91c1c6b566a219ed766
cecddc905099d8dadfc5b1d209b737cbe2c18cfb2c10c0ff0bcf0d3286fc1aa2
18f1fc7f205df8adddeb7fe007dd57e3af375a9c4d8d73546bf4f1fed1e18d35
d40e9c86cd8fe468c1776959f49ea774fa548684b6c406f3909261f4dce2575c
31ad6648f8104138c738f39ea4320133393e3a18cc02296ef97c2ac9ef6731d0
0C258A12A5674AEF25F28BA7DCFAECEEA348E541E6F5CC4EE63B71B361606AC3
Y29tLnNzLmFuZHJvaWQuYXJ0aWNsZS52aWRlbw==
CBB9C44D84B8043E1050EA31A69F514955D7BFD2E2C6B49301019AD61D9F5058
F008733EC500DC498763CC9264C6FCEA40EC22000E927D053CE9C90BFA046CB2
23804203CA45D8CDE716B8C13BF3B448457FA06CC10250997FA01458317C41E5
6CC05041E6445E74696C4CFBC9F80F543B7EABBB44B4CE6F787C6A9971C42F17
e23d4a036d7b70e9f595b1422079d2b91edfbb1fb651a0633eaa8a9dc5f80703
2e7bf16cc22485a7bbe2aa8696750761b0ae39be3b2fe9d0cc6d4ef73491425c
n9gYOvk2nZYrb8Aa6l9ORhE2qSQ0qn2t3FUtGS7AbL0THfOY+7EoV1R4KCKz+Cfi1
319AF0A7729E6F89269C131EA6A3A16FCD86389FDCAB3C47A4A675C161A3F974
B7C36231706E81078C367CB896198F1E3208DD926949DD8F5709A410F75B6292
06c1b874-8556-449e-8262-1d2b26d84eb9
047D00CE52551DCEDC5F847B0665E022
9D190B2E314566685BE8A889E27AA8C7D7AE1D8AADDBA3C1ECF9D24863CD34B9
A1A86D04121EB87F027C66F53303C28E5739F943FC84B38AD6AF009035DD9457
16af57a9f676b0ab126095aa5ebadef22ab31119d644ac95cd4b93dbf3f26aeb
92D8092EE77BC9208F0897DC05271894E63EF27933AE537FB983EEF0EAE3EEC8
2245023265AE4CF87D02C8B6BA991139
5c58468d55f58e497e743982d2b50010b6d165374acf83a7d4a32db768c4408e
9ACFAB7E43C8D880D06B262A94DEEEE4B4659989C3D0CAF19BAF6405E41AB7DF
caf2d46106404bf09bb47c8ca2d301a1
18ce6cfe7bf14e60b2e347b8dfe868cb31d02ebb3ada271569f50343b46db3a4
f611297f5472b4433df52891dc5d6705
59769007f7685d0fcd50872f9f95d5755a5b2b457d81f3692b610a98672f0e1b
bfd88fe1101c41ae3e801bf8be56350ee9bad1a6b9bd515edc5c6d5b8711ac44
b0bfd52bb0d7d9bd92bf5d4dc13da255c02c542f378365ea893911f55e55f23c
bec94911c2955676db6c0a550986d76e3ba005667c442c9762b4fbb773de228c
88ef81de202eb018452e43f864725cea5fbd1fc2d9d205730709c5d8b8690f46
C2B9B042DD57830E7D117DAC55AC8AE19407D38E41D88F3215BC3A890444A050
6c61dac3a2def031506be036d2a6fe401994fbd13df9c8d466599274c446ec98
0753e940378c1bd5e3836e395daea5cb839e5046f1bd0eae1951cf10fec7c965
Y29tLnNvaHUuaW5wdXRtZXRob2Quc29nb3U=
2a60276ca9d059a29d4494f8dc6cac6e
85666a562ee0be5ce925c1d8890a6f76a87ec16d4d7d5f29ea7419cf20123b69
13e6deb3-efec-4e83-8904-376b1c12ae90
0ED3FFAB6C149C8B4E71058E8668D429ABFDA681C2FFF508207641F0D751A3E5
8327BC8C9D69947B3DE3C27511537267F59C21B9FA7B613FAFBCCD53B7024000
3e9099b5015e8f486c00bcea9d111ee721faba355a89bcf1df69561e3dc6325c
15d5b8774619ea7d54ce1ca6d0b0c403e037a917f131e8a04e1e6b7a71babce5
aa06b79a-32e2-4b31-81bc-00262e20a3aa
EF3CB417FC8EBF6F97876C9E4ECE39DE1EA5FE649141D1028B7D11C0B2298CED
8a866fd1b276b57e578e921c65828a2bed58e9f2f288054134b7f1f4bfc9cc74
eec5496b988ce98625b934092eec2908bed0b0f316c2d4730c84eaf1f3d34881
7d05ebb682339f8c9451ee094eebfefa7953a114edb2f44949452fab7d2fc185
2605875AFCC176B2D66DD66A995D7F8D5EBB86CE120D0E7E9E7C6EF294A27D4C
73c176434f1bc6d5adf45b0e76e727287c8de57616c1e6e6141a2b2cbc7d8e4c
c45d7bb08e6d67e62e4235110b564e5f78fd92ef058c840aea4e6455d7585c60
e35d28419ed02025cfa69038cd623962458da5c695fbdea3c22b0bfb25897092
ebc5570c29018c4d67b1aa127baf12f703b4611ebc17b7dab5573894179b93fa
b5f01ac3f08a3391d477989606b7649f7fb6b1d6
A22DBA681E97376E2D397D728AAE3A9B6296B9FDBA60BC2E11F647F2C675FB37
4200f5043ac8590ebb527d209ed1503029fbcbd41ca1b506ec27f15ade7dac69
Y29tLmhhcHB5ZWxlbWVudHMuQW5kcm9pZEFuaW1hbA==
8ecde6884f3d87b1125ba31ac3fcb13d7016de7f57cc904fe1cb97c6ae98196e
5a885db19c01d912c5759388938cafbbdf031ab2d48e91ee15589b42971d039c
Y29tLmh1bmFudHYuaW1nby5hY3Rpdml0eQ==
568d6905a2c88708a4b3025190edcfedb1974a606a13c6e5290fcb2ae63edab5
c1b48299aba5208fe9630ace55ca68a03eda5a519c8802a0d3a673be8f8e557d
nxet6jhZrYKOTnN7FAQudsUv8TPOL6tViJ5ZFPJpsD/8QBcTCIFk1EhNAII9jjIpl
c3846bf24b9e93ca64274c0ec67c1ecc5e024ffcacd2d74019350e81fe546ae4
02ed0eb28c14da45165c566791700d6451d7fb56f0b2ab1d3b8eb070e56edff5
1ba5b2aa8c65401a82960118f80bec4f62304d83cec4713a19c39c011ea46db4
0376ab1d54c5f9803ce4b2e201a0ee7eef7b57b636e8a93c9b8d4860c96f5fa7
6FDB3F76C8B801A75338D8A50A7C02879F6198B57E594D318D3832900FEDCD79
513b2cecb810d4cde5dd85391adfc6c2dd60d87bb736d2b521484aa47a0ebef6
C7BA6567DE93A798AE1FAA791E712D378FAE1F93C4397FEA441BB7CBE6FD5995
8D722F81A9C113C0791DF136A2966DB26C950A971DB46B4199F4EA54B78BFB9F
70a73f7f376b60074248904534b11482d5bf0e698ecc498df52577ebf2e93b9a
fbd0c7ee-3317-4833-b569-8712f982a190
04048028bf1f2864d48f9ad4d83294366a828856553f3b14303f90147f5d40ef
e75e72ed9f560eec6eb4800073a43fc3ad19195a392282017895974a99026b6c
2399561127a57125de8cefea610ddf2fa078b5c8067f4e828290bfb860e84b3c
c0a6f4dc63a24bfdcf54ef2a6a082a0a72de35803e2ff5ff527ae5d87206dfd5
2ce1cb0bf9d2f9e102993fbe215152c3b2dd0cabde1c68e5319b839154dbb7f5
Y29tLnNzLmFuZHJvaWQuYXJ0aWNsZS5saXRl
0c2cd63df7806fa399ede809116b575bf87989f06518f9808c860503178baf66
bc104f15a48be709dca542a7e1d4b9df6f054527e802eaa92d595444258afe71
f1c1b50ae5a20dd8030ec9f6bc24823dd367b5255759b4e71b61fce9f7375d73
2530cc8e98321502bad96f9b1fba1b099e2d299e0f4548bb914f363bc0d4531f
D8E0FEBC1DB2E38D00940F37D27D41344D993E734B99D5656D9778D4D8143624
C766A9BEF2D4071C863A31AA4920E813B2D198608CB7B7CFE21143B836DF09EA
D95FEA3CA4EEDCE74CD76E75FC6D1FF62C441F0FA8BC77F034B19E5DB258015D
be6c4da2bbb9ba59b6f3939768374246c3c005993fa98f020d1dedbed48a81d5
eaa962c4fa4a6bafebe415196d351ccd888d4f53f3fa8ae6d7c466a94e6042bb
fd73dad31c644ff1b43bef0ccdda96710b9cd9875eca7e31707af3e96d522bbd
4FA3126D8D3A11D1C4855A4F807CBAD6CF919D3A5A88B03BEA2C6372D93C40C9
79e427d3e63c40adb1ed4380675845e0
Y29tLmFsaWJhYmEuYW5kcm9pZC5yaW1ldA==
3c5f81fea5fab82c64bfa2eaecafcde8e077fc8620a7cae537163df36edbf378
B0AB0254BD58EB87EAEE3172BA49FEFB
dd6936fe21f8f077c123a1a521c12224f72255b73e03a7260693e8a24b0fa389
cb3ccbb76031e5e0138f8dd39a23f9de47ffc35e43c1144cea27d46a5ab1cb5f
7F671B7BCFC947F3A8D3DDA5BAA60712
21DB20123660BB2ED418205DA11EE7A85A65E2BC6E55B5AF7E7899C8A266D92E
55926084ec963a64b96e2abe01ce0ba86a64fbfebcc7aab5afc155b37fd76066
FCBFE2886206F72B27593C8B070297E12D769ED10ED7930705A8098EFFC14D17
edf7ebbca27a2a384d387b7d4010c666e2edb4843e4c29b4ae1d5b9332e6b24d
6dc47172e01cbcb0bf62580d895fe2b8ac9ad4f873801e0c10b9c837d21eb177
35487fb4bd08cdf78302b2059dd5c287
D97761EAA60E040D2C542B03958DAB46
4d2491414cfe956746ec4cefa6cf6f72e28a1329432f9d8a907ac4cb5dadc15a
6b9c08e86eb0f767cfad65cd98b62149e5494a67f5845e7bd1ed019f27b86bd6
308203c7308202afa003020102021500dc286b43b4ea12039958a00a6655eb84720e46c9300d06092a864886f70d01010b05003074310b3009060355040613025553311330110603550408130a43616c69666f726e6961311630140603550407130d4d6f756e7461696e205669657731143012060355040a130b476f6f676c6520496e632e3110300e060355040b1307416e64726f69643110300e06035504031307416e64726f6964301e170d3137303830343136353333375a170d3437303830343136353333375a3074310b3009060355040613025553311330110603550408130a43616c69666f726e6961311630140603550407130d4d6f756e7461696e205669657731143012060355040a130b476f6f676c6520496e632e3110300e060355040b1307416e64726f69643110300e06035504031307416e64726f696430820122300d06092a864886f70d01010105000382010f003082010a02820101008998646f47fc333db09644c303104ed183e904e351152aa66a603b77f63389d45d6fcffae3c94fadf1f28038e265d697fea347327f9081a7f0b9074d5b148db5bf357c611a77f87f844a15068818bdcd5b21d187e93fa2551676170eedce04a150c35ec0a791eef507fa9b406573c36f6f207764842e5677e35a281a422659e91e26eb4fecfb053b5c936d0976c37f8757adb57a37953da5844ea350695854d343a61ad341b63a1c425d22855af7ebfee018e1736cee98536be5b9947f288e2a26f99eb9f91b5de93fecc513019d2e90f12b38610d1f02eaa81deca4ce91c19cbce36d6c3025ce2432b3d178616beafaf437c08451bc469c6bc6f4517a714a5b0203010001a350304e300c0603551d13040530030101ff301d0603551d0e0416041419a864c0f2618c67c803a23da909bc70521f269b301f0603551d2304183016801419a864c0f2618c67c803a23da909bc70521f269b300d06092a864886f70d01010b050003820101005403fc56fdefc440376a0337815002b96a15bffc2fe42de6c58f52fae4d80652e3704455b885409eef81ffbb4c44dba104b6b8e24c9e2e0e7a04338ee73baa5b71bfb4488f8e04bef3d0eaf7d43aa42b03b278c33cc1f0dd3802571624baa161d851fab37db4bc92b9094b6885dff62b400ecd81f069d56a1be1db46d8198c50c9628cdb6e38686ef640fd386775f50376f957e24ea45ed1942968f20c82f189607fdb22f11cfdfd0760a77a60ceb3416cfb3f48f13f9f83f3834a01001750a7c78bc1fd81f0b53a7c41dcba9f5a0118259d083c32bb9ebb84d645d6f6b9c31923d8ab70e7f0a25940ecc9f4945144419f86e8c421d3b99774f4b8f3d09262e7
B478B812250DF878635C2AA7EC7D155EAA625EE82916E2CD294361886CD1FBD4
1793927a0614549789adce2f8f34f7f0b66d0f3ae3a3b84d21ec15dbba4fadc7
d40264e6-6873-470e-ac32-4071848d3de0
187EF4436122D1CC2F40DC2B92F0EBA0
52f0e1c4e58ec629291b60317f074671b85d7ea80d5b07273463534b32b40234
85a0dd7dd720adb7ff05f83d542b209dc7ff4528f7d677b18389fea5e5c49e86
Y29tLnRlbmNlbnQuYW5kcm9pZC5xcWRvd25sb2FkZXI=
CBB5AF185E942A2402F9EACBC0ED5BB876EEA3C1223623D00447E4F3BA554B65
5cc3d78e4e1d5e45547a04e6873e64f90cf9536d1ccc2ef800f355c4c5fd70fd
0a81ec5a929777f145904af38d5d509f66b5e2c58fcdb531058b0e17f3f0b41b
552f7bdcf1a7af9e6ce672017f4f12abf77240c78e761ac203d1d9d20ac89988
f9e67d336c51002ac054c632022d66dda2e7e3fff10ad061ed31d8bbb410cfb2
45140b3247eb9cc8c5b4f0d7b53091f73292089e6e5a63e2749dd3aca9198eda
F96F23F4C3E79C077A46988D5AF5900676A0F039CB645DD17549B216C82440CE
22a2c1f7bded704cc1e701b5f408c310880fe956b5de2a4a44f99c873a25a7c8
824C6AA7A0C65328B9844CE714B96B8E
96bcec06264976f37460779acf28c5a7cfe8a3c0aae11a8ffcee05c0bddf08c6
d7a7a0fb5d7e2731d771e9484ebcdef71d5f0c3e0a2948782bc83ee0ea699ef4
27d848e5-22ad-459e-98cd-259d068d50d1
71cca5391f9e794b04802530b363e121da8a3043bb26662fea4dca7fc951a4bd
5a2fc03f0c83b090bbfa40604b0988446c7636183df9846e17101a447fb8efd6
3417bb06cc6007da1b961c920b8ab4ce3fad820e4aa30b9acbc4a74ebdcebc65
bd71fdf6da97e4cf62d1647add2581b07d79adf8397eb4ecba9c5e8488821423
Y29tLnNzLmFuZHJvaWQudWdjLmF3ZW1lLmxpdGU=
8fe4fb0af93a4d0d67db0bebb23e37c71bf325dcbcdd240ea04daf58b47e1840
MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzH8q0+dtUWGu9l13gywI
ebd41040e4bb3ec742c9e381d31ef2a41a48b6685c96e7cef3c1df6cd4331c99
Y29tLmFuanVrZS5hbmRyb2lkLmFwcA==
91e2f5788d5810eba7ba58737de1548a8ecacd014598bc0b143e041b17052552
179fbc148a3dd00fd24ea13458cc43bfa7f59c8182d783a513f6ebec100c8924
f356bea244b7a91eb35d53ca9ad7864ace018e2d35d5f8f96ddf68a6f41aa474
C57A3ACBE8C06BA1988A83485BF326F2448775379849DE01CA43571AF357E74B
0D83B611B648A1A75EB8558400795375CAD92E264ED8E9D7A757C1F5EE2BB22D
a48a29f53aca41e3bceb108252bdfeb6
cbb522d7b7f127ad6a0113865bdf1cd4102e7d0759af635a7cf4720dc963c53b
63343ABFB89A6A03EBB57E9B3F5FA7BE7C4F5C756F3017B3A8C488C3653E9179
ca42dd41745fd0b81eb902362cf9d8bf719da1bd1b1efc946f5b4c99f42c1b9e
6639D13CAB85DF1AD9A23C443B3A60901E2B138D456FA71183578108884EC6BF
Y29tLmVnLmFuZHJvaWQuQWxpcGF5R3Bob25l
136335439334a7698016a0d324de72284e079d7b5220bb8fbd747816eebebaca
302D7B1D081AD80D5C79B0A470F02EC8
92A9D9833FE1944DB366E8BFAE7A95B6480C2D6C6C2A1BE65D4236B608FCA1BB
a040929a02ce53b4acf4f2ffc6981ce4496f755e6d45fe0b2a692bcd52523f36
46edc3689046d53a453fb3104ab80dcaec658b2660ea1629dd7e867990648716
F2A7A9465BD586E2C20FE329B4C06B4E
9a114025197c5bb95d94e63d55cd43790847b646b23cdf11ada4a00eff15fb48
27995829FE6A7515C1BFE848F9C4761DB16C225929257BF40D0894F29EA8BAF2
a9c9478351684c388b62d750ed67ec73
30d0895a9a448a262091635522d1f52010b5867acae12c78ef958fd4f4389f2f
17f1d6df84885437a313558b4b20e39f
785264333748DC23BDD5874BBE44306F
2cabeafe37d06ca22aba7391c0033d25982952c453647349763a3ab5ad6ccf69
3B222E566711E992300DC0B15AB9473DAFDEF8C84D0CEF7D3317B4C1821D1436
EB04CF5EB1F39AFA762F2BB120F296CBA520C1B97DB1589565B81CB9A17B7244
49e7a442acf0ea6287050054b52564b650e4f49e42e348d6aa38e039e957b1c1
2A99F5BC1174B73CBB1D620884E01C34E51CCB3978DA125F0E33268883BF4158
CB627D18B58AD56DDE331A30456BC65C601A4E9B18DEDCEA08E7DAAA07815FF0
e3b6a2db2ed7ce48842f7ac53241c7b71d54144bfb40c11f3f1d0b42f5eea12d
5CBF6FB81FD417EA4128CD6F8172A3C9402094F74AB2ED3A06B4405D04F30B19
E17890EE09A3FBF4F48B9C414A17D637B7A50647E9BC752322727FCC1742A911
353FEA5DEB6FEC2344FC91D32FAD995E

信息 应用程序记录日志信息,不得记录敏感信息

应用程序记录日志信息,不得记录敏感信息
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x05d-Testing-Data-Storage.md#logs

Files:
am_okdownload/f/c.java, line(s) 138,147,198,69
am_okdownload/f/g/e.java, line(s) 120
com/alibaba/android/vlayout/ExposeLinearLayoutManagerEx.java, line(s) 573,576,578,781,928,929,930,931,932
com/alibaba/android/vlayout/VirtualLayoutManager.java, line(s) 926,608,1002
com/alibaba/android/vlayout/k/a.java, line(s) 42
com/alibaba/android/vlayout/k/b.java, line(s) 199,252
com/alibaba/android/vlayout/k/g.java, line(s) 335,564
com/alibaba/android/vlayout/k/k.java, line(s) 437,462,645,668,681,697,707,734,753,780,852
com/alibaba/android/vlayout/k/o.java, line(s) 71
com/baseflow/permissionhandler/j.java, line(s) 18
com/baseflow/permissionhandler/n.java, line(s) 50,72,75,138,196,202,205
com/baseflow/permissionhandler/o.java, line(s) 296,300,305
com/baseflow/permissionhandler/p.java, line(s) 76
com/heytap/mcssdk/i/c.java, line(s) 13,19
com/huawei/hiar/ARConfigBase.java, line(s) 252,370,384,393,422,436,459
com/huawei/hiar/ARFrame.java, line(s) 165,190,224,187
com/huawei/hiar/ARPlane.java, line(s) 118,126
com/huawei/hiar/ARServiceProxy.java, line(s) 97,114,137,145,171,174,181,261,269,274,104,131,147,189,198,216,236,186,226,232,388
com/huawei/hiar/ARSession.java, line(s) 58,187,190,193,196,199,202,335,339,385,391
com/huawei/hiar/ARVideoSource.java, line(s) 43,49,92
com/huawei/hiar/ArCallbackThread.java, line(s) 71,31,57,63,91
com/huawei/hiar/HuaweiArApkImpl.java, line(s) 23
com/huawei/hiar/utils/CheckSignature.java, line(s) 21,24,27,48,66,90
com/huawei/hiar/utils/CommonUtil.java, line(s) 31
com/huawei/hmf/tasks/a/g.java, line(s) 30,40,66
com/huawei/remoteLoader/client/ARDynamiteClient.java, line(s) 123,70,73,81,84,90,98,101,131,167,178,181,205,211,65,76,96,104,152,189,68,79,112
com/huawei/remoteLoader/client/ARRemoteLibraryLoader.java, line(s) 69,35
com/jarvan/fluwx/b/a.java, line(s) 48
com/jarvan/fluwx/handlers/a.java, line(s) 57,120
com/jarvan/fluwx/handlers/d.java, line(s) 75,82,131,171,178
com/jarvan/fluwx/io/ByteArrayToFileKt$saveToLocal$2.java, line(s) 81
com/jarvan/fluwx/io/WeChatNetworkFile$readByteArray$2.java, line(s) 62
com/jarvan/fluwx/wxapi/FluwxWXEntryActivity.java, line(s) 65
com/mr/flutter/plugin/filepicker/b.java, line(s) 80,96,101,120,228,245,264
com/mr/flutter/plugin/filepicker/c.java, line(s) 144,259,43,83,205,207,211,251,254,217,139
com/pauldemarco/flutter_blue/FlutterBluePlugin.java, line(s) 427,437,522
com/ryanheise/just_audio/AudioPlayer.java, line(s) 1109,1111,1113,1115,1119
com/tencent/mars/xlog/PLog.java, line(s) 350,340,345,480,492
com/tencent/mars/xlog/PLogCachedManager.java, line(s) 79,104,75
com/tencent/mars/xlog/PLogDebugCheck.java, line(s) 67,59
com/tencent/mars/xlog/Xlog.java, line(s) 163,166,135,138
com/tencent/wcdb/AbstractCursor.java, line(s) 124
com/tencent/wcdb/BulkCursorToCursorAdaptor.java, line(s) 116,144,33,53,156
com/tencent/wcdb/DatabaseUtils.java, line(s) 132,168,638,719,730
com/tencent/wcdb/DefaultDatabaseErrorHandler.java, line(s) 26,30,65
com/tencent/wcdb/database/SQLiteAsyncQuery.java, line(s) 36,47
com/tencent/wcdb/database/SQLiteConnection.java, line(s) 166,689
com/tencent/wcdb/database/SQLiteConnectionPool.java, line(s) 144,185,326,338,354,174,380,268,696
com/tencent/wcdb/database/SQLiteCursor.java, line(s) 100,154
com/tencent/wcdb/database/SQLiteDatabase.java, line(s) 247,585,652,776,422,425
com/tencent/wcdb/database/SQLiteDebug.java, line(s) 74,130
com/tencent/wcdb/database/SQLiteDirectCursor.java, line(s) 70,133,172
com/tencent/wcdb/database/SQLiteDirectQuery.java, line(s) 81
com/tencent/wcdb/database/SQLiteOpenHelper.java, line(s) 63,111
com/tencent/wcdb/database/SQLiteQuery.java, line(s) 24
com/tencent/wcdb/database/SQLiteQueryBuilder.java, line(s) 223
com/tencent/wcdb/repair/DBDumpUtil.java, line(s) 111,201,282,76,87,287,305,311,38
com/xunmeng/basiccomponent/titan/internal/TitanSoManager.java, line(s) 28,54
com/xunmeng/basiccomponent/titan/jni/TitanLogic.java, line(s) 144,621,1518,1498
com/xunmeng/basiccomponent/titan/service/TitanNative.java, line(s) 70
com/xunmeng/mbasic/XlogApiImpl.java, line(s) 134,138,139,140
com/xunmeng/mbasic/permission/rxpermission/RxPermissionsFragment.java, line(s) 44,54
com/xunmeng/mbasic/remoteconfig/RemoteConfigApiImpl.java, line(s) 334
com/xunmeng/mbasic/upgrade/o.java, line(s) 30
com/xunmeng/mbasic/upgrade/p.java, line(s) 17
com/xunmeng/mbasic/upgrade/q.java, line(s) 37
com/xunmeng/pinduoduo/apm/common/e/f.java, line(s) 25
com/xunmeng/pinduoduo/app_lego/v8/preload/LegoV8LoadManager.java, line(s) 285,44,71,455,471,496,522
com/xunmeng/pinduoduo/app_lego/v8/preload/h1.java, line(s) 113
com/xunmeng/pinduoduo/app_lego/v8/preload/j1.java, line(s) 74,78,82
com/xunmeng/pinduoduo/app_lego/v8/preload/z0.java, line(s) 71
com/xunmeng/pinduoduo/arch/foundation/Foundation.java, line(s) 133,137
com/xunmeng/pinduoduo/arch/foundation/c.java, line(s) 13
com/xunmeng/pinduoduo/arch/vita/fs/lock/ReadWriteLockBySemaphore.java, line(s) 103,123
com/xunmeng/pinduoduo/bridge/c.java, line(s) 55
com/xunmeng/pinduoduo/k/d/a.java, line(s) 347,577
com/xunmeng/pinduoduo/k/d/b.java, line(s) 631
com/xunmeng/pinduoduo/k/e/e.java, line(s) 194,198,91,95,103
com/xunmeng/pinduoduo/k/e/j.java, line(s) 43,39
com/xunmeng/pinduoduo/k/f/e.java, line(s) 6
com/xunmeng/pinduoduo/k/f/g.java, line(s) 31,169,189,46,174,194,209,71,179,199,146,184,204
com/xunmeng/pinduoduo/k/g/b.java, line(s) 42
com/xunmeng/pinduoduo/k/j/a/i0.java, line(s) 318,323,328,334
com/xunmeng/pinduoduo/k/j/a/o.java, line(s) 1890,2041
com/xunmeng/pinduoduo/k/j/a/t.java, line(s) 434,439,444,450
com/xunmeng/pinduoduo/k/j/b/b.java, line(s) 102,107
com/xunmeng/pinduoduo/k/j/b/b0.java, line(s) 52,117,120,204,206,214,219,230,239,255
com/xunmeng/pinduoduo/k/j/b/x.java, line(s) 431,690,854
com/xunmeng/pinduoduo/k/j/b/z.java, line(s) 62
com/xunmeng/pinduoduo/lego/v8/canvas/LegoCanvasView.java, line(s) 50
com/xunmeng/pinduoduo/lego/v8/canvas/a.java, line(s) 432
com/xunmeng/pinduoduo/lego/v8/utils/a.java, line(s) 124,186
com/xunmeng/pinduoduo/lego/v8/view/InternalLegoView.java, line(s) 287,307
com/xunmeng/pinduoduo/lego/v8/view/b.java, line(s) 113
com/xunmeng/pinduoduo/lego/v8/view/i/b.java, line(s) 82,85
com/xunmeng/pinduoduo/m2/core/BaseTValue.java, line(s) 293,663,927,1191
com/xunmeng/pinduoduo/m2/core/e0/g.java, line(s) 348
com/xunmeng/pinduoduo/m2/core/j.java, line(s) 1694,1709
com/xunmeng/pinduoduo/m2/core/o.java, line(s) 19,56
com/xunmeng/pinduoduo/m2/m2function/M2DomFunctions.java, line(s) 195
com/xunmeng/pinduoduo/m2/m2function/M2Error.java, line(s) 48,105,126
com/xunmeng/pinduoduo/m2/m2function/M2Jni.java, line(s) 13,16
com/xunmeng/pinduoduo/m2/m2function/j.java, line(s) 141
com/xunmeng/pinduoduo/m2/m2function/t.java, line(s) 459,473,754,768,790,792,882
com/xunmeng/pinduoduo/oaid/ImplLoader.java, line(s) 78,81
com/xunmeng/pinduoduo/oaid/b/c.java, line(s) 26
com/xunmeng/pinduoduo/oaid/b/e.java, line(s) 8,33,58,83,13,38,63,88,18,43,68,93,23,48,73,98,28,53,78,103
com/xunmeng/pinduoduo/oaid/b/j.java, line(s) 11
com/xunmeng/pinduoduo/oaid/b/k.java, line(s) 20
com/xunmeng/pinduoduo/pddmap/j.java, line(s) 18
com/xunmeng/pinduoduo/push/hms/HuaweiHmsPushChannel.java, line(s) 196
com/xunmeng/pinduoduo/secure/SecureNative.java, line(s) 32
com/xunmeng/pinduoduo/threadpool/HandlerBuilder.java, line(s) 98,103,108
com/xunmeng/pinduoduo/threadpool/p.java, line(s) 226,232,237
com/xunmeng/pinduoduo/volantis/kenithelper/PDDKenitResultService.java, line(s) 54,22,28,37,42,57
com/xunmeng/pinduoduo/volantis/kenithelper/b.java, line(s) 43,56,64,73,38,39,58,61,66,69,71
com/xunmeng/pinduoduo/xlog/XlogUpload.java, line(s) 92
com/xunmeng/pinduoduo/xlog/XlogUploadCommandListener.java, line(s) 32,38,43
com/xunmeng/pinduoduo/xlog/XlogUploadManager.java, line(s) 124,118,191,198,378,387,395,406,429,436,457,467,478,504
com/xunmeng/pinduoduo/xlog/g.java, line(s) 110
com/xunmeng/router/AbsRouter.java, line(s) 222,169,247
com/xunmeng/router/MatcherRegistry.java, line(s) 68
com/xunmeng/router/RealRouter.java, line(s) 177,290,292,294,317,343,351,360,362,364,408,512,538,559,582,601,630,51,114,118,121,129,331,386,419,422,510,545,547,557,589,594,599,637,641,103
com/xunmeng/router/Router.java, line(s) 48,64,72
com/xunmeng/router/matcher/AbsExplicitMatcher.java, line(s) 29,36
com/xunmeng/tms/app/o.java, line(s) 19,44,69,94,24,49,74,99,29,54,79,104,34,59,84,109,39,64,89,114
com/xunmeng/tms/camera_plugin/camerax_v2/PlatformWithCameraXView.java, line(s) 210
com/xunmeng/tms/goldfinger/test/AccessibilityTestReceiver.java, line(s) 54
com/xunmeng/tms/i/a.java, line(s) 14,25,31,45
com/xunmeng/tms/o/i/a/e.java, line(s) 110,119
com/xunmeng/tms/s/j.java, line(s) 40,45,48,61,35
h/a/a/c/b.java, line(s) 73
h/a/a/g/a.java, line(s) 18
h/a/b/e.java, line(s) 164
h/h/a/c.java, line(s) 265,313,408,468,483,524,530,541,563,567,593,608,692,732,741,767,780,833,923,931,317,715,736,946
h/h/a/d.java, line(s) 79,90
h/k/c/d/b.java, line(s) 84
h/k/c/d/d/a.java, line(s) 15,55,93,131,161,23,63,100,141,31,71,107,151,39,79,114,47,87,121,171
h/k/e/a/a/c.java, line(s) 388,393,382
h/k/e/a/a/d.java, line(s) 207,258,406,211
h/k/e/a/c/c.java, line(s) 39
in/srain/cube/views/ptr/g/a.java, line(s) 14
io/flutter/Log.java, line(s) 21,57,49,53,61,65
io/flutter/app/FlutterActivityDelegate.java, line(s) 166
io/flutter/embedding/android/FlutterActivity.java, line(s) 197,231,228,209,214,261
io/flutter/embedding/android/FlutterActivityAndFragmentDelegate.java, line(s) 218,272,285,297,306,319,337,352,356,384,398,407,419,428,448,457,470,481,505,518,538,566,276,301,324,393,412,423,509
io/flutter/embedding/android/FlutterFragment.java, line(s) 530,658,330,335,378
io/flutter/embedding/android/FlutterFragmentActivity.java, line(s) 190,211,208,253,271
io/flutter/embedding/android/FlutterImageView.java, line(s) 102
io/flutter/embedding/android/FlutterSplashView.java, line(s) 153,183,189,196
io/flutter/embedding/android/FlutterSurfaceView.java, line(s) 31,39,48,62,80,115,117,125,135,144,172
io/flutter/embedding/android/FlutterTextureView.java, line(s) 31,40,55,72,116,118,124,133,140,157
io/flutter/embedding/android/FlutterView.java, line(s) 370,136,272,274,277,280,346,349,352,443,445,519,638,659,710,749,754,811,833,313
io/flutter/embedding/android/KeyboardManager.java, line(s) 118,125
io/flutter/embedding/engine/FlutterEngine.java, line(s) 92,112,128
io/flutter/embedding/engine/FlutterEngineConnectionRegistry.java, line(s) 511,529,545,561,579,602,641,654,669,683,697,394,492,391
io/flutter/embedding/engine/FlutterJNI.java, line(s) 105,645,375,385,423,435,449,492,614
io/flutter/embedding/engine/dart/DartExecutor.java, line(s) 158,211,216,250,153,245
io/flutter/embedding/engine/dart/DartMessenger.java, line(s) 210,294,203,215,262,281,285,315,327,337,354
io/flutter/embedding/engine/deferredcomponents/PlayStoreDeferredComponentManager.java, line(s) 68,72,76,80,84,111,120,124,128,99,171,186,206,219,309
io/flutter/embedding/engine/loader/FlutterLoader.java, line(s) 146,219
io/flutter/embedding/engine/loader/ResourceExtractor.java, line(s) 94,114
io/flutter/embedding/engine/plugins/shim/ShimPluginRegistry.java, line(s) 106
io/flutter/embedding/engine/plugins/shim/ShimRegistrar.java, line(s) 151,158,164,170,176,186
io/flutter/embedding/engine/plugins/util/GeneratedPluginRegister.java, line(s) 13,14
io/flutter/embedding/engine/renderer/FlutterRenderer.java, line(s) 90,180,277,318,348
io/flutter/embedding/engine/systemchannels/AccessibilityChannel.java, line(s) 38
io/flutter/embedding/engine/systemchannels/DeferredComponentChannel.java, line(s) 41
io/flutter/embedding/engine/systemchannels/KeyEventChannel.java, line(s) 73
io/flutter/embedding/engine/systemchannels/LifecycleChannel.java, line(s) 82
io/flutter/embedding/engine/systemchannels/LocalizationChannel.java, line(s) 66,69
io/flutter/embedding/engine/systemchannels/MouseCursorChannel.java, line(s) 32
io/flutter/embedding/engine/systemchannels/NavigationChannel.java, line(s) 36,41,46,53
io/flutter/embedding/engine/systemchannels/PlatformChannel.java, line(s) 42,658
io/flutter/embedding/engine/systemchannels/PlatformViewsChannel.java, line(s) 151
io/flutter/embedding/engine/systemchannels/RestorationChannel.java, line(s) 32
io/flutter/embedding/engine/systemchannels/SettingsChannel.java, line(s) 32
io/flutter/embedding/engine/systemchannels/SpellCheckChannel.java, line(s) 26,31
io/flutter/embedding/engine/systemchannels/SystemChannel.java, line(s) 20
io/flutter/embedding/engine/systemchannels/TextInputChannel.java, line(s) 46,896,901,906,911,916,921,956,965,970,979,984,989,994
io/flutter/plugin/common/BasicMessageChannel.java, line(s) 45,63
io/flutter/plugin/common/EventChannel.java, line(s) 79,90,98
io/flutter/plugin/common/MethodChannel.java, line(s) 53,80
io/flutter/plugin/editing/InputConnectionAdaptor.java, line(s) 78,438,482
io/flutter/plugin/editing/ListenableEditingState.java, line(s) 71,84,103,146,197,112,74
io/flutter/plugin/editing/TextEditingDelta.java, line(s) 91
io/flutter/plugin/editing/TextInputPlugin.java, line(s) 633,509
io/flutter/plugin/platform/PlatformPlugin.java, line(s) 218
io/flutter/plugin/platform/PlatformViewWrapper.java, line(s) 130,132,151,257
io/flutter/plugin/platform/PlatformViewsController.java, line(s) 83,91,144,179,197,207,212,253,264,272,493,289,297,331,446
io/flutter/plugin/platform/SingleViewPresentation.java, line(s) 184,193,201,212,320
io/flutter/plugins/GeneratedPluginRegistrant.java, line(s) 33,38,43,48,53,58,63,68,73,78,83,88,93,98,103,108,113,118,123,128,133,138,143,148,153,158,163,168,173,178,183,188,193,198,203,208,213
io/flutter/plugins/deviceinfo/DeviceInfoPlugin.java, line(s) 22,25
io/flutter/plugins/urllauncher/MethodCallHandlerImpl.java, line(s) 104,93
io/flutter/plugins/urllauncher/UrlLauncherPlugin.java, line(s) 24,42,57
io/flutter/plugins/videoplayer/VideoPlayerPlugin.java, line(s) 123,142
io/flutter/plugins/webviewflutter/DisplayListenerProxy.java, line(s) 75
io/flutter/plugins/webviewflutter/FlutterWebViewClient.java, line(s) 287,284,278,306
io/flutter/plugins/webviewflutter/InputAwareWebView.java, line(s) 27,60,68,84,123
io/flutter/plugins/webviewflutter/WebViewResourceHitManager.java, line(s) 131
io/flutter/plugins/webviewflutter/WebViewTimeRecorder.java, line(s) 238,146,147,148,195
io/flutter/view/AccessibilityBridge.java, line(s) 1926
io/flutter/view/AccessibilityViewEmbedder.java, line(s) 58,60,67,70,73,87,89,104,107,121,124,140,177,183,190,197,210
io/flutter/view/FlutterNativeView.java, line(s) 197,180
io/flutter/view/FlutterView.java, line(s) 727,385
k/a/j.java, line(s) 85,198,39,57,67,109,122,165,181,191
k/a/k.java, line(s) 61,49,63,64
k/a/l.java, line(s) 13,15,22,26,29,30,12
k/a/m.java, line(s) 106,147,174,205,381,409,464,514,537,46,56,134,341,371,376,394,413,422,433,447,459,475,512,533,572,43,76,163,196,221,249,260,279,305,320,555
k/a/q.java, line(s) 7,12,17
k/a/r.java, line(s) 16,19
l/a/a.java, line(s) 38,42,154,36,44,55,60,66,75,82,88,102,107,110,117,119,132,137,140,146,179,165,172
l/a/b.java, line(s) 64,23,30,37,42,45,48,54,61,72,78,82
l/b/a.java, line(s) 26,29,21
l/b/c.java, line(s) 239,242,245,256,259,262,524,534,421,442,454,470,512,488
l/b/d/a.java, line(s) 12,17,23,28,34,39
l/b/d/c.java, line(s) 166,333,150,162,174,184,186,189,193,200,209,220,230,232,252,340,352,366,84,170,238,254,273,281,294,360,372,380
l/e/a.java, line(s) 25,55,82,109,113,119,132,23,51,63,78,80,123,146
m/a/c/d/b/a.java, line(s) 51,224,164,222,56,161,236
m/a/c/d/b/b.java, line(s) 17,22
m/a/c/d/b/c.java, line(s) 23
m/a/c/d/b/d.java, line(s) 109,112,118,122,126,130,141,145,149,153,166,170,174,179,188,194,198,204,208,220,227,231,234,277,281,52,70,93,135,212,254,245,248,251
m/a/c/d/c/a.java, line(s) 124,129,135,140,152,170,187,193,143,148,153,156
m/a/c/d/d/a.java, line(s) 59,116,118,121
m/a/c/d/e/c.java, line(s) 46,20,44
m/a/c/d/e/d.java, line(s) 105,192,31,41,60,71,74,83,90,94,99,117,121,182,187
m/a/c/d/e/e.java, line(s) 68,190,221,303,433,444,285,301,416,448,566,95,107,117,137,141,149,156,168,173,184,196,207,211,215,227,232,343,454,556,561
m/a/c/d/e/f.java, line(s) 56,62,200,339,342,385,44,78,87,92,101,108,113,118,134,138,162,203,212,215,223,254,270,298,318,372,378,388
m/a/c/d/e/g.java, line(s) 27,33,39,49,61,67,73,89,97,100,103,115,120,43,81,86,109
m/a/c/d/f/a.java, line(s) 32,36,44,53,75,77,19,26,28,38,41,46,49,51,61,71,73,84,89,95,101,107,112,130,146,135
m/a/c/d/f/b.java, line(s) 45,19,24,30,38,44,53,62
meco/core/component/DirMecoComponent.java, line(s) 47,74,85,119,38,43,50,72,114
meco/core/component/FlatMecoComponent.java, line(s) 140,141,60,131,135,146
meco/core/component/MecoComponent.java, line(s) 231,272,295,370,396,404,417,53,65,75,120,125,223,228,266,319,366,423,57,86,151,172,183,196,202,211,429,435,439,445
meco/core/component/MecoComponentConfig.java, line(s) 111,131,77,81,99,174,177
meco/core/dex/MecoBroadcastManager.java, line(s) 14,25
meco/core/dex/a.java, line(s) 185,424,125,188,497,512,538,548,558,568,579,602,113,135,148,255,339,401,404,415,419,515,523,526,532,542,552,562,600,353,396,460,472,520,596
meco/core/dex/b.java, line(s) 17,22
meco/core/fs/d.java, line(s) 40,146,122,136,142
meco/core/pkg/MecoPackage.java, line(s) 63,47,55,99,102,106,110
meco/core/pkg/b.java, line(s) 25,15,39,44,50
meco/core/utils/MecoCoreUtil.java, line(s) 34,37,40,43,23
meco/core/utils/a.java, line(s) 12,23,26,35,39,42,45
meco/core/utils/c.java, line(s) 49,27,43,37,45
meco/core/utils/e.java, line(s) 22,25,28,31,34,43,46
meco/core/utils/f.java, line(s) 24
meco/core/utils/g.java, line(s) 64,71,62,35
meco/core/utils/h.java, line(s) 14
meco/delegate/MecoReflectDelegate.java, line(s) 65,23,26,34,37,44,51,54,62,78,92,101,108,113,118,128,136
meco/logger/AndroidLogImpl.java, line(s) 10,50,88,126,18,58,95,136,26,66,102,146,34,74,109,156,42,82,116,166
meco/logger/MChromiumLog.java, line(s) 7,74,128,173,16,65,83,119,137,182,34,92,146,191,47,101,155,200,56,110,164,209
meco/logger/MecoShell.java, line(s) 24,37,50,68,81,94
meco/statistic/idkey/DummyReporter.java, line(s) 14,19
meco/statistic/idkey/IDKeyReport.java, line(s) 16,21,26,31
meco/statistic/idkey/impl/ChromiumVersionCoverageReport.java, line(s) 13
meco/statistic/kv/info/KVInfo.java, line(s) 115,129
meco/statistic/kv/info/MecoCoverInfo.java, line(s) 29
meco/util/HiddenApiBypassUtil.java, line(s) 18,31,48,53
meco/util/MecoRenderLongTaskManager.java, line(s) 59
meco/util/PathHelper.java, line(s) 29
meco/util/PreloadHelper.java, line(s) 26
meco/util/ResourceUtil.java, line(s) 25,19,21,23,33
meco/util/SoftInputHelper.java, line(s) 81,84,104,118,123,128,131,142,144,148,151
meco/util/SystemUAUtils.java, line(s) 29,48,18,20,25,33,42,55
meco/util/ViewRootImplHelper.java, line(s) 29,32,35,23,20,45,52
meco/webkit/JsDialogHelper.java, line(s) 113
meco/webkit/LegacyErrorStrings.java, line(s) 51
meco/webkit/WebView.java, line(s) 368,158,164,741,890,894,154,170,193,196,199,212,215,218,239,247,269,271,273,308,311,314,1265
meco/webkit/WebViewDelegate.java, line(s) 53,55,57,67,163,165,167,169,35,44,78,87,96,105,114,123,132,141,154,177,185,188,191,196,200,213,222,229,231,244,246,248
meco/webkit/WebViewFactory.java, line(s) 33,110,125,134,30,131
mecox/provider/impl/a/a.java, line(s) 1143,1350,1338,1347
mecox/provider/impl/a/b.java, line(s) 1152,1155,1158,1188,1191,1194,1204,1207,1210,1468,356,365,374,383,392,401,579,588,652,711,730,739,753,812,821,909,983,1002,1016,1035,1114,1123,1375,1382,1410,1424,1512,1521,1575,1737,1743,1822,1876,1953,1982
mecox/webkit/WebView.java, line(s) 111
org/jcodec/api/transcode/Transcoder.java, line(s) 279
org/jcodec/api/transcode/filters/DumpMvFilter.java, line(s) 20,38,44,48,75,76,77,78
org/jcodec/audio/Audio.java, line(s) 72,74
org/jcodec/codecs/mpeg12/FixHLSTimestamps.java, line(s) 13
org/jcodec/codecs/mpeg12/HLSFixPMT.java, line(s) 25,26,67
org/jcodec/codecs/mpeg12/HLSRelocatePMT.java, line(s) 37
org/jcodec/codecs/mpeg12/MTSMediaInfo.java, line(s) 80
org/jcodec/codecs/mpeg12/TimestampUtil.java, line(s) 86,88
org/jcodec/codecs/png/PNGDecoder.java, line(s) 328
org/jcodec/codecs/vpx/vp9/InterModeInfo.java, line(s) 876
org/jcodec/common/ArrayUtil.java, line(s) 254,278
org/jcodec/common/tools/Debug.java, line(s) 11,19,22,30,33,40,42,48,54,62,65
org/jcodec/common/tools/WavMerge.java, line(s) 13
org/jcodec/containers/flv/FLVReader.java, line(s) 261
org/jcodec/containers/flv/FLVTool.java, line(s) 460,73,141,230,235,247,251
org/jcodec/containers/flv/FLVTrackDemuxer.java, line(s) 175,189
org/jcodec/containers/mkv/MKVType.java, line(s) 380
org/jcodec/containers/mps/MPSDemuxer.java, line(s) 196
org/jcodec/containers/mps/MPSDump.java, line(s) 81,85,93,95,248
org/jcodec/containers/mps/MTSDump.java, line(s) 66,90,102,138,140,142,147,149,151,154
org/jcodec/containers/mps/MTSPktDump.java, line(s) 53,66,91,93,99,101
org/jcodec/containers/mps/MTSReplacePid.java, line(s) 65,94
org/jcodec/containers/mps/index/MPSIndexer.java, line(s) 37
org/jcodec/containers/mps/index/MTSIndexer.java, line(s) 24
org/jcodec/movtool/ChangeTimescale.java, line(s) 40,45
org/jcodec/movtool/Cut.java, line(s) 38
org/jcodec/movtool/Flatten.java, line(s) 56
org/jcodec/movtool/MetadataEditorMain.java, line(s) 151,128,130,140,142,187
org/jcodec/movtool/MovDump.java, line(s) 59,60,84,89
org/jcodec/movtool/Paste.java, line(s) 59
org/jcodec/movtool/QTEdit.java, line(s) 65,69,83,84,85,87
org/jcodec/movtool/QTRefEdit.java, line(s) 40,44,49,71,72,73,75
org/jcodec/movtool/SetPAR.java, line(s) 49
org/jcodec/movtool/Strip.java, line(s) 41
org/jcodec/movtool/Undo.java, line(s) 61,62,78
org/jcodec/movtool/WebOptimize.java, line(s) 32
org/jcodec/testing/TestTool.java, line(s) 105,138,139
org/jcodec/testing/VerifyTool.java, line(s) 36,40,43,51
pcrash/c.java, line(s) 7,22,12,17
top/kikt/imagescanner/core/PhotoManager.java, line(s) 286
top/kikt/imagescanner/core/utils/Android30DbUtils.java, line(s) 422,427,460,464,467,474
top/kikt/imagescanner/core/utils/AndroidQDBUtils.java, line(s) 423,428,461,465,468,475
top/kikt/imagescanner/core/utils/DBUtils.java, line(s) 516,519,526
top/kikt/imagescanner/e/d.java, line(s) 12,18,24,30
xmg/mobilebase/kenit/entry/DefaultApplicationLike.java, line(s) 19,24,29,34,39,44
xmg/mobilebase/kenit/lib/service/AbstractResultService.java, line(s) 26,38,43
xmg/mobilebase/kenit/lib/service/DefaultKenitResultService.java, line(s) 15,18,25,43
xmg/mobilebase/kenit/lib/service/KenitPatchService.java, line(s) 35,61,66,139,112,114,116,126,132,55
xmg/mobilebase/kenit/lib/util/a.java, line(s) 11,15,19,23
xmg/mobilebase/kenit/lib/util/b.java, line(s) 64,67
xmg/mobilebase/kenit/lib/util/c.java, line(s) 50,129,196,175,125,143,146,149,156,164,167,170,185,194,200,206,216
xmg/mobilebase/kenit/loader/AppInfoChangedBlocker.java, line(s) 80,32,71,75,77,34,65
xmg/mobilebase/kenit/loader/KenitArkHotLoader.java, line(s) 97,103,87,82
xmg/mobilebase/kenit/loader/KenitDexLoader.java, line(s) 257,293,306,46,52,57,140,157,161,207,222,241,264,279,202,251
xmg/mobilebase/kenit/loader/KenitDexOptimizer.java, line(s) 519,589,92,110,116,121,176,198,211,256,378,440,443,516,526,552,562,651,661,665,702,713,729,329,340,399,437,512,692,699,716,722
xmg/mobilebase/kenit/loader/KenitLoader.java, line(s) 127,312,352,54,57,62,68,74,97,104,145,151,158,165,172,201,210,217,221,223,240,244,264,276,287,290,297,305,344
xmg/mobilebase/kenit/loader/KenitMemClassLoader.java, line(s) 88,192,224
xmg/mobilebase/kenit/loader/KenitResourceLoader.java, line(s) 49,69,80,84,73,77
xmg/mobilebase/kenit/loader/KenitResourcePatcher.java, line(s) 45,60,41,142,54
xmg/mobilebase/kenit/loader/KenitUncaughtHandler.java, line(s) 30,32,37,49
xmg/mobilebase/kenit/loader/NewClassLoaderInjector.java, line(s) 26,66,76,98,69
xmg/mobilebase/kenit/loader/SystemClassLoaderAdder.java, line(s) 135,139,170,174,176,179,93,247,253,274,124,159,225
xmg/mobilebase/kenit/loader/hotplug/ComponentHotplug.java, line(s) 39,73
xmg/mobilebase/kenit/loader/hotplug/IncrementComponentManager.java, line(s) 359,61
xmg/mobilebase/kenit/loader/hotplug/handler/MHMessageHandler.java, line(s) 73,107,115,87,92,98
xmg/mobilebase/kenit/loader/hotplug/handler/PMSInterceptHandler.java, line(s) 53,56,102,105,27,76,37,69,86
xmg/mobilebase/kenit/loader/hotplug/interceptor/Interceptor.java, line(s) 28
xmg/mobilebase/kenit/loader/hotplug/interceptor/KenitHackInstrumentation.java, line(s) 81,76,108
xmg/mobilebase/kenit/loader/shareutil/ShareFileLockHelper.java, line(s) 29,34
xmg/mobilebase/kenit/loader/shareutil/ShareIntentUtil.java, line(s) 47,59,123,135,147,159
xmg/mobilebase/kenit/loader/shareutil/ShareKenitBackGroundManager.java, line(s) 49,62
xmg/mobilebase/kenit/loader/shareutil/ShareKenitInternals.java, line(s) 248,582,585,588,93,117,140,158,317,380,401,642,448,522,524,526,528,530,532,708,745,443,454,750
xmg/mobilebase/kenit/loader/shareutil/ShareKenitLog.java, line(s) 24,32,51,40,59,67
xmg/mobilebase/kenit/loader/shareutil/ShareLoadReport.java, line(s) 136,150,197,232,242,253,283,290,293,299,309,334,342,363,373
xmg/mobilebase/kenit/loader/shareutil/SharePatchFileUtil.java, line(s) 42,64,153,451,518,531,579,29,31,40,57,84,107,114,448,197
xmg/mobilebase/kenit/loader/shareutil/SharePatchInfo.java, line(s) 218,297,306,95,105,112,138,169,184,193,258
xmg/mobilebase/kenit/loader/shareutil/ShareReflectUtil.java, line(s) 19
xmg/mobilebase/kenit/loader/shareutil/ShareSecurityCheck.java, line(s) 33,106,116,129

信息 应用程序可以写入应用程序目录。敏感信息应加密

应用程序可以写入应用程序目录。敏感信息应加密


Files:
com/xunmeng/tms/o/i/a/f.java, line(s) 427,427

信息 此应用程序将数据复制到剪贴板。敏感数据不应复制到剪贴板,因为其他应用程序可以访问它

此应用程序将数据复制到剪贴板。敏感数据不应复制到剪贴板,因为其他应用程序可以访问它
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x04b-Mobile-App-Security-Testing.md#clipboard

Files:
com/xunmeng/tms/base/util/m.java, line(s) 4,12
io/flutter/plugin/editing/InputConnectionAdaptor.java, line(s) 5,93,102
io/flutter/plugin/platform/PlatformPlugin.java, line(s) 8,248

安全 此应用程序使用SSL Pinning 来检测或防止安全通信通道中的MITM攻击

此应用程序使用SSL Pinning 来检测或防止安全通信通道中的MITM攻击
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x05g-Testing-Network-Communication.md#testing-custom-certificate-stores-and-certificate-pinning-mstg-network-4

Files:
com/xunmeng/mbasic/network/n/a.java, line(s) 35,33
com/xunmeng/pinduoduo/pdddiinterface/network/c/d/b.java, line(s) 36,31

安全 此应用程序可能具有Root检测功能

此应用程序可能具有Root检测功能
https://github.com/MobSF/owasp-mstg/blob/master/Document/0x05j-Testing-Resiliency-Against-Reverse-Engineering.md#testing-root-detection-mstg-resilience-1

Files:
com/xunmeng/pinduoduo/apm/common/utils/c.java, line(s) 67,51,55,55,55,55,55,55
com/xunmeng/pinduoduo/basekit/commonutil/AppUtils.java, line(s) 18,18,18,18,18
pcrash/k.java, line(s) 15,15,15,15,15

关注 应用程序可能与位于OFAC制裁国家 (China) 的服务器 (apm.hutaojie.com) 通信。

{'ip': '212.64.116.43', 'country_short': 'CN', 'country_long': 'China', 'region': 'Beijing', 'city': 'Beijing', 'latitude': '39.907501', 'longitude': '116.397232'}

关注 应用程序可能与位于OFAC制裁国家 (China) 的服务器 (y2g.cn) 通信。

{'ip': '121.5.84.15', 'country_short': 'CN', 'country_long': 'China', 'region': 'Beijing', 'city': 'Beijing', 'latitude': '39.907501', 'longitude': '116.397232'}

关注 应用程序可能与位于OFAC制裁国家 (China) 的服务器 (pmmtk-a.pinduoduo.com) 通信。

{'ip': '101.226.46.28', 'country_short': 'CN', 'country_long': 'China', 'region': 'Shanghai', 'city': 'Shanghai', 'latitude': '31.224333', 'longitude': '121.469139'}

关注 应用程序可能与位于OFAC制裁国家 (China) 的服务器 (file.pinduoduo.com) 通信。

{'ip': '81.69.152.219', 'country_short': 'CN', 'country_long': 'China', 'region': 'Beijing', 'city': 'Beijing', 'latitude': '39.907501', 'longitude': '116.397232'}

关注 应用程序可能与位于OFAC制裁国家 (China) 的服务器 (cdl.pddpic.com) 通信。

{'ip': '58.216.20.149', 'country_short': 'CN', 'country_long': 'China', 'region': 'Jiangsu', 'city': 'Changzhou', 'latitude': '31.783331', 'longitude': '119.966667'}

关注 应用程序可能与位于OFAC制裁国家 (China) 的服务器 (file.hutaojie.com) 通信。

{'ip': '42.192.253.100', 'country_short': 'CN', 'country_long': 'China', 'region': 'Beijing', 'city': 'Beijing', 'latitude': '39.907501', 'longitude': '116.397232'}

关注 应用程序可能与位于OFAC制裁国家 (China) 的服务器 (meta.pinduoduo.com) 通信。

{'ip': '121.5.87.235', 'country_short': 'CN', 'country_long': 'China', 'region': 'Beijing', 'city': 'Beijing', 'latitude': '39.907501', 'longitude': '116.397232'}

关注 应用程序可能与位于OFAC制裁国家 (China) 的服务器 (apiv2.hutaojie.com) 通信。

{'ip': '42.192.253.100', 'country_short': 'CN', 'country_long': 'China', 'region': 'Beijing', 'city': 'Beijing', 'latitude': '39.907501', 'longitude': '116.397232'}

关注 应用程序可能与位于OFAC制裁国家 (China) 的服务器 (tc.pinduoduo.com) 通信。

{'ip': '81.69.246.99', 'country_short': 'CN', 'country_long': 'China', 'region': 'Beijing', 'city': 'Beijing', 'latitude': '39.907501', 'longitude': '116.397232'}

关注 应用程序可能与位于OFAC制裁国家 (China) 的服务器 (apm.pinduoduo.com) 通信。

{'ip': '101.226.153.254', 'country_short': 'CN', 'country_long': 'China', 'region': 'Shanghai', 'city': 'Shanghai', 'latitude': '31.224333', 'longitude': '121.469139'}

关注 应用程序可能与位于OFAC制裁国家 (China) 的服务器 (ccdn.pddpic.com) 通信。

{'ip': '180.97.228.112', 'country_short': 'CN', 'country_long': 'China', 'region': 'Jiangsu', 'city': 'Suzhou', 'latitude': '31.311390', 'longitude': '120.618057'}

关注 应用程序可能与位于OFAC制裁国家 (China) 的服务器 (ddmc.pinduoduo.com) 通信。

{'ip': '81.69.68.235', 'country_short': 'CN', 'country_long': 'China', 'region': 'Beijing', 'city': 'Beijing', 'latitude': '39.907501', 'longitude': '116.397232'}

关注 应用程序可能与位于OFAC制裁国家 (China) 的服务器 (api.pinduoduo.com) 通信。

{'ip': '81.69.104.49', 'country_short': 'CN', 'country_long': 'China', 'region': 'Beijing', 'city': 'Beijing', 'latitude': '39.907501', 'longitude': '116.397232'}

关注 应用程序可能与位于OFAC制裁国家 (China) 的服务器 (cfg.pddpic.com) 通信。

{'ip': '180.97.228.112', 'country_short': 'CN', 'country_long': 'China', 'region': 'Jiangsu', 'city': 'Suzhou', 'latitude': '31.311390', 'longitude': '120.618057'}

关注 应用程序可能与位于OFAC制裁国家 (China) 的服务器 (dl-test.pddpic.com) 通信。

{'ip': '117.85.65.46', 'country_short': 'CN', 'country_long': 'China', 'region': 'Jiangsu', 'city': 'Wuxi', 'latitude': '31.568871', 'longitude': '120.288567'}

关注 应用程序可能与位于OFAC制裁国家 (China) 的服务器 (commimg.pddpic.com) 通信。

{'ip': '121.226.245.103', 'country_short': 'CN', 'country_long': 'China', 'region': 'Jiangsu', 'city': 'Suqian', 'latitude': '33.933334', 'longitude': '118.283333'}

关注 应用程序可能与位于OFAC制裁国家 (China) 的服务器 (driver.pinduoduo.com) 通信。

{'ip': '81.69.238.99', 'country_short': 'CN', 'country_long': 'China', 'region': 'Beijing', 'city': 'Beijing', 'latitude': '39.907501', 'longitude': '116.397232'}

关注 应用程序可能与位于OFAC制裁国家 (China) 的服务器 (ccdn.yangkeduo.com) 通信。

{'ip': '180.97.228.112', 'country_short': 'CN', 'country_long': 'China', 'region': 'Jiangsu', 'city': 'Suzhou', 'latitude': '31.311390', 'longitude': '120.618057'}

关注 应用程序可能与位于OFAC制裁国家 (China) 的服务器 (mstatic.pinduoduo.com) 通信。

{'ip': '180.97.228.112', 'country_short': 'CN', 'country_long': 'China', 'region': 'Jiangsu', 'city': 'Suzhou', 'latitude': '31.311390', 'longitude': '120.618057'}

关注 应用程序可能与位于OFAC制裁国家 (China) 的服务器 (funimg.pddpic.com) 通信。

{'ip': '111.170.23.41', 'country_short': 'CN', 'country_long': 'China', 'region': 'Hubei', 'city': 'Xiangyang', 'latitude': '32.042198', 'longitude': '112.144791'}

安全评分: ( 多多买菜司机 6.9.3)